this post was submitted on 25 Aug 2026
37 points (100.0% liked)

Technology

43468 readers
428 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 4 years ago
MODERATORS
 

Lately, the process of accessing apps and websites has grown dizzying. “I’m in password hell,” a colleague confided to me recently. “Every login attempt is playing the lottery.” The problem is not just the sheer number of digital accounts, all of which require their own password, ideally unique and unguessable (which usually also means un-memorizable). It’s the pileup of solutions to that problem: all of the different layers of software offering to remember your passwords, the six-digit codes sent to your phone, the authenticator apps, the passkeys.

top 12 comments
sorted by: hot top controversial new old
[–] debanqued@beehaw.org 1 points 10 hours ago* (last edited 9 hours ago)

Website enshitified. Had to use lynx to see the text for more than 1 second:

$ torsocks lynx https://www.theatlantic.com/technology/2026/08/password-manager-login-difficulty/688396/?gift=A_VYuI0Bs4X1cJsYonaJVE29HRH1L8Ei13mJ3d1owSA

[–] Scrath@lemmy.dbzer0.com 29 points 2 days ago (2 children)

There's also websites that for some reason only request a username/e-mail and then send you a one time login code, requiring me to open my e-mail program instead of having a one click login with my password manager...

[–] XLE@piefed.social 14 points 2 days ago (1 children)

There are so many downsides to this method compared to a password manager too. There's no encryption, email itself is a minefield when it comes to decent security practices, and I've often been stuck waiting for a login link to arrive before I can actually use whatever I was trying to manage.

[–] Mora@pawb.social 4 points 2 days ago

It is literally insane. The codes/links usually only work for 10-15 minutes. If the mail fails the RFC 5321 recommends a retry interval of at least 30 minutes (for up to 4 to 5 days).

[–] IronKrill@lemmy.ca 9 points 2 days ago* (last edited 2 days ago)

These drive me up the wall. If you email me a signin code at login and offer a "forgot password" reset by email, then the password is cosmetic. Just get rid of it ffs.

[–] clmbmb@lemmy.dbzer0.com 7 points 2 days ago

I don't even want to comment on the fact that everything gets very very hard for older people. My mother calls me every time some application changes the authentication method and almost never understands why the change is needed.

[–] reksas@sopuli.xyz 2 points 2 days ago

and then skilled intruder just bypasses most of the things should they want in

[–] KingThrillgore@lemmy.ml 8 points 2 days ago* (last edited 2 days ago)

Passwords were easier. All you needed was a good manager like Bitwarden and that was it. Maybe 2FA for money and corporate.

[–] panda_abyss@lemmy.ca 9 points 3 days ago (1 children)

Yesterday my partner asked me about passkeys and I had to finally have the talk with her.

[–] Maestro@fedia.io 9 points 2 days ago (1 children)

That passkeys suck and that username + password + optional totp managed by a password manager is by far to easiest solution?

[–] panda_abyss@lemmy.ca 5 points 2 days ago* (last edited 2 days ago) (1 children)

Yes! Passkeys don’t solve anything.

I just don’t see how you can do passkeys without still having passwords, so it’s nice that it can’t be phished, but your password still can! (I mean, you can go magic/email link only, but that’s annoying AF)

If you did go pure passkeys, the second someone gets a new computer or phone, or switches phone type, or they have a house fire and their devices get destroyed, they’re kinda fucked.

Unless they have a password manager, which is a single point of failure that a lot of people don’t trust. But that doesn’t fix the above issues.

So where I’m at is keep your main passwords or password manager backup auth codes in a safe deposit box and just do whatever the fuck you find easier, and hope your house doesn’t burn down.

[–] Kache@lemmy.zip 3 points 2 days ago

Passkeys are good at the fundamental level, but the practical implementation is lacking, despite their efforts.

IMO best way is /w a pw manager that's also backed up, available, and synced everywhere you need it, but that's a hurdle for most users.

I think the "intended way for normal ppl" is to set multiple keys, each on their trusted devices, like backup physical keys, but that's kind of a pain to have for every service, too.