Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can I take a moment to complain about Anthropic's insistence on using a magic email link for login in the year 2026? It's so unnecessary. Please, anthropic team. Just allow us to user username/password/2FA.
 help



Oh yes, upvoting, my top annoyance with anthropic too, email links are a bit ridiculous as a login mechanism. Anytime I have to login again, it’s the ridiculous dance of figuring out what surface I’m logging into and how to get the magic link to open there, and not mistakenly somewhere else. Never a problem with openAI - input password and 2FA - done, logged in.

Passkeys are the 2026 answer. No (added) username, no password, no two factor SMS, no phishing.

Passkeys are auth garbage. Normal users do not benefit from overly complex auth.

You tap your finger and you're done. Faster than a password paste. How is that complex or difficult UX?

Too confusing for me, I don't get it. How do I record my login info on paper so my family can get in if I die?

I'm not a fan. But what Anthropic SHOULD have done is use plain ol' SSO. Google, GitHub, Microsoft, etc. logins with the option to do this magic link stuff. The third party auth providers would use passkeys at the user's discretion.

Don't they have Google SSO?

Until you lose your device or it breaks suddenly.

I store passkeys and totps in 1Password. I know it means there's no hardware protection of the secure element, but in return they're trivially synced across my devices.

I feel this tradeoff is worth it to me; certainly it is no worse than email or SMS as the second factor.


Chrome Sync, iCloud Sync. There are great answers for this.

Sure. But if you sync passkeys, are there any advantages apart from phishing protection?

The biggest advantage for me is using the hardware secure enclave, thus effectively getting a 2nd factor.


I love it. I forget my passwords.

I support not storing any kind of password, but they should add passkey support.

Email link is way more convenient than a 2FA text, surely? It means you don't need to remember credentials or have your phone with you.

On iOS and macOS 2FAs are auto-populated for you, and of course also your saved login and password. You don't need to leave the page and open other applications.

This is by far the most common sign-in UX. So is there some security benefit in the email link sign-in?


> auto-populated

Auto population of login credentials including 2FA is currently an attack vector.

"A critical security flaw has been uncovered in the autofill functionality of nearly every major password manager. This vulnerability allows threat actors to stealthily harvest user credentials and sensitive financial data from deceptive web forms without user interaction, turning a core convenience feature into a potent weapon for cybercrime."

https://undercodetesting.com/the-autofill-trap-how-your-pass...


The only way an account accessed by a magic link can be compromised is by an already compromised associated email. No password in clipboard, which is how some of us still do it, etc. The magic link makes everyone secure regardless of how they store their secrets.

And there's also no password stash if the server were to be hacked, which means no sending out "please update your password" emails and the like.


2FA != SMS codes

TOTP works just fine and you can save it in a password manager if you like. Email links don't allow me to use a keyboard shortcut to login, instead I have to open a new tab and click around for a magic code/url.


I'd like to think I am pretty security conscious, but I still don't get the obsession with magic links (and passkeys). This is the one thing where I think I disagree with most of the industry. I thought forgetting passwords was a solved problem. I thought 2fa is much faster than searching for the last email for X provider the maybe takes 1 minute to arrive, requires retries and high tend up in spam? Some one please help me get on board.

It depends how convenient it is for you to constantly be carrying devices that have 2fa software or the correct SIM card installed. I might prefer to simply access my email account, which I know how to do anywhere.

Autofill of password manager creds is an attack vector.

Passkeys and email links prevent things like: clipboard interception, malicious iframes, fake login UIs, etc.



But less convenient than a TOTP generator in your password app.

Not if you don't happen to have a device on you with that app installed.

It is terrible, slow, assumes that I receive my E-mail instantly (what if I use greylisting?), makes me check my E-mail when I don't want to.

This as opposed to my password manager filling in the password field within a second or so.

But they know it's terrible. The reason they do it is to make account sharing more difficult.


The magic link is nice IMO. One less secret to manage.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: