It only has to be as secure as password reset.
Passwordless login is just password reset without a password, neatly removing the weak link in the chain.
Passwordless login is just password reset without a password, neatly removing the weak link in the chain.
A password-less login, the email can be deleted and unless there are logs of last login, and the user notes the pertinent detail, then the intrusion can be covert.
Having someone unknowingly have a key to your apartment is much more of a breech than discovering a broken lock that you know needs fixing.
And without the security questions.
I think the biggest security differential is the fact that a compromised password reset generally is harder to hide, because the attacker cannot replicate the original token.