I've written a detailed argument for why passwordless auth (using email or some sort of reliable auth) is more secure than using passwords: https://medium.freecodecamp.org/360-million-reasons-to-destr...
The risk factors associated with how humans use passwords vastly outweigh the risk of data being captured in transit.