User/password is an inconvenient method of logging in. True. But it's so common that we have password managers making it convenient again. And supposedly better solution don't have the benefit of that tooling.
They either don't trust password managers, or don't want to change their current workflow.
They don't seem to care that using a password manger is probably a better solution then using the same password everywhere or writing all their passwords in a little black book.
I suspect that you and I aren't representative of typical users, and that Medium and Notion might actually be acting rationally, trying to act in accordance with the ways the majority of their users want the login experience to be.
> They either don't trust password managers, or don't want to change their current workflow.
I used to memorize all my passwords but now I just use my browser's 'remember password' feature. In both Firefox & Chrome it syncs between devices, and is usable on both the desktop and mobile applications. There's no extra setup required, which was the big selling point (or I would still be memorizing them) - one day I reset the browser. FF e2e encrypts it too.
The only drawback is if you need to login on a foreign device - but that's a pretty rare circumstance, and if I can't remember the password I just reset it. I generate passwords with a pattern but I am saved the hassle of typing them in, and having to remember the exceptions that differ from the usual pattern.
Firefox even offers to generate a random secure password when you are creating a new account! It's a built-in solution which provides most of the benefits of a full password manager with 0 setup or switching cost.
You’re not the target audience for these features - not only are you the tiny minority, but no matter what system they give you, you’ll find a way to interact with it safely, so for that interaction you simply don’t matter.
And choosing to do this kind of login pushes blame for authentication issues away from that company, and onto the federated provider, who presumably has legions of security researchers to make sure they’re doing things safely.
I'd imagine Medium would offer "authentication through X", and I can either enter my id for X, or go to the X app and generate a new ID for use for Medium, and paste it on Medium. So next time I want to login to Medium, after entering my username, Medium's backend talks to X's backend (saying user with this ID wishes to login) X can prompt me on one of my devices. Medium can display a unique number on their page for me, and I can compare that to the number my X app is showing me to confirm it's me I'm letting myself in.
This is a 1 minute concept without considering creative ways it can be attacked. But I guess there wouldn't be any money to be made...