I disagree. Authentication and authorization are central to many areas in which programmers work. And while there are plenty of gotchas (especially in webdev perhaps), at it's core it can be learned, understood, and implemented right as long as you rely on the experts for the proper tricky bits ("don't roll your own crypto")
Sure, if you can outsource authentication to FB or Apple or OAuth, then that's great. But even then you're still on your own when it comes to authorization. And it's still important to understand what these services are doing for you.
So in the end you still need to properly grok both authentication and authorization.
One of the big 'milestones' in my career was finally building something that involved logins, roles, sessions, etc. It scared the crap out of me from all the HN stuff I'd read. In the end, despite all the gotchas in browser-land in particular, it turned out to not be as complicated as I thought, or at least the complications involved things that no 3rd party service could take care of for me.