If I am creating a new service today I will probably won't bother and just offer social logins.
If I am creating a new service today I will probably won't bother and just offer social logins.
It really isn't, it's fairly basic. It's mostly "basic" because people have been implemented those things for so long that there basically are established patterns you can reuse with very few drawbacks.
As long as read up on how to implement it and use common sense, you can get authentication working (& being secure) under a day.
Edit: Today you can even do it the lazy way and implement "passwordless" email login as a step to see if it's worth implement the simple email+password way later. Basic steps: 1) Allow users to request login, which creates a login token in the DB and sends a URL to the users inbox 2) Allow users to exchange login token for a auth token that eventually expires somehow, delete login token from DB and store login token 3) be able to lookup if a login token is correct when hitting other API endpoints
Congrats, you now have a basic authentication scheme
If anything, it's 2FA that has me more concerned, because it has made my phone number a near single point of failure with the way everyone wants to use my phone number for it still.