Expect more trash from them since it worked once.
Expect more trash from them since it worked once.
Clicking "forgot password" typically sends you an email prompting to set a new one; this is similar, in a sense.
I mean, that's how it works for most websites. I think I have 2FA turned on for FB, but honestly the phone system is way less secure than email at Google/Microsoft.
When it comes to the security implications, consider that email has long been a "single point of failure" for a lot of services in the form of the "forgot password" feature that emails you a link to reset your password.
When I'm talking to non-tech people in my life about how best to protect themselves, I usually tell them to think about priorities and disaster scenarios. What would suck the most if it got hacked? The two that are usually at the top of the list for pretty much everyone are email and online banking. Others might include Amazon accounts (hackers can order themselves gift cards with your CC if compromised etc.) Prioritize securing those with a strong password + MFA. The rest is case by case but make sure to use a password manager so you're not reusing passwords.
Google is comparable, but it's too risky for them to have so many magic links hanging around in customer inboxes, because Google identities tend to be tied to far more sensitive 3rd party applications. Which is not to say that there are no sensitive applications with "Login with Facebook", but I'll argue there are fewer.
Edit: I just found I didn't set up 2fa. I wonder, if I had, would they still do this? Then it would have just blatantly ignored my second factor...
You will be asked to authenticate if you try to do anything.
Can still log in as often as I want into clean browser sessions. Even when I log out, clean the session, tapping the url logs me in again.
And every time FB sends me an email: "Someone logged in from some location, was it you?"