It absolutely drives me nuts that the western world is moving to "as seen in China" login-via-callback flow. Aside from the privacy issue of forcing people to attach an email or phone number or third-party auth provider to their every account, it's just a waste of time and energy to delete our passwords and force us through this weird multi-app flow just to log in to a service we spent years logging into without ever getting hacked. Imagine if every time you wanted to get into your house you had to press the doorbell and then wait for someone to call you back to decide whether you should be allowed in. It's absurd.
What, exactly, does this mean?
But passkeys are the new hotness, not SSO, and what you’re describing is SSO. Passkeys aren’t tied to an outside account, just a password manager (which can be your browser - no account required).
And yes, I understand the major conflict of interest in saving important passwords to Google, which I personally don't do and wouldn't recommend, but I think if they're interested in staying out of the Googleverse, we can also tell people about the good paid alternatives out there.
Because there are vested interests in doing the latter. That said, I don't trust password managers either.
This is exactly what I do to visitors to my house.
Many sites have "magic links" (they sent you a link to login via email instead of having to write a in password), but there's almost always a way to say you want to log in with your password. Sometimes, especially for touchier things, there's MFA.
> Aside from the privacy issue of forcing people to attach an email or phone number or third-party auth provider to their every account
How do you login without an email, phone number or delegating to a third party? You perform a secret magic dance? Especially for something such as booking.com which more likely than not has your bank details saved, and can wreak havoc (cancel your bookings), I'm really not sure what you want them to do.
The thing that makes it particularly egregious is that Booking.com is literally designed to be used on the road, from any location anywhere, on any weird device you might have access to at the time. There's no guarantee that whatever janky airport wifi allows IMAP, or that your phone can receive SMS in whatever country you're in. Forcing 2FA - or now apparently just the "1FA" of magic link/OTP - has made the service useless for its primary purpose.
[0] https://old.reddit.com/r/Bookingcom/comments/1hl055b/cannot_...
Bold of you to even assume the current generation of a 'decision makers' do know what IMAP is.
Passkeys are a great Trojan horse for password managers vs oauth, magic links, "password123" strings
Mainly due to conflict resolution, corruption and version history. It still has best implemented “online only files”.
Think 10 person design studio all working in one big studio “Work” folder.
So while the clients got bloated Dropbox still has edge in essentials. People trust it unlike other services some of which are straight up infamous for loosing your files like iCloud or corrupting them like adobe creative cloud.