I feel this tradeoff is worth it to me; certainly it is no worse than email or SMS as the second factor.
The biggest advantage for me is using the hardware secure enclave, thus effectively getting a 2nd factor.
This is by far the most common sign-in UX. So is there some security benefit in the email link sign-in?
Auto population of login credentials including 2FA is currently an attack vector.
"A critical security flaw has been uncovered in the autofill functionality of nearly every major password manager. This vulnerability allows threat actors to stealthily harvest user credentials and sensitive financial data from deceptive web forms without user interaction, turning a core convenience feature into a potent weapon for cybercrime."
https://undercodetesting.com/the-autofill-trap-how-your-pass...
And there's also no password stash if the server were to be hacked, which means no sending out "please update your password" emails and the like.
TOTP works just fine and you can save it in a password manager if you like. Email links don't allow me to use a keyboard shortcut to login, instead I have to open a new tab and click around for a magic code/url.
Passkeys and email links prevent things like: clipboard interception, malicious iframes, fake login UIs, etc.
This as opposed to my password manager filling in the password field within a second or so.
But they know it's terrible. The reason they do it is to make account sharing more difficult.