Do I understand correctly that soon we won’t be able to log in using username & password, but have to use Apple/Google or “magic links”?
Do you really want to punish users who are able to manage their credentials (for example by using a password manager) because some people forget their password?
Please don’t! This is yet another stupid step to alienate your customers…
Totally agree, i got the announcement that trakt will no longer use username/password but the hideous apple or google logins. Why ? do not do that. I support you with the change of theme and the bashing but here it is beyond logic.
Apply 2FA, do something else. why do i have to login with my google account (and why do i need one to access the site, yes i have one but others may not, or apple account) You are forcing people to go a path noone wants.
I don’t have a problem with Apple sign on. That’s how I’ve been logging in, but it’s weird that you’re making this change, but not offering 2FA or passkeys is weird.
Hmm. I do have a problem with Apple sign on. Because I use Google Drive for weekly backups, it has made it the default connection. I expect that you can only have Google or Apple connected one at a time and not both. Perhaps that is why it is not showing as connected for me (for Apple) when I try to validate the sign on. And because I use Google Drive, I have to have Google as the login as well…
I hope you reconsider and allow us to use 2FA instead. Magic links are slow, interact poorly with password managers, and I don’t like using my e-mail as a part of your site’s security.
I understand that a passwordless login via email can be easier for many users that struggle with secure passwords.
But many others have password managers that can handle secure long passwords and TOTP 2FA to enable frictionless and secure login.
Forcing those users to use an email code makes the process much slower and also less secure.
Can’t you have a “Continue with Password” or similar option, maybe even less prominent, so that users have the option between an email code and password login?
This doesn’t improve security at all, it just shifts it to the mail provider, just offer passkeys + OTP like all good services, I also don’t want you junk in my email everytime I login, which is everytime I restart my computer since my browser nukes credentials on close.