Logging in Was Never Supposed to Be This Complicated
One afternoon earlier this month, I pulled up to the rec center and realized that I had a problem.
It was not the three boisterous tweens in the back seat who were clamoring to be set loose in the basketball gym.
It was my parking app.
I had somehow gotten logged out of Passport Parking, which has become the only way to pay for a spot in much of my town, and it was demanding a four-digit PIN to let me back in.
My first guess drew a warning message in red letters: “Invalid PIN.
PIN cannot contain 4 sequential numbers, 2 repeated digits, or the last 4 digits of your phone number.” I searched my trusty password manager, which was supposed to spare me these predicaments, but it came up empty.
By that point, the kids had run ahead and piled themselves against the gym door, waiting for me to let them in.
Lately, the process of accessing apps and websites has grown dizzying.
“I’m in password hell,” a colleague confided to me recently.
“Every login attempt is playing the lottery.” The problem is not just the sheer number of digital accounts, all of which require their own password, ideally unique and unguessable (which usually also means un-memorizable).
It’s the pileup of solutions to that problem: all of the different layers of software offering to remember your passwords, the six-digit codes sent to your phone, the authenticator apps, the passkeys.
Browsers and operating systems compete with third-party password managers to generate, store, and autofill your credentials.
Most of my logins live in 1Password, but others are stored in Apple’s Passwords app (usually by accident), and still others were created via “single sign-on” features such as those offered by Google and Facebook.
I vaguely recall certain apps—Facebook is one—prompting me many years ago to copy down a set of “login recovery codes” that would become extremely important should I ever get locked out of my account.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theatlantic.com — the content belongs to The Atlantic.