Which is more secure to log into an online account: simple password, or "secure" code emailed to me?

My account for Slate Auto does not have a password; I type in my email address that they have on file for me and they email me a one-time secure code (or I could have set it up with my phone number to receive a text of the code).

I rather prefer having a code sent to me, and I wonder why more sites don’t do it that way. Is it less secure?

p.s. I suppose it is probably less secure that 2-factor authorization, but that’s not what I’m asking.

I see more websites all the time are adopting that approach. It’s a relatively new fashion in website design that’s still catching on.

Because it’s more secure than a dumb password like “Password”. And it’s more convenient for end users now that the customers they care about (those under age ~40) do everything on their phone, not on a primitive geezer PC or Mac like you or me.

But it’s arguably much less secure than a real password like “aTf*4jy2Mzxv^4yGexpi”.

And it’s definitely less secure than 2FA of a complex PW and a code sent via email or SMS.

When they use an SMS text of a one-time code as the only authentication, in effect that moves the security boundary from “Does somebody else know your secret password?” to “Does somebody else have your phone?” That’s a different kind of risk profile.

When they use an email of a one-time code as the only authentication, in effect that moves the security boundary from “Does somebody else know your secret password?” to “Does somebody else have your phone, OR access to your email?” That’s an even worse kind of risk profile.

It’s probably much more secure for someone who uses aTf*4jy2Mzxv^4yGexpi on every website, which is an unfortunately common bad security habit.

If one site is compromised, which happens all the time, it won’t compromise your Slate Auto account.

Unfortunately, even if you use a different password on every site, the only one that really matters is your email password. When an attacker has that, they can click on “I forgot my password” on almost every other site and read the reset link that gets emailed to you.

True, but how common really is that sort of multi-step targeted attack? Most security breaches (at least the ones I hear about) seem to be mass hacking thefts of database contents, which data is then made available for sale (on the “dark web” I guess). How often does it happen that a particular person is targeted with that kind of research? And wouldn’t that sort of thing be most likely to happen to someone who is notable for some reason, either because they have lots of money, or they make a useful target in some other way? (These are genuine questions, by the way, I don’t know the answers.)

I receive on average 1 or 2 scam emails each day, which are only sent to me because my email address was stolen from some database somewhere and sold to the hopeful scammers. That’s the closest I have come (so far, knock wood) to suffering from any attempted scam. As a pretty anonymous one among billions, how worried do I have to be?

What is the difference between the typical 2-factor authorization, and having a code sent to you email.?

In my experience, the typical 2-factor system is just a code sent to my phone number, which I then type back into the website.

(This scares me so much that I told me bank to never allow a transfer of money from my savings accounts unless I physically sign a paper form at the branch.
My worry is that if my phone gets stolen, the thief would see my bank branch in my contacts, phone them, return the 2FA code and transfer all my money to his account .)

With 2FA you have to type in your secret password and a one-time code that’s sent to your phone or email.

What the OP was talking about is getting a one-time code instead of entering a secret password. There is no secret password at all.

Mostly because it’s a newish idea, and a lot of sites still use older methods. (Or 2FA)

I have switched to using a phrase (leaving out any spaces).

As a password, you mean? No numbers or symbols?

Password is now a terribly antiquated notion. As is requiring one number and capital letter and one special character in a minimum of 8 characters.

2FA and passkeys are safer options. A passphrase is much more secure than just a password.

No it’s not. Anybody with access to your email can initiate a password reset flow. The email OTP pattern came from a sites realizing a decent chunk of their users using the password reset flow as their default flow. The email OTP is essentially turning the password reset flow to become the default flow instead. Usually, a lot of sites will have a tiny text link where you can login with a password instead so the previous password flow now becomes the alternate flow.

I haven’t heard of “passphrase” as a thing before. How is it used that is different from the way a password is used?

p.s. if you don’t want to take the time to type all this, I would appreciate a link to somewhere that explains it. Thanks.

The gist is passphrases are a way to make it easier for people to use long passwords. The longer a password is, the harder it is to brute force it (or decrypt its hash.)

Oh, perhaps the basic point is that passphrases are basically just passwords. The difference is you’re using manynormalwordstomakeone instead of l33tsp3@k.

Personally, I absolutely hate it, especially if it’s the only way to log in.

Inevitably, it works like this. They send a code to my email. Email is asynchronous. Sometimes I get it in one minute; other times it takes 15 or 20 minutes. If it doesn’t arrive right away I fear it’s stuck in my spam folder so I have to log in to my ISP and see if it’s there or not. Which is a pain in the neck, especially if I’m out and about and only have my phone.

Even worse is if the email takes 15 minutes to show up, but the code was only good for ten minutes. Or I switch screens to check my email, and when I go back to the app it has refreshed and generated a new code. And this part makes me want to scream: WHY WON’T THEY TAKE THE FIRST CODE??! Would it be so hard to write the system to accept any code recently generated? Because I get into a loop of multiple codes being generated, and the one I am trying to use doesn’t work.

This actually made me miss a train once on the Amtrak website. I was trying to buy a last-minute ticket an hour before departure, but by the time I got into my account it was sold out. So I got to drive to Utica, NY instead.

More recently (but much less consequentially), I was unable to log into my KFC or Chipotle app accounts for the same reason. By the time the email arrived, the code was no good. And waiting around for an email to show up is maddening if you’re trying to log into their stupid app while standing at the counter. Plus the app randomly logs you out, so you have to go through the same thing again.

This is happening to me more and more as more websites and apps go to this stupid email login route.

Whenever possible, I use a password manager. So I’m not using the same password everywhere.

See Passphrase - Wikipedia.

How can we be discussing passphrases without referring to

A simple illustration of the importance of length: Compare two passwords. One is drawn at random from the set of all possible characters you can type on a standard keyboard. The other also drawn at random, but from absolutely nothing except digits… but the second password is twice as long. Which one is more secure? The longer password with the digits. Each keyboard character has 95 different possibilities, but each pair of digits has 100 possibilities, and you have as many digit-pairs as you have keyboard-characters.

The one I don’t understand is the College Board’s website (for things like AP Classroom). There, you login by using your username and password, and then you’re given a choice, to log in using your password or to use a code emailed to you. But you’ve already entered your password, so it’s effectively just asking you “Do you want to go on in now, or do you want to jump through optional extra hoops to get to the same place?”.

With longer passwords being much more secure, I don’t understand websites that in 2026 restrict passwords to very short lengths. Turkish Airlines is the worse current offender that I’m aware of. Their website still requires that passwords be exactly six (6) digits. No more, no less. And only digits. I had to create an account on their website last year, and I was flabbergasted. :roll_eyes: