# Which is more secure to log into an online account: simple password, or "secure" code emailed to me?

**URL:** <https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612>\
**Category:** In My Humble Opinion\
**Created:** [July 11, 2026, 11:09pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612 "2026-07-11T23:09:41Z")\
**Posts on this page:** 12\
**Page:** 2

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [July 13, 2026, 4:26pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/21 "2026-07-13T16:26:12Z")

</div>

One reason more sites are moving to an email or text code is liability. If you don’t have a database of usernames and passwords, it can’t be hacked and stolen.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [July 13, 2026, 7:25pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/22 "2026-07-13T19:25:07Z")

</div>

Well, they still have a highly valuable stealable database of userids, often emails. And a database full of customer details like credit cards, purchase history, physical addresses, interests, etc.

But yeah, the bad guys can’t steal a password from that site if there are no passwords.

---

<div class="post-metadata">

**Author:** ![puzzlegal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/puzzlegal/32/3827_2.png) [@puzzlegal](https://boards.straightdope.com/u/puzzlegal)\
**Post date:** [July 14, 2026, 12:34am UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/23 "2026-07-14T00:34:05Z")

</div>

One of the reasons a lot of companies use “Shop”, or ask you to pay via PayPal, is so they _don’t_ have a database with a lot of credit card numbers in it.

Not that the emails and addresses and purchase histories aren’t valuable, but they are less worth stealing than either passwords or credit card numbers, with fewer consequences when it happens.

---

<div class="post-metadata">

**Author:** ![phs3](https://avatars.discourse-cdn.com/v4/letter/p/8491ac/32.png) [@phs3](https://boards.straightdope.com/u/phs3)\
**Post date:** [July 14, 2026, 3:05pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/24 "2026-07-14T15:05:03Z")

</div>

I’ve been assuming this is the reason. Yes, there’s other PII stored, but less is better.

Now if only [shop.com](http://shop.com) and friends did some real-world testing: every one of them has serious usability issues in my experience. Nobody tests nuttin’ no mo’.

---

<div class="post-metadata">

**Author:** ![robby](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/robby/32/11048_2.png) [@robby](https://boards.straightdope.com/u/robby)\
**Post date:** [July 14, 2026, 5:59pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/25 "2026-07-14T17:59:29Z")

</div>

> [@TroutMan](#):
>
> One reason more sites are moving to an email or text code is liability. If you don’t have a database of usernames and passwords, it can’t be hacked and stolen.

Of all of the things that a hacker could steal from a website, the one I care about _least_ is my username and password. Reasons:

- I use a password manager with different random passwords for every website, so my password is only good for that one website. It is useless anywhere else.
- If passwords _are_ ever compromised, the admins of the website itself can immediately make them useless to the attackers by requiring everyone to reset their passwords. I think the SDMB did that once upon a time (twenty years ago or so).
- It should be impossible to steal actual passwords regardless. No website should be storing them in plaintext. They should instead be storing a hash of the passwords (along with salting them) so that they cannot be utilized by an attacker.

So all this effort to get rid of passwords seems misguided for so many reasons—but what is _does_ do is make it much more difficult and sometimes impossible for me to log in to their website for the reasons I outlined in my previous post (i.e. delayed emails, expiring codes, etc.).

---

<div class="post-metadata">

**Author:** ![moes\_lotion](https://avatars.discourse-cdn.com/v4/letter/m/7ba0ec/32.png) [@moes\_lotion](https://boards.straightdope.com/u/moes_lotion)\
**Post date:** [July 16, 2026, 8:54pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/26 "2026-07-16T20:54:00Z")

</div>

> [@TroutMan](#):
>
> One reason more sites are moving to an email or text code is liability. If you don’t have a database of usernames and passwords, it can’t be hacked and stolen.

Any properly coded website will not store passwords, a one-way hash generated from the password is stored instead. The password cannot be derived from the hash so someone hacking into the backend user database is not able to access the accounts. Granted, having a list of usernames gives hackers a leg up, but not the keys to the kingdom.

---

<div class="post-metadata">

**Author:** ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)\
**Post date:** [July 17, 2026, 2:01am UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/27 "2026-07-17T02:01:50Z")

</div>

> [@puzzlegal](#):
>
> _don’t_ have a database with a lot of credit card numbers in it.

There are very strong [rules](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard) that you have to abide by if you are storing credit card information with audit requirements. It’s no wonder that a lot of organisations would want to offload those requirements on someone else who specialises in dealing with that.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [July 18, 2026, 8:46pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/28 "2026-07-18T20:46:52Z")

</div>

The issue is probably more that so many people insist on using passwords that can be figured out from the hash in a short enough time.

I hate it. I use secure passwords on anything that matters. Slowing down the process just makes me want to use your website less. I wind up permanently signing in on sites I previously wouldn’t have, because it’s a chore.

It’s all the hassle of two-factor without the actual security of two-factor. And, if you’ve seen what I said about Wendy’s (which requires you to open the email on the same device you try to log in with—no typeable code) they love to find ways to make these things worse.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [July 19, 2026, 3:08am UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/29 "2026-07-19T03:08:57Z")

</div>

> [@BigT](#):
>
> It’s all the hassle of two-factor without the actual security of two-factor. And, if you’ve seen what I said about Wendy’s (which requires you to open the email on the same device you try to log in with—no typeable code

I’m not a huge fan of doing things on my phone but the only time I’d ever possibly want to use a fast food app is when I’m out, meaning I’d want to use my phone for that. I agree that a fast food app doesn’t need the same security as my bank but is it really that big of a deal?

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [July 21, 2026, 4:16am UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/30 "2026-07-21T04:16:40Z")

</div>

Yes. Because I like to share the app with my roommate so we can both use the benefits. So I would need to have my roommate’s email on my phone. I also tend to use a different email for automated crap so that my main email (the one I would actually use on my phone) can actually be important stuff and not a bunch of useless spam.

I don’t only use apps when I’m out. I order food from home a lot, either to have it ready before I go out, or because roomie is in town with the car. I sometimes buy food for other people. I could in theory also do delivery—something they really seem to want me to do—but that’s a whole other discussion of all the hidden ways they increase the prices to where it’s almost never worth it.

But, regardless, I shouldn’t have to justify my use case. This is pointless reinventing of the wheel. They had to specifically modify their system not to just give a code, like literally every other email verification system. And for what purpose?

Good software design considers edge cases. If you don’t want to do that (and I don’t blame you on a low security app) then you use preexisting solutions that do. I literally cannot see what making people have both the app and that particular email account on the same device accomplishes for anyone.

It’s almost certainly an issue of “well, it’s not inconvenient for **me**.”

Note any passion in this is toward the developers, not you for asking.

---

<div class="post-metadata">

**Author:** ![TroutMan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/troutman/32/6721_2.png) [@TroutMan](https://boards.straightdope.com/u/TroutMan)\
**Post date:** [July 21, 2026, 5:18am UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/31 "2026-07-21T05:18:27Z")

</div>

> [@BigT](#):
>
> But, regardless, I shouldn’t have to justify my use case.

I sympathize with you, but that’s not an edge case. That’s something (sharing accounts among multiple people) that they specifically don’t want to support.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [July 21, 2026, 12:07pm UTC](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612/32 "2026-07-21T12:07:27Z")

</div>

> [@BigT](#):
>
> …  
> This is pointless reinventing of the wheel. They had to specifically modify their system not to just give a code, like literally every other email verification system. And for what purpose?

To largely prevent this:

> [@BigT](#):
>
> Yes. Because I like to share the app with my roommate so we can both use the benefits. …

This isn’t hard.

Same as how IIRC Netflix and Comcast xFinity both had to implement technical obstacles to the widespread practice of dozens (hundreds?) of potential customers sharing one account that one somebody was paying for.

  

Their goal is _not_ to maximise customer convenience. It’s to maximize profitability. Giving out fewer discounts and spiffs, without actually driving too many people into switching to a competitor is the route to that goal. Once we all accept that we’re just sheep to be shorn, not customers to be served, it all makes a LOT more sense.

[Previous page](https://boards.straightdope.com/t/which-is-more-secure-to-log-into-an-online-account-simple-password-or-secure-code-emailed-to-me/1031612.md?page=1)
