Why Doesn't Your Cantrip Login Ask for a Password?

Why Doesn't Your Cantrip Login Ask for a Password?

Is the password on your Cantrip login the same one you use somewhere else? Your email, maybe. An old forum account you forgot existed. You don't have to answer, but you already know.

Cantrip's web login skips that problem, because there's no password to reuse in the first place. Type in your email, we send you a one-time code, you type that in, you're logged in. Nothing to remember, and nothing sitting on a server waiting to end up in some other site's breach dump next year.

This isn't a workaround we shipped because password resets were annoying to support (though, fair, they were). It's the actual login. A password field is one more thing that can leak, and it leaks from someone else's server as often as ours.

You can sign in with Google instead, if that's easier. First time you use it, Cantrip either matches it to your existing account by email or sets one up. One less password either way, because there's still no password.

A code emailed to you is only as safe as that email account, and if you're logging in from a shared computer, that session can stick around longer than you'd expect. So we don't leave it there. Your account settings have a two-factor authentication option: turn it on, and any standard authenticator app (Google Authenticator, Authy, whatever you've already got) adds a second code on top of the one we email you.

Once it's on, Cantrip remembers your own computer for thirty days, so you're not punching in a code every morning. A new device, or someone logging in from somewhere you've never been, gets the extra check every time.

One honest limit, worth knowing before you turn it on: there's no recovery code today. Lose the phone with your authenticator app and you're stuck until we can verify it's really you and clear it manually. If your authenticator app already backs up to the cloud (most of the popular ones do), turn it on without a second thought. If you're not confident you'd ever see that phone again, it's fine to skip it. The email code alone is already safer than the password you're using right now for the same job.