There was a time when logging into an account online only involved a username and password. It was a simple, elegant contract between human and machine: you typed the sequence of characters you had carefully memorised, the screen blinked, and you were in. Sure, half the time you had to click "forgot password" because your brain refused to retain a string of words containing a mandatory capital letter and a symbol you could only find by pressing three separate keys at once, but at least it was over quickly.
Now, signing into a website feels less like accessing your email and more like auditioning for an elite intelligence agency.
You enter your credentials, and the machine pauses, squinting at you suspiciously. “We don’t recognise this device,” it whispers, despite the fact that you are sitting on the exact same sofa, using the exact same laptop, with the exact same cup of cold tea sitting beside you that you have used for the past three years.
Suddenly, a security protocol swings into action.
First comes the verification code sent via text message. You pick up your phone, unlock the screen, and wait. You wait thirty seconds. You stare at the blank message app like a fisherman waiting for a bite. You refresh. Nothing. You begin to wonder if mobile networks have quietly collapsed across the entire country while you weren't looking.
Then, just as you resign yourself to defeat, the notification arrives: “Your code is 482901. Do not share this with anyone (not even MI5).”
You rush back to your laptop, your fingers flying across the keyboard to type the digits before they self-destruct, only to discover that the code expired precisely three seconds ago because you took too long opening your messages.
And that is just the baseline level of digital paranoia.
Some websites have escalated to an entirely different plane of psychological warfare: the image verification grid. You are presented with a blurry, pixelated photograph taken by a Google street-view car in 2011 and instructed to “select all squares containing traffic lights.”
You squint at the screen. Does that tiny, three-pixel smudge in the bottom-right corner count as a traffic light, or is it a pigeon? If you click it, will the system decide you are a rogue automaton and lock you out of your account forever? You agonise over the decision like a bomb disposal technician cutting a wire, feeling an unreasonable amount of anxiety over a manual that you haven't looked at since the pandemic.
We have built a digital infrastructure that treats every single user as a suspected cybercriminal attempting to hack into the mainframe of a high-security bank, when all we are actually trying to do is check the status of a library book reservation.
The irony, of course, is that while legitimate users are being forced to solve complex visual riddles and wait for vanishing text messages, actual nefarious entities seem to bypass the whole system effortlessly. Meanwhile, I am locked out of my utility provider account because my browser cache cleared itself during an automated update and it refuses to believe I am me without a fingerprint scan, a retinal sweep, and a notarised letter from a person of good standing.
Maybe the solution isn't adding more layers of cryptographic security to every mundane corner of the internet.
Maybe we need to accept that sometimes, the stakes just aren't high enough to warrant a six-stage verification process. If someone manages to hack into my account and successfully pay my water bill or read my draft emails about buying a new bath mat, frankly, they deserve the prize.
Until then, I’ll be sitting here, staring at my phone, waiting for a text message that may never arrive, wondering when logging onto the internet became an extreme sport.