One afternoon earlier this month, I pulled up to the rec center and realized that I had a problem. It was not the three boisterous tweens in the back seat who were clamoring to be set loose in the basketball gym. It was my parking app. I had somehow gotten logged out of Passport Parking, which has become the only way to pay for a spot in much of my town, and it was demanding a four-digit PIN to let me back in. My first guess drew a warning message in red letters: “Invalid PIN. PIN cannot contain 4 sequential numbers, 2 repeated digits, or the last 4 digits of your phone number.” I searched my trusty password manager, which was supposed to spare me these predicaments, but it came up empty. By that point, the kids had run ahead and piled themselves against the gym door, waiting for me to let them in.Lately, the process of accessing apps and websites has grown dizzying. “I’m in password hell,” a colleague confided to me recently. “Every login attempt is playing the lottery.” The problem is not just the sheer number of digital accounts, all of which require their own password, ideally unique and unguessable (which usually also means un-memorizable). It’s the pileup of solutions to that problem: all of the different layers of software offering to remember your passwords, the six-digit codes sent to your phone, the authenticator apps, the passkeys.Browsers and operating systems compete with third-party password managers to generate, store, and autofill your credentials. Most of my logins live in 1Password, but others are stored in Apple’s Passwords app (usually by accident), and still others were created via “single sign-on” features such as those offered by Google and Facebook. I vaguely recall certain apps—Facebook is one—prompting me many years ago to copy down a set of “login recovery codes” that would become extremely important should I ever get locked out of my account. Whatever device I stored them on was probably wiped and sold long ago.Logins have always been a hassle. In the 1990s, forgetting your password sometimes meant mailing a postcard to your service provider and waiting a week or two for it to mail you a new password. In the early 2010s, hackers learned to steal massive troves of logins and then reuse them on other services to steal people’s identities. Things spiraled from there; services started requiring unique, complex passwords with arbitrary requirements. These days, the user experience of logging in is “probably worse than ever,” Troy Hunt, a cybersecurity expert who runs the website Have I Been Pwned, told me. “There’s just no consistency.”Password managers promised a way out, but they often don’t work as seamlessly as you might hope. I click to autofill my password somewhere, and a 1Password authorization appears, only for an iCloud Keychain authorization to pop up directly over it, preventing me from clicking on the 1Password one. When I manually enter a login I thought I remembered, my browser prompts me to remember it; only after I hit “Save” (pro tip: Do not do this) does the website inform me that the password was not recognized. Even when you log in successfully, there’s the tedious dance of waiting for a six-digit authorization code to appear on your phone or in your email, which defeats the concept of a single password for everything. And if you’re somewhere without cell service or you’re sharing a login with someone who isn’t around, you might just be out of luck.All of these steps serve a purpose. At least in theory, each added layer helps prevent hacks and breaches. Erring on the side of safety is worth an amount of inconvenience. At the same time, extra steps can introduce security problems of their own. Last year, Hunt fell for a clever phishing scheme when he clicked a link to log in to his newsletter service. His password manager failed to autofill his information, which should have alerted him that something was wrong, he said. But like the rest of us, he was so used to things not working that he went ahead and manually entered his credentials on a site that turned out to be an impostor, designed to steal and exploit them.None of these obstacles is insurmountable on its own. My problem with Apple’s native password manager fighting with 1Password, for instance, was eventually solved with a 10-minute foray into the bowels of my device settings. But together, they amount to a near-daily irritant. For the less tech-savvy, the situation can be overwhelming. My recent attempts to help my mother fix her password-storage system—which involved loose-leaf notepad sheets full of hand-scrawled credentials scattered around her house like Easter eggs—consumed the better part of a day. By the end, she had all of her credentials updated, validated, and stored in a password manager, just as the experts have been advising for years. But even then, her preferred browser, Google Chrome, showed no interest in surfacing the credentials we had stashed in Apple’s Keychain. And some websites short-circuited her attempts to log in by prompting her to set up a “passkey,” which she interpreted as meaning that her password had failed and she needed to scrap it and set up a new one.Cybersecurity experts will tell you that passkeys—which typically entail logging in to apps or websites with a face or fingerprint scan instead of a password—are the future. When they work properly, they’re both painless and secure. “It may get to a point where we’re all using passkeys and we don’t even know we’re using passkeys,” Lorrie Cranor, a computer-science professor at Carnegie Mellon University who researches privacy and cybersecurity, told me. “I just say ‘Log in’ and I smile at it, and it gets my passkey, and I’m logged in.”But that future isn’t here yet, and in the present, passkeys have added a new layer of frustration. Part of the problem is that virtually no one seems to know what they are. “The fact that even I have trouble explaining them should be a clue,” Cranor said. Her past research on the rollout of two-factor authentication suggests that most people tend to resist new security features for as long as they can. Companies can nudge them, but for websites and apps trying to attract and retain users, pushing people to adopt an unfamiliar authentication technology risks scaring them away.To further complicate matters, passkeys generally aren’t yet replacing passwords altogether, even on sites that use them. Because many passkeys live on your device, one that works on your phone might not work on your laptop, and one that works on your personal laptop might not work on your office device. So you still need a password that works across devices as a backup. It’s a lot, Dave Lewis, 1Password’s global-security adviser, acknowledged to me in an email. “The problem is cognitive overload,” he said. “All these tools are trying to help, but they don’t always work together intuitively.” Still, he disagreed that the situation has never been worse: “When the alternative was using the same password across dozens of accounts or putting it on a sticky note, the fact that people now have password managers, passkeys, biometrics, and multifactor authentication is a good thing.”The mess might compound before it improves. Hacking attempts have been multiplying as crooks harness AI tools. Companies are adding even more security layers that make logging in harder, and they are pleading for people to make the switch to passkeys. On the bright side, maybe the seamless biometric future is actually within sight, and all of our login woes will soon be over. Then again, that’s what we were promised with password managers too.