13. Believe it or not, many in the security community have long been adamant that "push auth" is insecure, precisely because they're susceptible to social engineering attacks
In fact, many Clerk customers disable magic link auth for this reason, and instead use email-based OTPs