The switch from passwords to email-based tokens only improves security for the least secure users and decreases security for all other users. Many users leave their email authenticated on phones and computers, increasing risk of attack if devices are stolen, compromised, or otherwise made accessible—and because the login identifier is the email, all required information is available to an attacker. I would highly suggest the use of email-based tokens on top of passwords, rather than replacing them—for password related concerns, users should be advised to make use of password managers.