yes, your summary is accurate, which is why we have 2Fa
on a low risk site's FAQ, I wrote
Can I login with a password?
We have eliminated passwords on this site for several important reasons.
People forget passwords and then have to go through the process of resetting their password, which is not much different to just asking to be let in as we do now.
People use the same password for multiple sites. This means that if another site is compromised your password might work on this site also.
If SpeakerNet site is compromised and your password obtained, we don’t want to be responsible for you having also used it for your banking.
We can’t imagine a scenario where you would want to give someone else your username and password so that they can access the site on your behalf.