The Security page was long, repetitive, and warned you about things that were not wrong. Two of its six checks could never pass: it reported that your session was not remembered and showed a “Missing token” badge — while you were signed in and working normally — and it said your terms had not been accepted, when you could not have reached the page without accepting them. The score was stuck below full for everyone, which is the fastest way to teach people to ignore a security page.
It now checks things that are true and that you can act on, and it names the single most useful next step at the top with the control to do it — usually adding a passkey, which cannot be phished, guessed or reused. Panels that were only ever useful to us have gone: a raw data dump, a diagnostics tool and a card describing infrastructure you do not control.
“Manage sign-in security” did nothing. It opened the sign-in page in a new tab, which for someone already signed in simply completed and returned them to the dashboard. Adding a passkey has always been possible on the Security page itself, so that is where the button now takes you.