4 ms·
The problem with 2FA apps is that they don't also serve as an instant notification you when someone is trying to log in as you. 2FA SMS does. This needs to be a
by wfunction 10y ago
The problem with 2FA apps is that they don't also serve as an instant notification you when someone is trying to log in as you. 2FA SMS does. This needs to be addressed somehow before we declare the former superior.
- wyaeld 10y agoThere is more than 1 way to do 2FA apps. I'm a big fan of push-based authorization like Duo Security does it.
- wyaeld 10y agoThere is more than 1 way to do 2FA apps. I'm a big fan of push-based authorization like Duo Security does it.
- iamshs 10y agoMicrosoft Authenticator had this facility, the last time I used it. Instead of using 2FA; it popped up a notification on my phone, which I could then approve or decline. But you can have your mail configured to send email whenever there is a login attempt.
- niftich 10y agoSeveral mobile 2FA apps come with the platform's native cloud messaging support for push notifications; is that not sufficient?
- Spooky23 10y agoThe O365/Azure app does this, but using it doesn't meet other NIST requirements.
- senex 10y agoI use Duo Mobile for some accounts; it supports push. Definitely nicer than rushing to type a number in before the timer expires :)
- rickycook 10y agodefinitely recommend duo push. you get the notifications, the multi-device support, and it's really easy to integrate into lots of things. big fan
- spicyj 10y agoThere's a few minutes' slack so you shouldn't need to rush.
- aianus 10y agoThat is up to the website implementing the 2FA check. We only have tens of seconds slack.
- lyonlim 10y agoInstead of SMS, wouldn't email notifications suffice? Apple (iCloud), Gmail and Salesforce does this when there's a new login on a new device. Furthermore, I'm not too in favour of using SMS... I have two numbers and when I don't have both phones with me, it's a huge hassle. I end up setting up my phones to auto forward such smses. I use 1Password OTP support and love how it works seamlessly across my phones. (Edited for clarity)
- maxerickson 10y agoThis is what Twitter has been doing for me. For whatever reason, I get logged out when I restart my browser and they send me an email each time letting me know I logged in.
- BinaryIdiot 10y ago> Instead of SMS, wouldn't email notifications suffice? Maybe? Email requires a data connection but SMS can reach more places on more phones in worse conditions. I mean sure if you have a terrible or no internet connection then you won't be able to address it anyway but SMS at least in my anecdotal experience has given me much better notifications than email (occasionally I've had issues even with my Nexus 6P where I have to manually refresh my email).
- gambiting 10y agoWhen my Origin account was hacked, I found out that hackers used a very basic vulnerability in Gmail - they've logged into my Origin account, changed the language to Russian, and then changed the password - I received the "your password has been changed" email, but because it was in russian, gmail automatically put it in Spam folder and I never saw it(when I eventually found it the message shown by gmail was "this email is in a different language than used normally for this email address so we've automatically marked it as spam".). Obviously by the time I realized, the "I didn't do this!" link in the email has expired and I had to call EA to recover my account(surprisingly, I did!). So yeah, now I have 2FA enabled on my origin account, but I still wish I received a text message telling me my password was changed.
- askvictor 10y ago2fa via the Google app (not authenticator) does exactly this. Your phone pops up a notification when someone tries to log in.
- kennydude 10y agoI would love just a push notification I can open and get the 2FA code instead of unlocking my phone, finding authenticator etc.