6 ms·
I no longer tell many of my less tech-savvy to use 2FA for most sites. The notable exception being their primary email and a few others. I instead push them to
by e0m 9y ago
I no longer tell many of my less tech-savvy to use 2FA for most sites. The notable exception being their primary email and a few others. I instead push them to use a system like 1Password that will let them generate unique strong passwords.
For a huge majority of people, the odds of them losing, breaking, or wiping their phones and misplacing or forgetting to save their backup codes is MUCH higher than getting hacked while using a 1Password system.
- tomtheengineer 9y ago1Password supports saving the 2FA token: https://support.1password.com/one-time-passwords/ https://support.1password.com/one-time-passwords/. Though you could argue that's not much safer than not using 2FA since if 1Password is breached, the tokens would be available as well. As an alternative, you could use Authy, which backs up the tokens encrypted (just don't store the Authy password in 1Password if you're worried about that being a single point of failure).
- stusmall 9y ago2FA and unique passwords aren't an either or thing. There is a lot of overlap in what they protect against but it's not complete. Having a strong, unique password won't help again being phished but 2FA can help mitigate the dangers of password reuse. I get that everyone's exposure to and acceptance of risk is different. I understand that sometimes the best you can hope for out of a non-technical friend is that they accept maybe one piece of advice at most, but I'd disagree with the priority. 2FA is extremely powerful.