4 ms·
For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any
by interfixus 8y ago
For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.
- XorNot 8y ago2FA is nice when you're working across devices - I.e. using a public PC but have your phone on you.
- interfixus 8y agoOh yes,just please don't force me into it. I actually use it in a few essntial places, but only as an opt-in.
- u801e 8y agoIdeally, I would not want to use a public computer to access an important account. People can forget to use an incognito session, forget to log out, or even forget to close the browser.
- jaxn 8y agoI recently started using a Titan key where I can and am in the process of requiring it for my team. We can handle good passwords. But our customers deserve for our database, admin tools, etc to require the more comprehensive authentication. I'm not going to make our customers use 2FA, but we do require it internally now. We can handle it.
- u801e 8y agoIn contrast, I wouldn't hesitate to enable 2FA if the company supported doing so via client-side TLS certificates (such that I can import it into my browser and use it in combination with my existing credentials).
- knorker 8y agoUntil a zero day exploit takes your browser, your VM you run your browser in (with confidence like yours you'd better run Qubes OS style) and just sniffs everything. The "I know what I'm doing" doesn't hold up very well, statistically.
- aasasd 8y agoSo you trust all the services you use to never leak your password. Good luck with that.
- interfixus 8y agoWhatever gives you that idea?
- mmirate 8y agoThe inherent limitations of human memory likely made that person assume you use a single password everywhere. Your response makes me assume that you memorize a unique password for every account. You do you; but personally, I would rather memorize timeless things like facts and theorems - or at least ephemeral-yet-important things like deadlines, decisions, names+faces, etc. - than memorize a ton of meaningless blobs of entropy.
- aasasd 8y agoContrary to what the other person said, I didn't think that you use a single password. Still, when a password is stolen, I prefer to have a second layer of security instead of losing my stuff in that account (and giving the attacker additional data to use against other accounts).
- em-bee 8y agoas mentioned elsewhere, 2FA protects against identity theft in that someone can call your bank, pretend to be you and get access, whereas it is actually less effective against phishing sites that will ask you for your 2FA code and if you didn't notice you are on the wrong site you'll likely just give it to them. while you can protect yourself against fishing, and there 2FA is indeed less useful, you can't control how diligent the bank is in verifying your identity.