4 ms·
This is why I have 1-time codes printed out on paper stashed away in a safe place. If I ever lose my phone, I can get back into the account without access to SM
by 4FNET7 8y ago
This is why I have 1-time codes printed out on paper stashed away in a safe place. If I ever lose my phone, I can get back into the account without access to SMS or an authenticator app.
- giobox 8y agoThis doesn’t solve the original problem though, this is just a potential mitigation strategy for when/if it goes bad (e.g. the cell number is hijacked). It’s personally annoying to me how many 2 factor equipped sites force the use of SMS as the second factor. I imagine the conversation with the PO/PM for the feature must frequently include discussion of fears that allowing customers to opt out of SMS 2FA and use their own code generation tools is risky; you are relying on customer not screwing up to keep them as a paying customer. They lose their personal Authenticator and recovery keys, it can be really awkward to fix. SMS could be argued to be superficially more attractive in this regard, given a cell number can be reissued unlike the permanently lost authenticator device/app. Of course the security of SMS 2FA is terrible etc, but I can understand some of the fear of the alternatives if you need to keep customers happy and able to actually use your service.
- deleted 8y ago[deleted]
- eswat 8y agoI’ve found banks - at least Canadian ones - don’t even provide you with an option with backup codes.
- coldacid 8y agoI'm pretty pissed with TD's complete unwillingness to switch to a better 2FA scheme than SMS codes. Hell, even TOTP would be an improvement.