3 ms·
That's why everyone sane avoids giving out their phone numbers to any company except dire necessities, like maybe banks. Use U2F, don't use "google authenticato
by nukeop 8y ago
That's why everyone sane avoids giving out their phone numbers to any company except dire necessities, like maybe banks. Use U2F, don't use "google authenticators" or any other pseudo-2FA. No website has any business knowing your phone number.
Bonus: phone number databases are used in online tracking for connecting accounts across many websites to datamine more accurate data and form better profiles. Everyone privacy minded should be aware of this.
- Spivak 8y agoWhat do you have against TOTP? It doesn't require turn over your phone number, just that you store the key somewhere secure-ish.
- nukeop 8y agoNothing against TOTP per se, but plenty enough against Google Authenticator and its typical use cases. If you log into a website on your phone and use an authenticator running on the same phone, it's not 2FA, it's just two passwords.
- AgentME 8y agoIf you're reusing passwords, it's still better. Obviously it would be better to not reuse passwords, but in general it seems to be easier to encourage users to do 2FA than to not reuse passwords.
- vinay427 8y agoThis depends on your threat model. Imagine someone looking over your shoulder while you type in your password and TOTP token. Without TOTP, they would be able to log into your account on a different device without having your current device. With TOTP, they would need some way to get the correct token when they login, which is much more difficult and more easily noticed by you.