3 ms·
Yep. They've been planning that for awhile, hopefully a case of "leading by example". For me hardware keys (U2F) with TOTP as a backup are really essential. I'v
by ncphil 5y ago
Yep. They've been planning that for awhile, hopefully a case of "leading by example". For me hardware keys (U2F) with TOTP as a backup are really essential. I've purged SMS where I can. Unfortunately, too many (like banks) have stopped at SMS and email as options -- and that only recently. My (insert name of wildly popular open source password manager here) vault is secured by U2F with TOTP as a fallback, and I use its TOTP feature to secure logins for less sensitive services. Someone mentioned building in delays for resets: that's actually how both the US IRS and Social Security roll. Last time I reset SSA I had to wait for a physical letter with further instructions. Inconvenient, but probably a step in the right direction. If government intel agencies weren't so uptight about crypto, we could all have our own officially issued crypto keys by now. But no. The prols can't be trusted -- and don't deserve it anyway.
- chris_st 5y agoFor whatever it's worth, the US government has shown itself to be spectacularly bad at keeping secrets (proof left as an exercise for the reader).
- bouke 5y agoMaking existing accounts less secure by removing a second factor is not “leading by example” in my book. Just make me pick a different second factor on my next sign-in.