5 ms·
Why would 2FA of all things be the critical issue? Tech savvy people should understand and use hardware security keys at this point to be securing their cloud a
by ferdowsi 5y ago
Why would 2FA of all things be the critical issue? Tech savvy people should understand and use hardware security keys at this point to be securing their cloud accounts in general.
- dmw_ng 5y agoTech savvy people often discard browser cookies at every opportunity. Adding a 2FA step to every interaction with Google is a change in routine, and forced routine changes are a great time to break any harmful habit
- toast0 5y agoAs a tech savvy person, I used 2fa for all the corporate stuff I could and for some personal stuff too. Now that I only have one phone, I've turned off 2FA as much as possible, because only one phone means when it breaks, I can't access my accounts, because I can't get to the 2FA tokens. No thanks.
- sct202 5y agoYou can add the 2FA authenticator codes to multiple authenticator programs. I usually add them on to 2 different devices at the same time.
- lotsofpulp 5y agoI use Keepass with Strongbox and save the database file in iCloud. That way I have TOTP codes backed up, and I can share with others such as my spouse.
- artificialLimbs 5y agoYou didn't read any of those screens warning about you needing the backup codes? I do realize some services don't provide backup codes (which is insane), but when they don't I have found that they provide the codes you can manually type in to authenticator apps. With that, you can add the code in multiple places, like on your phone and also another computer with any totp app like authy or TOFU or whatever to have a 'backup'. I keep my backup codes in a plain text files in a folder on my home NAS which is encrypted on disk, and backs up through rclone (with encryption) to backblaze every night. I'm about to configure up a second NAS for redundancy because 3 2 1.
- toast0 5y ago> You didn't read any of those screens warning about you needing the backup codes? I read them, and said, no thanks; I'd rather be able to recover my accounts easily.
- deleted 5y ago[deleted]
- xdennis 5y agoBecause my email account is that's linked to every other account and I can't afford to lose everything just because I've lost my phone (which has happened twice in the last two years, but recovered it both times).
- r0m4n0 5y agoYou have many options including notifications in google apps, authenticator apps, text messages, hardware tokens, written backup codes. Not all of these rely on your phone so set them all up
- KennyBlanken 5y agoSo in other words dramatically increase the attack surface on my account. Enabling SMS authentication for an account is a huge DOWNGRADE in security, not an increase. Cellular providers are infamously easy to socially engineer.
- iszomer 5y agoEspecially some banks that still use SMS as your 2FA.
- r0m4n0 5y agoNo… Well I guess if you were adding SMS as a 2fa option to your real 2fa would increase surface but that wouldn’t solve what the parent comment was saying. So yea don’t do that (but it’s better than just a password). 1)Password alone is weak. 2)Password and SMS 2fa better. 3)Password and real 2fa best. 4)Password, real 2fa, backup codes, basically just as good as best. Google is only eliminating #1, and only requires 2fa when logging into a new device. I’m surprised HN folks are having a tough time grasping this one, in general it’s pushing people (I’d guess 90% of people would never opt into anything more than a regular password, including the parent) into #2 above. Parent should do #4, but #2 is fine
- browningstreet 5y agoOh c'mon, even tech savvy people are just using email for email. For me, I have to consider 2FA, or in the case of my son, who doesn't want a phone, a Yubikey or similar. I don't want to live with the additional management and potential disaster of 2FA blocking his access to his email account, which is currently his gateway to university. At work I have 2FA, but there's a whole IT/IS team to manage and unblock things (which happens, co-workers get blocked out of their email accounts regularly). Personally, I'm hoping to convince my domain cohorts (family) to move to Protonmail or similar.
- ryandrake 5y ago> For me, I have to consider 2FA, or in the case of my son, who doesn't want a phone, a Yubikey or similar. I don't want to live with the additional management and potential disaster of 2FA blocking his access to his email account, which is currently his gateway to university. This is a good point: For many people, passwords are already too much of a hassle. 2FA is going to be just more hassle. I manage all the passwords for everyone in my family, because they just can't manage to remember theirs (even simple ones like hunter2), and they don't want to use a password manager themselves. I'm sure ours is not the only family in the world who does this. So, the burden falls on me to keep their passwords stored and secure, and tell it to them when they need it. Now add 2FA onto that pile and it's just going to be more of a hassle for me.
- handrous 5y ago> Why would 2FA of all things be the critical issue? Tech savvy people should understand and use hardware security keys at this point to be securing their cloud accounts in general. Yeah, sure, should be. Meanwhile I've yet to actually see one in the wild, in a 20 year career, aside from one that's used on a server I know of. Coworkers at small tech companies? Nope. Serious-business clients coming into the office? Don't see them busting out the USB stick and plugging it in to their laptops. Medium-sized tech companies? Nope. Hell, I'd hate it even worse than phone 2fa. I lose my actual keys all the damn time. 80% of all remote controls in our house are, at any given time, vanished to some other dimension, because I have kids. The last thing I need is another tiny, super-important physical thing to lose. The only reason a cell phone is a useful object to me, and not another annoying thing I can never find, is because of "Find My".