3 ms·
What I hate the most is forced 2fa. Even if you disable 2fa, "ooops you logged in from a slightly different IP address. go check your email, sucker ;)"
by vadfa 5y ago
What I hate the most is forced 2fa. Even if you disable 2fa, "ooops you logged in from a slightly different IP address. go check your email, sucker ;)"
- sattoshi 5y ago2FA is a good idea. But it makes makes me nearly lose it when a phone number is required and they refuse to accept VOIP numbers. Looking at you, Doordash, Discord, Twitter, etc
- vadfa 5y ago2fa is a good idea. Still, I think it should be my choice whether I use it or not. If I want to have an account that I can always log in just with my user and password, that should be possible.
- hakfoo 5y agoI'd be happier with 2FA everywhere if it wasn't always tied to a mobile phone, whether it's app based or SMS. I don't want too much of my life dependent on a mid-line device manufactured by the Umidigi corporation. If it decides to go spicy-pillow tomorrow, or I just decide I want a new shiny device, I know it's going to be a full day of dancing around with IT support at work to get the work-related 2FA reset alone. SMS-based 2FA might be better from that UX perspective but it's vulnerable and basically seems like a vector for everyone to have an excuse to demand your mobile number which they totally won't use for marketing reasons later. If the account security is important enough, you can afford to buy me a Yubikey. I also feel like there's opportunities to rethink account management in general. There are a lot of accounts where you access them so erratically that there's good odds you'll hit "password expired, must reset now" or "this was set up back when I was on a different device and the 2FA didn't carry over." I'd love to see more sites using the "we'll send you a one-time login link" pattern. This leverages the security of the email account, which is more likely to be kept fresh because you actually use it. Carried to its logical conclusion, you could have accounts with no password on file, which reduces the value of the database for credential-reuse attacks.
- egberts1 5y agoFacebook too, it’s how I lost my 12-yo Facebook account due to VoIP phone number. Still no available recourse to get it back.
- ThePowerOfFuet 5y agoThe best user tracking method is a real phone number.
- Nextgrid 5y agoI suspect there might be a malicious reason for that: to dissuade you from using private browsing or clearing cookies.