4 ms·
2fa is a good idea. Still, I think it should be my choice whether I use it or not. If I want to have an account that I can always log in just with my user and p
by vadfa 5y ago
2fa is a good idea. Still, I think it should be my choice whether I use it or not. If I want to have an account that I can always log in just with my user and password, that should be possible.
- hakfoo 5y agoI'd be happier with 2FA everywhere if it wasn't always tied to a mobile phone, whether it's app based or SMS. I don't want too much of my life dependent on a mid-line device manufactured by the Umidigi corporation. If it decides to go spicy-pillow tomorrow, or I just decide I want a new shiny device, I know it's going to be a full day of dancing around with IT support at work to get the work-related 2FA reset alone. SMS-based 2FA might be better from that UX perspective but it's vulnerable and basically seems like a vector for everyone to have an excuse to demand your mobile number which they totally won't use for marketing reasons later. If the account security is important enough, you can afford to buy me a Yubikey. I also feel like there's opportunities to rethink account management in general. There are a lot of accounts where you access them so erratically that there's good odds you'll hit "password expired, must reset now" or "this was set up back when I was on a different device and the 2FA didn't carry over." I'd love to see more sites using the "we'll send you a one-time login link" pattern. This leverages the security of the email account, which is more likely to be kept fresh because you actually use it. Carried to its logical conclusion, you could have accounts with no password on file, which reduces the value of the database for credential-reuse attacks.