5 ms·
Enabling two-factor can help, but if you are the victim of a phishing attack as many are, one would expect one of the largest tech companies on the planet to ha
by agentdrtran 5y ago
Enabling two-factor can help, but if you are the victim of a phishing attack as many are, one would expect one of the largest tech companies on the planet to have a plan for that.
- tluyben2 5y agoThis will only get worse. Most people have no clue what mfa is and when I tell them they find it incredibly annoying and/or forgot how it worked again when they login from somewhere else a month later. I had people deleting Google authenticator or Authy from their phone because they forgot what it was for and their phone was getting slow…
- mitchdoogle 5y agoIt's crazy that the onus is on individuals, who, as you point out, are often ignorant about online security practices. Put the onus for security on the businesses who safeguard information, and they will have a big incentive to force users to use more secure methods of logging in, they will do more verification for account changes, etc. End users won't have any excuse for not using MFA when they can't do anything without it.
- tluyben2 5y agoAgreed, and if people don't want to use 'difficult tools', they could swap it for privacy: do KYC for your email account. Then you, in this case, the business could freeze the accounts until you go through the motions of proving you are the owner. Tech savvy people can then stay 'private'. Amazon has a simple KYC form for when you lose your otp device (I lost access to my sms and forgot to change to phone based otps).
- agentdrtran 5y agoAgreed, companies forcing horrible 2fa implementations are turning people off to the idea of using it at all on their personal accounts (even when it's far less onerous)