21 ms·
> 2fa is a scam in part to force them to give up more data and in part to try to force people to use a government tracking device. Just remember this is Micros
by mataug 4y ago
> 2fa is a scam in part to force them to give up more data and in part to try to force people to use a government tracking device. Just remember this is Microsoft behind this.
How is 2FA a scam ?
Nowhere in the article is a phone number mentioned which is the only potential "government tracking device". The second factor can be an authenticator app, or even a FIDO device
- Am4TIfIsER0ppos 4y agoSometime in the not so distant future > Those old yubikeys [or similar HW device] have a flaw and are weak so we [read: the government] are deprecating them. You can change them here for the next year or use your phone or install our app. Further in the future after a few cycles of the above > Too few people use HW tokens so boot up your spy device now to log in. Maybe it won't be HW flaws maybe it will be software. Maybe they'll mandate use of some chrome only feature. Maybe they bring out the Xbox authentication drink cans.
- dane-pgp 4y agoWhen we all have Neuralink chips in our brains, they will be able to read the data from our taste buds to check that we are really drinking a genuine can of Doritos™ Mountain Dew™.
- hqball 4y agoThen I have to trust an app (which can have vulnerabilities) or a USB device which can be exchanged for a BAD-USB exploit carrier. That looks like offloading security issues to the user. Sounds far fetched? If the code repositories are that valuable, why wouldn't state actors try to mess with the hardware and commit underhanded C or similar? The repository owners would detect the malicious commit? Well, in that case, why do we need 2FA in the first place?