7 ms·
I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones de
by megraf 4y ago
I don't have the same view, in my mind you have created a single point of failure for _yourself_. I use Authy for MFA, which comes with a desktop app. Phones dead / missing? No problem, I can get OTP's from my laptop.
What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my life easier.
- noSyncCloud 4y ago>Google Voice Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.
- Spooky23 4y agoYup. Chase does the same thing. They blackhole SMS to Google voice.
- mindslight 4y agoYet another push to get a better bank, in addition to all their ridiculous fees. Ally blackholes Gvoice (messages just disappear), but gives you an email option to login. When calling customer service, they can do the challenge with a phone call rather than SMS. Capital One, Discover, and Alliant all seem to accept Gvoice just fine. There of course is a major problem that Gvoice seems to be special, in that many places will accept Gvoice but not standards-based VOIP competitors. I even had a problem with someone on "Comcast mobile" not being able to text a Voip.ms number of mine.
- 1123581321 4y agoProbably Comcast Voice. Comcast/Xfinity Mobile is a Verizon MVNO
- Spooky23 4y agoOh agreed, Chase is an awful bank in any dimension. I use a credit union for most things. Chase owns the Amazon card, and 5% rebates on Amazon are worth dealing with the drama.
- withinboredom 4y agoSame with USAA. This is pretty recent though.
- unethical_ban 4y agoUSAA's "Cybercode" logon options are god-awful. It's Symantec VIP wrapped in their mobile app. I have no idea why generic TOTP with backup codes is not an option for every site on the planet.
- thesuitonym 4y agoMany companies, not just financial are the same. They usually fail silently, too, so you sit around wondering if the text ever sent.
- vladvasiliu 4y agoThe issue is that some services insist on using their own app as a second factor. You can't choose to use a superior U2F YubiKey, for example. You are also not allowed to have their shitty app installed on multiple phones at the same time. If you lose your phone, you need to call them up to reset this. To name and shame: BNP Paribas, one of the biggest banks in France.
- Double_a_92 4y ago> you need to call them up to reset this My bank sent me a super key (some colorful QR code) to setup new 2FA devices, which I need to securely store somewhere.
- cube00 4y agoIt's interesting that a super key even exists. Normally the enrolment QR codes are one time use only.
- gunapologist99 4y agoThis is incorrect. A standard TOTP QR code can be used on multiple devices or saved and printed (and stored in a safe or something). There is no expiration date encoded in the QR; it is simply the shared secret for the TOTP app to use and some extra metadata like labels. See https://www.rfc-editor.org/rfc/rfc6238 https://www.rfc-editor.org/rfc/rfc6238 It is a good idea to enroll multiple devices as a backup against failure, or to store it somewhere safe.
- NohatCoder 4y agoSure, blame the user, that is the mature response whenever someone is pointing out that modern ID security is a topple tower. Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account can get closed for spurious reasons.
- Dr_ReD 4y agoEspecially when the user is a senior or a minor, blaming the user is not really the solution.
- megraf 4y ago>"Sure, blame the user, that is the mature response..." We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP. I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.
- agileAlligator 4y agoWhen you acknowledge that there is a problem in the system and have solved it by way of a third party application, why do you still place the blame on the user for not solving the problem the same way you did instead of the system for having holes in it
- 888666 4y agoHow does providing information have anything to do with placing blame?
- agileAlligator 4y ago> in my mind you have created a single point of failure for _yourself_ You are offloading decisions to the consumer, decisions that the consumer shouldn't have to take. They should be solved by systems design already.
- BLKNSLVR 4y agoTIL Authy has a desktop app. Thank you friend, said app will be somehow added to my setup and workflow as another option.
- auslegung 4y agoCan you get OTPs on Google voice? Last I read (years ago) they said don’t do that because some won’t support it
- knaik94 4y agoSome of the financial services I use do, some don't. Things like discord don't either which is also annoying.
- deleted 4y ago[deleted]
- canadianwriter 4y ago"I use Authy for MFA, which comes with a desktop app" Fantastic. A lot of banks (at least here in Canada) ONLY have text or phone call for 2FA (which is awful, but welcome to banking).
- newscracker 4y ago> in my mind you have created a single point of failure for _yourself_. I use Authy for MFA Since Authy requires an SMS verification for setup, now you’ve made yourself vulnerable to SIM jacking. A better approach would be to use a TOTP generator that doesn’t verify you by SMS. In general, there’s no point in people dissing SMS OTP as insecure and at the same time adopting a service that uses it.
- unethical_ban 4y agoSome of the most important things to secure, namely many banks, both * mandate MFA * use proprietary and/or insecure phone-based mechanisms I agree with all my heart that TOTP with backups is ideal. I discovered Authy a few months ago, and only because of that app did I enable 2FA on Amazon, Discord, AWS, and a number of other sites that offered it. Ask me how many of the six banking and investment apps I use support generic TOTP.