3 ms·
I chose not to use sendgrid (twilio) because they force their own 2nd factor auth app, instead of allowing to use literally any of the ones already out there.
by orangepanda 4y ago
I chose not to use sendgrid (twilio) because they force their own 2nd factor auth app, instead of allowing to use literally any of the ones already out there.
Anecdotal, but still
- thebigspacefuck 4y agoWhat do you use instead?
- tracker1 4y agoThere are standards for 2FA (OTP) codes... "Google Auth" being one, but the same generators are available inside both LastPass and BitWarden, for contrast. The Microsoft authenticator is another annoying variation imo. While other techniques and applications might be (somewhat) more secure, the loss of ability to use the same application you already have/use for 2FA is a pretty big annoyance for a lot of people. I have my 2FA in bitwarden myself... with a pretty long passphrase that I don't use for anything else. It's the master key to the kingdom. There are many sites that I keep with the sms/email codes simply because they either don't offer typical OTP as an option.
- thebigspacefuck 4y agoSorry, I meant what do you use instead of Sendgrid?
- tracker1 4y agoSorry, my bad... Mailgun is pretty popular as an alternative... there's also AWS SES, which some seem to like.
- kl4m 4y ago1 - Create a Twilio account. 2 - You need to add a phone number and receive a SMS challenge, before setting up any other 2FA method 3 - With the Authy app installed on your phone, the token is instead instantly added to your account upon reception of the SMS. This cannot be disabled. Use a very particular combination of steps in the account settings to convince it to let you use a simple offline TOTP app instead. 4 - Use your recovery code every month and repeat the whole thing because somehow all other 2FA methods break simultaneously for all Twilio accounts set up with that phone number. The experience was so awful I had to delete the App and the account.
- rsync 4y agoAgreed. Their process is ridiculous and is matched only by the insane password requirements that they recently implemented (I think they required a 18 character password ? Or 24 ?) However, I am entwined in their ecosystem for all of my texting and calling and message management, etc., so I am forced to deal with it. In fact, their clownish requirements were the impetus behind the 2FA Mule[1] experiment which I now use across almost all services. [1] https://kozubik.com/items/2famule/ https://kozubik.com/items/2famule/
- ehPReth 4y agoIt seems to me like they bought Authy for $waytoomuch and are now too egotistical to allow things like security keys :/