4 ms·
Feels like SMS 2FA logins have become the new norm for some reason.
by DustinBrett 3y ago
Feels like SMS 2FA logins have become the new norm for some reason.
- 70rd 3y agoAnyone tracking signup conversion will realize that phone numbers are autofilled whereas 2FA requires an installation for a greater number of users, leading to drop-off.
- mewpmewp2 3y ago2FA apps also require me to do many more actions as opposed to SMS as notification. Would be much better if there was some sort of nudge mechanism for phone to display the proper code.
- Loughla 3y agoMicrosoft does this. eBay also. And steam. Once you install the app, any time there is a sign in, you get a pop up on your phone. Yes/no button. Very convenient. Why don't more apps do that?
- rolobio 3y agoI disabled my eBay app login pop up because it would never come. My login would sit pending forever. Would much prefer TOTP, even if a little slower.
- fiddlerwoaroof 3y agoBecause, over the last five or ten years, MFA has been adopted as a best practice and it’s easier to check the box with SMS than to get all your users to install a TOTP app. (another example of “Best Practices” being actively harmful: people should use passkeys now)
- semiquaver 3y agoIn the past two years or so I’ve seen the floodgates open for un-opted-in email-based 2FA, usually tied with “known device” recognition. This is obviously more secure than SMS but I just wish it weren’t less convenient, especially on mobile (specifically talking about the iOS 2FA iMessage input method integration) By contrast I feel like SMS 2FA increasingly is not an option, or at least not the default. Almost no sites I interact with outside of big tech offer TOTP or FIDO2, which is a real shame.
- njovin 3y agoI don't see how email-based 2FA is more secure than SMS. With email, if an attacker gains access to my email account she can remotely de-auth my mobile device's email client, reset my password for service X, and sign in to service X without my knowledge (assuming I don't notice my email client has stopped working). With SMS, if they gain access to my email account, I at least get the notice of the attempted login via SMS and can take appropriate action.
- semiquaver 3y agoSMS is architecturally insecure. It’s been demonstrated time and time again that cellular providers cannot effectively prevent SIM-hijacking via social engineering and other means. Email isn’t perfect, but I believe that my account is much more resistant to takeover than my phone number is.
- robertoandred 3y agomacOS/iOS support autofilling 2FA codes received via email in addition to those received via Messages.
- semiquaver 3y agoYeah, but only if you use Mail.app. AFAIK there’s no api for third party apps like gmail to do so.
- 3y ago
- deleted 3y ago[deleted]