4 ms·
> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to
by usui 2y ago
> Advocate for apps and hardware keys all you want, don't dump on an extemely valuable technology, please. The worst possible situation would be for someone to "take your advice" and refuse to use any 2FA at all.
It was your interpretation that I advise people to not use any 2FA at all. I won't honor the request to not dump on SMS, as I am perfectly happy to dump on an "extremely valuable technology" on technical demerits, on the grounds of security while simultaneously acknowledging highly debatable, highly questionable positive merits on grounds of user-experience, which more often than not oppose each other. Why do you construct a single-faceted single-shot ability for us to evaluate SMS? It sucks and it also doesn't, and saying it sucks isn't going to entirely destroy its already-terrible reputation amongst technicals. I would much rather have a message sent to my email address since that is harder to lose than a text message or phone number, and it costs me far less per month.
- ajross 2y ago> It was your interpretation that I advise people to not use any 2FA at all. No, to be clear, it's the obvious interpretation of a non-expert user, which is why your advice is so dangerous. They don't have a yubikey, don't understand how the apps work, and are faced with a decision to either enable SMS 2FA or not. And you're telling them not to, so they won't. And we'll all suffer. Again, work the other side of the problem if this is important to you. Make the other solutions better and educate people about them. Don't tell them not to use something that might very well save their bank account.
- tialaramex 2y ago> They don't have a yubikey, don't understand how the apps work... But they almost certainly do have a phone, any vaguely modern phone is also a valid hardware credential - and given how much time people spend using a phone it might even be more practical for them. I would argue that the problem is we've made the inconvenience symbolic - people see me sign in at work (with a Yubico Security Key 2 typically) and assume that's some sort of get out or workaround rather than, in reality, the much more secure option that my employer was too cheap to provide. They intuit that the thing they're doing is annoying and takes more effort so logically it must be more secure not less, right ?
- ajross 2y agoOnce more, I'm not saying that SMS 2FA is the best choice. I'm saying it's a vastly better choice than "1FA", and that telling people not to use it is hurting and not helping.
- tialaramex 2y agoAs I stated above because it can cause people to believe they're doing the right thing when they aren't I am actualy not convinced it's necessarily better than nothing.