6 ms·
OP's problem sounds like failure to plan. If you are going to suspend your cell plan, you should probably check your authenticator works or have a backup option
by pnw 1y ago
OP's problem sounds like failure to plan. If you are going to suspend your cell plan, you should probably check your authenticator works or have a backup option before you travel to another country.
I don't know what the viable alternative is. Passkeys have just as many issues when phones are stolen, lost or broken. You cannot expect consumers to store recovery codes. I do agree support of TOTP authenticators would help savvy consumers, but probably still too complicated for seniors etc. Watching my elderly relatives with poor vision enter a TOTP code was quite instructive. The UI of Google Authenticator made no sense to them and they didn't understand why it kept changing and getting rejected. They were barely able to enter six numbers in a 30 second window.
- fullstop 1y ago> you should probably check your authenticator works or have a backup option before you travel to another country. They may sign you out automatically if you connect from a different country.
- coppsilgold 1y agoTD Authenticate does not require a network connection. I outright disabled network access for the app on my phone. Don't know how he got logged out but he almost certainly didn't check before leaving the country. Having said that, the 2FA for TD is atrocious as it provides SMS fallback in addition to their bespoke app.
- Zak 1y agoA viable alternative is to offer multiple 2FA options, one of which should be RFC 6238 TOTP. The author would have probably planned ahead by selecting that rather than a proprietary app or SMS.
- nmca 1y agohardware tokens are the way! Everyone has had a house key their whole lives, and understands how to keep a spare to prevent lock-outs.
- Muromec 1y agoIf only there was some kind of a physical tokem with a crypto key that is protected by a password and tied to one's bank account. -s
- craftkiller 1y agoThe only bit we're lacking is the "tied to one's bank account". The rest already exists in the form of yubikeys and other hardware security tokens.
- FateOfNations 1y agoYour bank/credit/debit/etc. card is a “physical token with a crypto key that is protected by a password and tied to one's bank account”. FIDO and EMV even both use the same underlying ISO/IEC 7816 and 14443 protocols for communications.
- craftkiller 1y agoAh! I forgot about my debit card. I only use it ~once per month. Yeah, we'd need an additional piece of hardware to be able to connect it to our computers but that also could enable doing chip-based transactions over the internet so I think it would absolutely be worth it.
- pasttense01 1y agoSome of us don't want to have a dozen plus separate physical tokens (one for each of bank/credit card/tax, etc sites with sensitive financial information we have).
- Muromec 1y agoOkay, I will make the "S" mark bigger next time.
- mixmastamyk 1y agoNot how it works. One key can keep dozens of entries.
- saltcured 1y agoOne thing I like about the Aegis authenticator app is the clear way it changes colors and even flashes to indicate a code is getting ready to change, so it is less common that you might start copying digits, glance away, and then finish copying digits from a different code. But, I think it would still be a challenge for many elderly for other reasons.