2 ms·
Definitely not more convenient for users in all cases. LinkedIn did something similar. When they told me to append my code to the end of my password and I click
by markcerqueira 12y ago
Definitely not more convenient for users in all cases. LinkedIn did something similar. When they told me to append my code to the end of my password and I click on the password field, my password would be wiped away so I'd have to type in my password AGAIN and then add the security token to the end of it.
You don't need a third field. On mobile, if you pass the password auth, you go to a new screen and bring up a number pad and ask the user to wait for the text message. It's pretty smooth. Much smoother than the LinkedIn flow I described above. If you don't have 2-factor auth after passing the password auth, you just go right to the app.
I documented my frustrations here in case you want to see: http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication/ http://mark.gg/2013/07/17/linkedin-2.5-factor-authentication...
LinkedIn already fixed this, but it's quite shameful they even let this out into the wild. :/