If it's not something you can get it back by demanding it in real life you shouldn't put 2FA on it. A bank account will be given back for that reason. Accounts online are unrecoverable that way. Lemmy's 2FA was so bad that many people lost their accounts using it.
post
Things that I have 2FA for for some reason:
- my abandoned Ubisoft account which holds two free games and doesn’t have any personal details about me
Things I don’t have 2FA for, although I’d probably prefer if I could have:
- my bank account
This, but specifically because of Microsoft Authenticator. I hate this app so damn much. [I'm forced to use it] not with TOTP tokens, but push-notification based ones which arrive only sometimes and are slow. And then it's mocking me saying "pull to refresh if you don't see a notification", but there is no pull to refresh feature. Oh and Microsoft Azure Portal? It asks you to authenticate twice in a row, just to be sure. Burn burn burn
I tried MS Authenticator after creating a business account with me as the admin, and it let me enroll and then immediately gave me a device untrusted error (I'm rooted, sue me, but there's no warning or way to tell that's not allowed) which then login-looped every recovery option to try to re-enroll or remove the 2FA, requiring me to file a ticket and manually prove who I am which took 48-hours.
Just the fact that they let me sign up before pulling the rug and revoking access with a hidden, time-bomb fail condition, really impressed me. It takes work to be that evil.
Some companies let you use TOTP instead of the app, look in the dashboard and select the verification mode that gives you the qr code
That sounds horrible. I hate that steam requires me to use their app instead of the authenticator app I use for everything else but at least it works every time
I feel this. And the endless fucking prompt to log in. Several times a day. Everywhere. We should bill Microsoft for the time lost.
Only for its "cloud saves" to suddenly forget everything after switching devices 🤦♀️️ I'd upvote 3 times if i could
I would rather have 2fa than the magic link email bullshit. I am so fucking tired of sites assuming I don't want to use a simple username and password, and I clearly want to have to wait on email delivery to be able to access my account instead of JUST ENTERING MY GODS DAMNED CREDENTIALS.
There is an app on my phone that, after every update (and sometimes just because it's bored) logs me out. When I log back in, it opens a browser to request a username, a password, and a random number that it emails me. The number is not in the subject line of the email, so I have to switch to my inbox to get the number.
Unfortunately, half the time when I open the email, when I switch back to the web browser number form has forgotten that it's a text field and so won't open my keyboard. I haven't yet figured out a way to fix this, other than waiting a few hours then trying again. If I force close and try again immediately, the same issue occurs.
also not everything needs email
just username + password is enough usually
For some reason I read it as “I lost the love of my life to two factor authentication” and really wanted to hear how that was possible.
Long distance relationship, locked out of email, can't remember their email address 🥀
heyy cutie, can I get your number? can you give me the code i sent to your phone number, hot stuff? you're adorbs, is this still a good email to reach you with?
Just use Keepass, it lets you store your passwords and totp in an encrypted database file you can move around just like any other file. Just make sure you make a backup when ever you add new credentials.
If I store your password and totp in one app it's not 2fa, there's literally no reason to setup both then
Sounds like it solves OPs problem then.
Well yeah, if their problem is the security of their accounts, that solves it
Keepass is pretty well respected by security experts. Often more than other password managers such as bitwarden. Though of course bitwarden is recommended as well.
It’s a file that is not stored online so hackers cannot access it unless they’ve already compromised your personal system, even then it’s encrypted so they would also need to capture your keepass password as well.
I store 2FA in the same place I store my password, I just need to copy one, then the other. I may have lost hours or even days to 2FA, the same amount I lose by having to authenticate with a password
SoCal Edison just enabled 2fa? To protect what, exactly? Someone hack my account and pay my bill!
My utility account shows power use by 15 minute intervals. Technically someone could use that as a way of figuring out when people are home or away if you have a regular life schedule. Seems like a farfetched concern though.
Always had the same reaction to requiring a PIN to refund a transaction on an EFTPOS machine. Someone wants to steal my card and put money on it that's cool, just stop them from taking it out and they can hold onto that card as long as they want.
I had one the other day. Enter passcode from Auth app. Ok done. Great. We just emailed you another code enter that now.
What really grinds my gears is when they require a password as well.
Why did you require a password when your going to bug me about 2fa anyways? Why did you require me to change said password every 3 months if you bug me about 2fa anyways? Why are you asking me to switch my password with your dumb restrictions (no special characters, really BofA?) when it has been recommended for years to not require users to do that since it just makes the passwords less unique in the long term?
2fa is fine, just remove passwords if your going to do it.
It’s not a second factor if you remove passwords, the password is the first factor.
otherwise yes absolutely, password recycling should be dropped as soon as 2fa is implemented.
That's what bugs me about passwordless. It's just 1fa again, except that the password is still there to sign in from other devices if you don't have a passkey set up yet, so now you have more than one attack vector.
I had a really fun one with my Google account the other day. It was the one where you had to select the number it was showing on "the other screen". However it was trying to show it on my same phone I was trying to log in on, only to immediately overwrite it with the prompt to select the correct number. Cue me sitting there having to guess the right number like 6 times before finally getting access, getting logged back out every time I failed to guess right
all 41 comments