381
submitted 10 months ago* (last edited 10 months ago) by [email protected] to c/[email protected]

I personally am fine with this.

top 50 comments
sorted by: hot top controversial new old
[-] [email protected] 114 points 10 months ago* (last edited 10 months ago)

Yep, should be standard everywhere

..... for accounts you actually give a shit about

[-] [email protected] 39 points 10 months ago

And not via SMS

[-] [email protected] 30 points 10 months ago

And not the twitch way, where you have to have in an identifier, your phone number, but using proper, standards ways for it, like TOTP and such

[-] [email protected] 4 points 10 months ago
[-] [email protected] 17 points 10 months ago

But you can only enable it, after you give them your phone number.

Also, apparently years of subscribing to channels is not as verified as giving them your phone number. They should just say "We really want your phone number and don’t give a shit about anything else".

load more comments (5 replies)
[-] [email protected] 5 points 10 months ago* (last edited 10 months ago)

As the other commenter said, only if you give them your phone number, and only through that garbage authy that does not use standard TOTP, but some proprietary crap, specifically made for twitch.

And if you give them a phone number, which another user will also try to use in the future, then the secret used for TOTP can change in any moment, which means if you exported the secret to e.g. Aegis and deleted that tracking filled garbage that is named authy, at one point the codes just won't work anymore, and you're practically locked out. Apparently support should be able to help, but they don't give a single fuck.

[-] [email protected] 4 points 10 months ago

and only through that garbage authy

you can use any TOTP app. I use bitwarden

load more comments (8 replies)
load more comments (2 replies)
[-] [email protected] 25 points 10 months ago* (last edited 10 months ago)

emphasis on the

… for accounts you actually give a shit about

[-] [email protected] 4 points 10 months ago

I foresee hardware tokens becoming more of a thing - also Passkeys (they’re so easy to use!). I do wonder if we’ll have more of a formal process to either backup or have “ownership” of our cloud accounts as they become even more intertwined with our lives.

For example: iCloud Keychain is so easy to use, but what happens to your Passkeys if the account gets frozen? Currently, I don’t think there’s a way to extract the private keys (?).

[-] [email protected] 5 points 10 months ago

Just FYI, your account shows up as a bot. You should change it in your account settings.

load more comments (1 replies)
load more comments (6 replies)
[-] [email protected] 36 points 10 months ago

While you are adding this anyway consider using an open source app instead of google auth like aegis. There are many others but I wish I knew about them sooner.

[-] [email protected] 7 points 10 months ago

I personally love keeweb. Passwords and 2fa all in one place.

I mean you could argue that defeats the purpose of having 2fa, but it's convenient

load more comments (2 replies)
load more comments (3 replies)
[-] [email protected] 32 points 10 months ago

What was wrong with allowing people to make a choice? Personally I have an account I don't give two shits about, but currently it is also the one I use more often. I don't want to pull out my phone each time I have to login..

[-] [email protected] 50 points 10 months ago

Too many people were making poor choices. When there's an incident of an account that should have been secured but wasn't getting compromised, that's bad for the platform, ecosystem, and community. This is just another level beyond not allowing you to set a password of "password"

[-] [email protected] 7 points 10 months ago

Yep. If people care about supply chain attacks or so, just add features that allow only commits from accounts with 2FA to certain repositories.

[-] [email protected] 5 points 10 months ago

At least you should be able to use your local password manager as well if you don't care about keeping your 2fa on separate hardware. KeePass 2, KeePassXC, Bitwarden, ...

load more comments (1 replies)
load more comments (14 replies)
[-] [email protected] 23 points 10 months ago

Good, people are fucking stupid and if it effects others it's often better to choose the security for them!

[-] [email protected] 10 points 10 months ago

Yup. I'm actually a bit baffled by how much negativity/misinformation there's around 2FA even in a place like this, which should naturally have a more technically inclined userbase.

[-] [email protected] 6 points 10 months ago

Well negativity is there because every app wants it.

I don't care if account x is compronised, as it has absolutly no value

[-] [email protected] 5 points 10 months ago* (last edited 10 months ago)

I dislike MFA because it creates a risk of losing access to my account. I can back up my passwords; I can't back up a hardware device.

load more comments (7 replies)
[-] [email protected] 13 points 10 months ago

2fa should be mandatory everywhere

[-] [email protected] 16 points 10 months ago

Hard disagree. I do not want to have 2FA for every shittly little thing I do not care about.

load more comments (1 replies)
load more comments (1 replies)
load more comments
view more: next ›
this post was submitted on 22 Aug 2023
381 points (98.7% liked)

Technology

33582 readers
243 users here now

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

founded 5 years ago
MODERATORS