290
submitted 11 months ago by throws_lemy@lemmy.nz to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] KairuByte@lemmy.dbzer0.com 14 points 11 months ago

As long as that factor is auth app based, and not email/text/call/proprietary app I’m all in. If I need to go digging for the second factor for 5 minutes, I’m almost always going to turn it off. Texts emails and calls all get delayed regularly, and it’s super fun to have to sit with my thumb up my ass waiting 10 minutes for an OTP that was good for 5.

[-] stealth_cookies@lemmy.ca 5 points 11 months ago

Ideally they also support a hardware key. Not nearly enough websites out there support FIDO/Webauthn.

[-] 1984@lemmy.today 5 points 11 months ago

I think for email it's essential, it's critical that someone doesn't make it into your email. Otherwise they can reset all your other passwords.

I have mfa on my account but I just click a checkbox after first time to not ask again. I'm still protected by it and don't have to do anything until I clear my cookies (which I don't for email).

[-] Scolding7300@lemmy.world 2 points 11 months ago* (last edited 11 months ago)

I think they're thinking of TOTP noy being the standard, where you'd just pull out your totp app and paste it without waiting

[-] KairuByte@lemmy.dbzer0.com 2 points 11 months ago

Precisely, my brain just completely forgot the term for it and after minutes of not being able to remember for the list of my I just loosely described it. TOTP is exactly what I meant.

[-] HubertManne@kbin.social 1 points 11 months ago

I wish more were like azure where you can get a phone call and hit pound

[-] KairuByte@lemmy.dbzer0.com 3 points 11 months ago

That’s also a less secure version of 2fa. Granted, it is still better than nothing, but sim spoofing is still a thing that happens regularly. Making it much less useful in a targeted attack.

[-] HubertManne@kbin.social 2 points 11 months ago

over texting or an app. because an app requires a smartphone.

[-] KairuByte@lemmy.dbzer0.com 2 points 11 months ago

A smartphone is infinitely more secure than relying on a SIM card not being compromised. A little social engineering can get you access to receive a text as the link isn’t even controlled by you but a third party. An app on your phone is likely secured by a pin/biometric, and a password/pin/biometric, both controlled by you.

[-] HubertManne@kbin.social 2 points 11 months ago

yup. if you have or care to have a smartphone. having a smartphone or even a cell phone should not be some sort of requirement live in society.

[-] KairuByte@lemmy.dbzer0.com 0 points 11 months ago* (last edited 11 months ago)

Oh cmon, you can get a smartphone literally for free these days. And yes, having a cell phone of some type is pretty much a requirement to live in the 23rd century. Even if you are just communicating over free McDonalds wifi (no shame, been there done that) you pretty much need a smart phone in the modern world.

[-] bobo@lemmy.world 2 points 11 months ago
[-] KairuByte@lemmy.dbzer0.com 2 points 11 months ago

Whoops, lmao. Obviously I meant the 21st century. Definitely not a time traveler.

[-] bobo@lemmy.world 1 points 11 months ago

Too bad. I was hoping to get some hot stock tips.

[-] HubertManne@kbin.social 2 points 11 months ago

its not the cost. I hate them. I use my laptop on wifi.

[-] Akuchimoya@startrek.website 1 points 11 months ago

One time I had to use a website where the email 2FA expired in 30 seconds! I usually keep my email client open while my computer is on, but, come on, that was ridiculous.

this post was submitted on 18 Jan 2024
290 points (100.0% liked)

Technology

60012 readers
1702 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS