I'm 100% in favor of 2fa, but use a standard system that allows for my password manager to solve it. Don't send me a SMS or require you custom goofy app.

@grumpygamer email 2FA should work better than SMS, but password manager TOTP would just make it "security fiction" for what it's worth.

flameeyes.blog/2021/11/30/2fa-

@flameeyes @grumpygamer I always get very sad when people save their second factor back to the first factor for convenience. This is the digital form of PINs written on the magnetic stripe cards. 😉

@grumpygamer @flameeyes @ASCIInaut

But that’s only true if the password manager is compromised. If the password manager is safe, but the password is compromised another way, then the additional factor in the password manager still protects the account.

@f1337 @grumpygamer @ASCIInaut covered it in the post as well. Email 2FA scales better for that and it's easier to reason around.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml