Follow

So over "2FA" messages that are just coming back to you via the same channel you've already demonstrated control of. Isn't that still 1FA? (Click a "you've received a secure message" link in a text, which then asks you to enter the phone number wherefrom you already visited the link to begin with, so they can text you a verification code...)

@johns It's all dumb (2FA, passkeys, etc. security-theater-of-the-week) and site-specific random passwords are, and always have been, fine.

Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml