Live data from Hacker News

Ask HN: Should HN Get 2FA?

news.ycombinator.com

11–13 of 13 posts

Re: Ask HN: Should HN Get 2FA?

#11
post #8

Earlier quoted context omitted.

If you do 2FA without recovery keys or a recovery eMail, you’re doing it wrong. Everything I have heard from you so far is draped with ignorance and misinformation.

recovery keys = "write down your password" which they've been telling us to not do for years recovery email/phone = same threat model as regular passwords, and it's a big crack, all the time somebody bribes somebody at a phone carrier to take over the phone number of a crypto whale Practically low-touch services are going to have to resort to these things, but they render 2FA performative. Now at work 2FA is OK becau…

Thank you for confirming my second sentence for me. Especially the first sentence of your response - “write down your password”. Wow. This is the worst possible take I can imagine.

Like, this isn’t the 1980s anymore, password managers exist - even local-only ones - that can keep both strong passwords and recovery keys totally safe. KeePass in particular can be synced using server-free methods, keeping everything on-device, strongly encrypted, and essentially offline.

I suggest you touch some grass and actually educate yourself. TOTP 2FA is a massive leap in security that brings the traditional username+password safely into the modern threat era. Provided that the password is long+strong and the username leverages dot extensions in the eMail (if an eMail) or is a totally unique username (if only a text string), said three-point security can reliably exceed that of passkeys.

Re: Ask HN: Should HN Get 2FA?

#13
post #6

Dont exactly see the appeal of what someone with my login credentials would do on HN.

Doxxing. Posing as you, to get you fired or otherwise affect your reputation, especially if there is already a traceable connection to your meatworld persona. As a first step in a fraud scheme. To leverage social credibility to affect others. The options are varied, and are really only nerfed by obscurity of both the platform and your handle in terms of its doxxability.

This. It's baffling people shrug their shoulders or outright ignore the risks.
Post reply on HN