Live data from Hacker News

The bleak picture of two-factor authentication adoption in the wild

elie.net

1–10 of 96 posts

Re: The bleak picture of two-factor authentication adoption in the wild

#2
I was having an argument over 1password's 2fa support not being a second factor. (I don't think it is.) However, it is so much safer than not using 2fa. In similar terms U2F is amazing and keeps you from being phished and has a great challenge/response protocol, if that was implemented in 1password (or browsers themselves thank you!) we'd all be a lot safer than not using it at all.

In 2018 I'm using an app to take screenshots of QR codes to generate one time codes. It's a sad state of the art, we need to do better.

Re: The bleak picture of two-factor authentication adoption in the wild

#3
It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account).

Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known attack vector.

Re: The bleak picture of two-factor authentication adoption in the wild

#4
post #3

It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…

My bank did that, maybe a decade ago. It was pretty inconvenient any time I wanted to access my bank account away from home. SMS is a godsend by comparison.

Re: The bleak picture of two-factor authentication adoption in the wild

#5
post #3

It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Re: The bleak picture of two-factor authentication adoption in the wild

#6
For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.

Re: The bleak picture of two-factor authentication adoption in the wild

#7
post #5
post #3

It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Google authentication is great, until it's time to get a new phone.

Re: The bleak picture of two-factor authentication adoption in the wild

#8
post #5

Earlier quoted context omitted.

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Google authentication is great, until it's time to get a new phone.

I store my totp secrets in keepass with everything else and synchronise it to my other devices.

This probably undermines the idea - but phones get lost/destroyed/wiped regularly.

Re: The bleak picture of two-factor authentication adoption in the wild

#9

For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.

2FA is nice when you're working across devices - I.e. using a public PC but have your phone on you.

Re: The bleak picture of two-factor authentication adoption in the wild

#10
post #5

Earlier quoted context omitted.

The thing that is nutty is.. they PAY MONEY for the SMS method! I do not understand why more sites don't support TOTP like Google Authenticator.

Google authentication is great, until it's time to get a new phone.

Check out Authenticator Plus - its another TOTP app that lets you backup your (encypted) 2FA secrets and optionally syncs them across devices.

Thankfully Google Authenticator is just TOTP, so you can use whatever client you want.

Post reply on HN