For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.
2FA is nice when you're working across devices - I.e. using a public PC but have your phone on you.
The bleak picture of two-factor authentication adoption in the wild
11–20 of 96 posts
Re: The bleak picture of two-factor authentication adoption in the wild
#12Earlier quoted context omitted.
Google authentication is great, until it's time to get a new phone.
Check out Authenticator Plus - its another TOTP app that lets you backup your (encypted) 2FA secrets and optionally syncs them across devices. Thankfully Google Authenticator is just TOTP, so you can use whatever client you want.
Re: The bleak picture of two-factor authentication adoption in the wild
#13Re: The bleak picture of two-factor authentication adoption in the wild
#14For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.
We can handle good passwords. But our customers deserve for our database, admin tools, etc to require the more comprehensive authentication.
I'm not going to make our customers use 2FA, but we do require it internally now. We can handle it.
Re: The bleak picture of two-factor authentication adoption in the wild
#15It completely blows my mind that blizzard got it right over a decade ago with a dedicated physical device that would generate a one-time, time sensitive key for second factor authentication (to protect my video game account). Where as I feel I'm still waiting for my bank (actual money) to catch up. they took the easy way out by sms-ing me a second factor authentication key. Even though phone number theft is a known a…
My bank did that, maybe a decade ago. It was pretty inconvenient any time I wanted to access my bank account away from home. SMS is a godsend by comparison.
Re: The bleak picture of two-factor authentication adoption in the wild
#16Interesting write up here: https://wunderwuzzi23.github.io/blog/passthecookie.html
I have seen this being used by red teams, not sure about real malware.
Re: The bleak picture of two-factor authentication adoption in the wild
#172FA is a user interface disaster, exporting the failures of software security as a huge annoyance on to users. I would rather be hacked than deal with 2FA.
All that's really needed is for browser vendors to improve their UI for generating certificate signing requests and importing certificates.
Re: The bleak picture of two-factor authentication adoption in the wild
#18For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.
2FA is nice when you're working across devices - I.e. using a public PC but have your phone on you.
Re: The bleak picture of two-factor authentication adoption in the wild
#19I was having an argument over 1password's 2fa support not being a second factor. (I don't think it is.) However, it is so much safer than not using 2fa. In similar terms U2F is amazing and keeps you from being phished and has a great challenge/response protocol, if that was implemented in 1password (or browsers themselves thank you!) we'd all be a lot safer than not using it at all. In 2018 I'm using an app to take s…
If your master password is someone exposed, then nothing really protects you.
Re: The bleak picture of two-factor authentication adoption in the wild
#20For those among us who can handle our passwords and general security, 2FA is just a penalty we have to pay for those who can't. As far as possible, I ditch any company that wants to force it upon me. I've done my homework, I don't want to consult my telephone, my mailbox, or even worse, some pesky dongle to complicate my life and add to my expenses.