Earlier quoted context omitted.
>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.
I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.
A future without passwords
81–90 of 227 posts
Re: A future without passwords
#82Why don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.
There's Firefox Lockwise: http://lockwise.firefox.com Firefox also introduced a feature that offers to generate a secure password when it detects a sign-up page.
Re: A future without passwords
#83Re: A future without passwords
#84The thing I like about the password is that it does not involve any additional technology dependencies. GitHub is going down this road, too, announcing that they will soon disallow password-based auth on git operations. I'm not sure if I will keep using it after that, because having to log into the website from every workstation, some of which may not even have a browser "good enough" for github.com, is more extra wo…
Can you still use ssh keys? I haven’t used http for git in years. I store the SSH key’s password in the keychain and then I’m good to go.
Re: A future without passwords
#85https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.
Seems like they prefer google prompt, then SMS, then the actually secure stuff.
Re: A future without passwords
#86Earlier quoted context omitted.
> companies want to get rid of one of the factors This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow. > So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Unsu…
> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabl…
I can use biometrics/sms for the less important stuff.
Re: A future without passwords
#87Re: A future without passwords
#88Earlier quoted context omitted.
>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.
> they apparently know how to secure my account better than I do This is definitely true for 99% of people though
"Trust us."
Yet no company wants more personal information from you than this one. They want everything. Even when they have so much, they are going to great lengths to get more.
They are not in the security business, they are in the online ad sales business.
Re: A future without passwords
#89Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…
>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.
Some bullshit with Windows Hello, I'm sure, since using a hardware key in the browser triggers it.
Re: A future without passwords
#90Earlier quoted context omitted.
I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.
docs, drive and photos are pretty packed for me at least