I really hate "two factor" auth. Like, cool, I get it, it let's you pretend you can divest responsibility for security and recovery, but also it means dropping my phone too hard could be a life disrupting event so somehow I don't really feel like this is for my benefit.
Conversation
Notices
-
Embed this notice
aeva (aeva@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 12:29:52 JST aeva
-
Embed this notice
aeva (aeva@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 12:29:50 JST aeva
anyways if someone wants to break into my github account and steal my open sources you've got about an hour give or take to break into my home and somehow steal this printout of recovery codes from the printer tray right next to me without me noticing you before I put it somewhere so safe I'll never find it again
Haelwenn /элвэн/ :triskell: likes this. -
Embed this notice
aeva (aeva@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 12:29:51 JST aeva
It takes a really special kind of mind to say that tying your ability to access your accounts to a tiny slippery fragile glass object that is designed to break every two years average so you buy a new one for the benefit of the shareholders is somehow a significant security improvement, but then again maybe this is as close as we'll ever get to a public admission that the bar really is that low.
-
Embed this notice
aeva (aeva@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 12:30:37 JST aeva
(please do not break into my home. I will make a lot of noise and wave my hands like I'm trying to chase off a bear and my wife will probably brain you with a pipe wrench if you don't leave)
Haelwenn /элвэн/ :triskell: likes this. -
Embed this notice
narcolepsy and alcoholism :flag: (hj@shigusegubu.club)'s status on Thursday, 26-Sep-2024 18:57:12 JST narcolepsy and alcoholism :flag:
@aeva @scherzog you know you can make backups of OTP keys and have recovery strings as well, right? -
Embed this notice
aeva (aeva@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 18:57:13 JST aeva
@scherzog what's cool about my house keys is there's more than one set of them in the whole world, and so if I lose mine I'm not like well fuck I guess I don't have a house now
-
Embed this notice
Scherzog von Beast Oil (scherzog@mastodon.gamedev.place)'s status on Thursday, 26-Sep-2024 18:57:14 JST Scherzog von Beast Oil
@aeva I'm slightly sad that I didn't really need 2FA (or even 1FA) during the time when said 2nd factor was commonly encased in a thick layer of silicone, had a tiny 7-segment display as its sole user interface and was about the same size as your house keys. And was usually kept on the same keyring as said house keys.
-
Embed this notice