@azonenberg @ireneista @stringlapse @glyph @steadilyebbing @xssfox It's never helpful to the consumer. It's helpful to the site owner's CYA.
Conversation
Notices
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Thursday, 08-May-2025 19:28:09 JST Rich Felker
-
Embed this notice
Andrew Zonenberg (azonenberg@ioc.exchange)'s status on Thursday, 08-May-2025 19:28:10 JST Andrew Zonenberg
@ireneista @stringlapse @glyph @steadilyebbing @xssfox (also, i can't stand when sites only let you enroll one TOTP authenticator. Bonus points if it's something that is absolutely not sensitive enough to need 2fa or that does not let me not use 2fa.
I generally avoid 2fa when I don't have to use it because I'm using strong per-site passwords and it just adds another layer of hassle. If you can steal my 16-character random alphanumeric password you've probably already RCE'd my endpoint or the server, and 2fa won't stop you. I mostly see it as a defense against password reuse which... i guess is probably helpful for the average consumer, maybe?
-
Embed this notice