We are tired of the risk that SMS 2FA brings. Most of us have gotten smart enough to not use it but some companies (financial institutions especially) only have SMS based 2FA even in 2022.
Then, there are some shady ones that force you to enter a phone number even for non SMS/TOTP based (looking at you sendgrid)
People losing access to their phone is a scenario and puts users at significant risk of losing access to key accounts. I am not even talking about the security risk SMS 2FA brings which of course it does.
The worst part is that even now, companies are implementing it as a "updated security measure". Who are these people in the tech. departments making these decisions ? It is beyond ridiculous and why can't there be someone who understands that this needs to stop. I know most common people have no idea but there are plenty of us who know what a pain in the ass this is.
Is it time to try and force a legislation through Congress because I don't think these companies give a shit until forced to.
Comments URL: https://news.ycombinator.com/item?id=33435682
Points: 10
# Comments: 9
Continue reading...
Then, there are some shady ones that force you to enter a phone number even for non SMS/TOTP based (looking at you sendgrid)
People losing access to their phone is a scenario and puts users at significant risk of losing access to key accounts. I am not even talking about the security risk SMS 2FA brings which of course it does.
The worst part is that even now, companies are implementing it as a "updated security measure". Who are these people in the tech. departments making these decisions ? It is beyond ridiculous and why can't there be someone who understands that this needs to stop. I know most common people have no idea but there are plenty of us who know what a pain in the ass this is.
Is it time to try and force a legislation through Congress because I don't think these companies give a shit until forced to.
Comments URL: https://news.ycombinator.com/item?id=33435682
Points: 10
# Comments: 9
Continue reading...