490
MFA grind (lemmy.nz)
you are viewing a single comment's thread
view the rest of the comments
[-] BassTurd@lemmy.world 37 points 1 year ago

Every time I read comments on posts like these, it reaffirms to me how the average person does not give a shit about real security or is completely ignorant to how and why these extra safeguards are used. Lemmy, I would assume, has a higher than average tech knowledge amongst it's user base vs many other platforms, but the sentiment often that of, MFA and needing to login to a bunch of separate applications is too much work and the people that designed them don't know what they're doing. It's a bit disheartening.

[-] lightsblinken@lemmy.world 26 points 1 year ago* (last edited 1 year ago)

nah, you can care about security and also lose hours on MFA. for global enterprise, the overall user experience is far from optimal imho.

[-] Pulptastic@midwest.social 7 points 1 year ago

Do I really need TFA for social media? Or a forum? News sites? Fucking weather? Financial logins I get, but every single site requiring it is a cumulative time and hassle burden that is not worth it.

[-] BassTurd@lemmy.world 4 points 1 year ago

I would say anytime where someone can impersonate you or make purchases as you deserves MFA. That's my risk tolerance, but it can differ obviously. I just feel that threshold is too low for a lot of people.

[-] AtariDump@lemmy.world 2 points 1 year ago* (last edited 1 year ago)

…for social media?

Where someone can impersonal you and scam people out of money? Yes. 2FA.

…Fucking weather?

I mean, I’m not here to kink shame but, probably? I’m partially wondering now what weather looks like when it fucks. Like a tornado in a sinkhole?

…every single site requiring it is a cumulative time and hassle burden that is not worth it.

It wouldn’t be necessary IF:

  1. People chose decent passwords that were different for every login
  2. Website security was taken seriously by anyone who has a login.
[-] creation7758@lemmy.ml 1 points 1 year ago

I don't mean to sound rude but why would you need an account just to check weather

[-] LaLuzDelSol@lemmy.world 2 points 1 year ago

At work I need multifactor for everything, but... ITS ALL THE SAME MICROSOFT ACCOUNT. We have SSO, but every single stupid webpage needs me to sign in separately with 2FA and forgets about me hours later. It's needlessly tedious.

[-] Duamerthrax@lemmy.world 1 points 1 year ago

I just use strong, unique passwords and be mindful when something is asking for my logins.

[-] BassTurd@lemmy.world 1 points 1 year ago

That should be the bare minimum for everyone, but it doesn't protect anything if a password is compromised, especially something like email that can lead to getting other passwords.

[-] Duamerthrax@lemmy.world 1 points 1 year ago

If your email is compromised, isn't 2FA also compromised?

[-] BassTurd@lemmy.world 2 points 1 year ago

I suppose in some cases, yea. I was thinking about authenticator apps as MFA and forgot about email. Ideally, all MFA would be through a separate authenticator. For stronger security, something like a ubikey or other hardware security device can be used.

[-] Duamerthrax@lemmy.world 1 points 1 year ago

I don't even think I use websites that would use that. The only "app" like that is google using my phone for new logins. Every other 2fa uses my email. If it's not a google service, I'd prefer not to have to use an app because I treat my whole phone as insecure.

this post was submitted on 17 May 2025
490 points (95.2% liked)

Technology Memes

695 readers
1 users here now

Welcome to Technology Memes. Here you can make memes and/or rant about technology, internet, computers, corporations, enshittification and etc.

Rules:

  1. Stay on-topic.
  2. Don't attack and harras anyone. Be nice.
  3. No racism and discrimination.
  4. No politics unless they're related to tech.
  5. No spam, no ads.
  6. No NSFW.
  7. Don't repost.

Please report any posts and comments that violate these rules.

Related communities:

founded 2 years ago
MODERATORS