490
MFA grind (lemmy.nz)
top 50 comments
sorted by: hot top new old
[-] BassTurd@lemmy.world 37 points 1 year ago

Every time I read comments on posts like these, it reaffirms to me how the average person does not give a shit about real security or is completely ignorant to how and why these extra safeguards are used. Lemmy, I would assume, has a higher than average tech knowledge amongst it's user base vs many other platforms, but the sentiment often that of, MFA and needing to login to a bunch of separate applications is too much work and the people that designed them don't know what they're doing. It's a bit disheartening.

[-] lightsblinken@lemmy.world 26 points 1 year ago* (last edited 1 year ago)

nah, you can care about security and also lose hours on MFA. for global enterprise, the overall user experience is far from optimal imho.

[-] Pulptastic@midwest.social 7 points 1 year ago

Do I really need TFA for social media? Or a forum? News sites? Fucking weather? Financial logins I get, but every single site requiring it is a cumulative time and hassle burden that is not worth it.

[-] BassTurd@lemmy.world 4 points 1 year ago

I would say anytime where someone can impersonate you or make purchases as you deserves MFA. That's my risk tolerance, but it can differ obviously. I just feel that threshold is too low for a lot of people.

load more comments (2 replies)
load more comments (6 replies)
[-] neatchee@lemmy.world 25 points 1 year ago

A minor annoyance now to avoid a major headache later. Worth the trade

load more comments (17 replies)
[-] GreenKnight23@lemmy.world 21 points 1 year ago

got hired by a new company. every fucking day I have to MFA to use the VPN. then I have to MFA to sign into email. Then MFA into tickets. MFA into confluence. MFA into git.

and then I have to do it all over again 4 hours later after lunch.

[-] Evotech@lemmy.world 4 points 1 year ago
[-] GreenKnight23@lemmy.world 3 points 1 year ago

mid-size enterprise. my team has gone through 5 managers in 12 months.

they can't even with SSO right now lol

[-] Evotech@lemmy.world 2 points 1 year ago

It’s relatable

[-] ArtVandelay@lemmy.world 3 points 1 year ago

Same, but also add MFA to log into laptop.

load more comments (1 replies)
load more comments (3 replies)
[-] GissaMittJobb@lemmy.ml 16 points 1 year ago

The galaxy-brain move is to store the password in a password manager, and also have the same password manager store the TOTP. Finally, you set your password manager to unlock by biometric authentication

All of a sudden, you're set by just showing your fingerprint to the reader.

[-] nucleative@lemmy.world 15 points 1 year ago

Only downside is that you can more likely be compelled to give up biometric authentication than a password (as far as I understand)

[-] GissaMittJobb@lemmy.ml 6 points 1 year ago

This is a threat I'm not planning to handle.

[-] Opisek@lemmy.world 12 points 1 year ago* (last edited 1 year ago)
[-] asudox@lemmy.asudox.dev 4 points 1 year ago

Physical security keys to the rescue!

Break it when you're in danger.

[-] Charlxmagne@lemmy.world 3 points 1 year ago

Or just invest in some real, physical security using all the crypto you've got to prevent something like this happening in the first place, that way you've got both physical and digital security to protect u rather than js one like some jokeman.

load more comments (2 replies)
load more comments (1 replies)
[-] Anomalocaris@lemm.ee 7 points 1 year ago

I have a very secure password protecting my password manager, and have set up all my passwords there to 123456

Oh you know your password? Fuck you. We’re sending an email to your second account and to verify that one we will text you.

[-] thermal_shock@lemmy.world 8 points 1 year ago* (last edited 1 year ago)

Let's say your account is logged into from 1000 miles away, wouldn't you want that account or device, whether it was you or an attacker, to prove itself?

In most cases, if you've logged in on a specific browser/device/account, unless you've cleared cookies, it doesn't constantly ask for MFA. but in my example above, a new IP, new device, or app, it should absolutely go "whoa, wtf is this" and make you verify.

[-] AFKBRBChocolate@lemmy.world 15 points 1 year ago

Well, maybe. You said years plural, so let's take just two years. 2 years * 365 days a year * 24 hours a day * 60 minutes an hour is 1,051,200 minutes in two years.

Let's say that every time you use 2FA it's an extra 2 minutes. How many times a day do you use 2FA? That's probably the biggest variable. For some people it's a couple times a week, for others it's several times a day. Let's say 5 times a day. We also need to know how long you've been using 2FA. That's going to be another big variable. Does 5 years seem reasonable? If so, 5 years * 5 times a day * 365 days a year * 2 minutes each time = 18,250 minutes wasted on 2FA.

That's a small fraction of the million minutes in two years, but it could change a lot depending on some of the variables.

But on the other side, if even one time the 2FA stopped you getting your account hacked, the calculation would change a lot.

[-] count_dongulus@lemmy.world 9 points 1 year ago
[-] paraphrand@lemmy.world 7 points 1 year ago
[-] rimu@piefed.social 5 points 1 year ago

I saw your comment earlier today and thought "heh ok, challenge accepted."

https://piefed.social/post/762082

load more comments (1 replies)
load more comments (1 replies)
[-] toy_boat_toy_boat@lemmy.world 7 points 1 year ago

lost your password? time for a scavenger hunt!

[-] 2ndSkin@sh.itjust.works 7 points 1 year ago

What was the colour of your childhood best friend's hero's first car?

[-] Albbi@lemmy.ca 3 points 1 year ago

Blue! No, yellooooooooowwwwwwwww...

[-] dragonfucker 6 points 1 year ago

There's lots of things that have two factor authentication that don't need it.

Drag's bank lets drag log in and see drag's balance with just a password, but drag needs to authenticate to transfer any money. That's perfect, drag loves it. Yet somehow, drag's library card and epic games account have more restrictive MFA requirements.

[-] AtariDump@lemmy.world 2 points 1 year ago* (last edited 1 year ago)

Drag probably wouldn’t want the library books Drag has been reading to be splashed across the town when the revolution happens.

Also, Drag’s bank doesn’t sound as secure as it should be; if I were Drag I would move my shiny rocks elsewhere.

[-] frezik@midwest.social 5 points 1 year ago

I'm glad that a pizza place has higher MFA requirements than many banks. We've made good decisions as a society for that to be true.

[-] miss_demeanour@lemmy.dbzer0.com 5 points 1 year ago* (last edited 1 year ago)

The MFAs using an authenticator are torture.

[-] zurchpet@lemmy.ml 9 points 1 year ago

Do you like the ones sending you a text better?

For me they're worse. You need to have reception. And SIM cloning/swapping/stealing is something that is a thing too.

That can't happen with an authenticator app.

load more comments (1 replies)
[-] JoYo@lemmy.ml 4 points 1 year ago

they lost access to their account because of mfa or they just think it's a waste of time?

[-] sik0fewl@lemmy.ca 5 points 1 year ago

I assumed it was cumulative use.

load more comments (1 replies)
[-] Charlxmagne@lemmy.world 4 points 1 year ago

Like with insurance, it's far more worth spending an extra 2.5 seconds on 2fa than it is spending regaining your stolen identity and (potentially) ruined reputation (unless it's text based 2fa)

[-] Evotech@lemmy.world 3 points 1 year ago

2.5 seconds? You must be the fastest 2fa grinder

[-] Widdershins@lemmy.world 4 points 1 year ago

That reminds me I've gotta change the authenticator for my luggage

[-] neatchee@lemmy.world 3 points 1 year ago

1....2....3....4....5

[-] tauren@lemm.ee 4 points 1 year ago* (last edited 1 year ago)

At work, I must to use it every day to open google docs or gmail.

load more comments
view more: next ›
this post was submitted on 17 May 2025
490 points (95.2% liked)

Technology Memes

695 readers
1 users here now

Welcome to Technology Memes. Here you can make memes and/or rant about technology, internet, computers, corporations, enshittification and etc.

Rules:

  1. Stay on-topic.
  2. Don't attack and harras anyone. Be nice.
  3. No racism and discrimination.
  4. No politics unless they're related to tech.
  5. No spam, no ads.
  6. No NSFW.
  7. Don't repost.

Please report any posts and comments that violate these rules.

Related communities:

founded 2 years ago
MODERATORS