Or even an account for that matter

  • Bieren@lemmy.today
    link
    fedilink
    English
    arrow-up
    3
    ·
    9 hours ago

    I had one the other day. Enter passcode from Auth app. Ok done. Great. We just emailed you another code enter that now.

  • SailorMoss@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 hours ago

    Just use Keepass, it lets you store your passwords and totp in an encrypted database file you can move around just like any other file. Just make sure you make a backup when ever you add new credentials.

    • pressanykeynow@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      11 hours ago

      If I store your password and totp in one app it’s not 2fa, there’s literally no reason to setup both then

          • SailorMoss@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            10 hours ago

            Keepass is pretty well respected by security experts. Often more than other password managers such as bitwarden. Though of course bitwarden is recommended as well.

            It’s a file that is not stored online so hackers cannot access it unless they’ve already compromised your personal system, even then it’s encrypted so they would also need to capture your keepass password as well.

  • Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    13
    ·
    15 hours ago

    I would rather have 2fa than the magic link email bullshit. I am so fucking tired of sites assuming I don’t want to use a simple username and password, and I clearly want to have to wait on email delivery to be able to access my account instead of JUST ENTERING MY GODS DAMNED CREDENTIALS.

    • toynbee@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 hours ago

      There is an app on my phone that, after every update (and sometimes just because it’s bored) logs me out. When I log back in, it opens a browser to request a username, a password, and a random number that it emails me. The number is not in the subject line of the email, so I have to switch to my inbox to get the number.

      Unfortunately, half the time when I open the email, when I switch back to the web browser number form has forgotten that it’s a text field and so won’t open my keyboard. I haven’t yet figured out a way to fix this, other than waiting a few hours then trying again. If I force close and try again immediately, the same issue occurs.

      • psilotop@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        11 hours ago

        Ugh that’s frustrating. I’ve had similar experiences. Bluetooth keyboard was my savior which is really only available if I’m at home

  • germanatlas@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    89
    ·
    1 day ago

    Things that I have 2FA for for some reason:

    • my abandoned Ubisoft account which holds two free games and doesn’t have any personal details about me

    Things I don’t have 2FA for, although I’d probably prefer if I could have:

    • my bank account
    • Chloé 🥕@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      9
      ·
      19 hours ago

      2fa for a ubisoft account is actually very important. what if somebody hacks into ur account and buys more ubisoft games???

    • Malgas@beehaw.org
      link
      fedilink
      English
      arrow-up
      47
      ·
      1 day ago

      No, you see banks don’t need 2fa because they’ve got ironclad password requirements like “max of 8 characters, alphanumeric only”.

      • igmelonh@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        18
        ·
        1 day ago

        But some of them don’t tell you that when you first set it, so you have to call tech support and, after sending you a temporary password to log in and set a new password which then also doesn’t work, they’re like “wait, you can’t have & or ! in the password — try it without,” and it works because it accepted the password but removed all special characters without telling you 🙃

      • Darkassassin07@lemmy.ca
        link
        fedilink
        English
        arrow-up
        9
        ·
        24 hours ago

        My bank doesn’t allow copy+paste into the new password fields, and clears anything you’ve typed if you switch apps.

        To set a new password (which is mandatory every 6mo) I have to physically write down the new password that my password manager generates…

      • NominatedNemesis@reddthat.com
        link
        fedilink
        English
        arrow-up
        9
        ·
        1 day ago

        Your bank lets you use letters? Mine just numbers. The registration allowed 10 numbers but the login does not allowed more than 8… At least they block the account after 3 incorrect guess and make you ask for a reset in person. So I had to go twice in a day… and the teller lady asked why I don’t use 4 digits like a normal person… Sill beter than the other bank which sends the password back in plain text email after registration in 2019

  • Azura The Spellkissed@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    40
    ·
    edit-2
    23 hours ago

    This, but specifically because of Microsoft Authenticator. I hate this app so damn much. [I’m forced to use it] not with TOTP tokens, but push-notification based ones which arrive only sometimes and are slow. And then it’s mocking me saying “pull to refresh if you don’t see a notification”, but there is no pull to refresh feature. Oh and Microsoft Azure Portal? It asks you to authenticate twice in a row, just to be sure. Burn burn burn

    • NekoKoneko@lemmy.world
      link
      fedilink
      English
      arrow-up
      12
      ·
      23 hours ago

      I tried MS Authenticator after creating a business account with me as the admin, and it let me enroll and then immediately gave me a device untrusted error (I’m rooted, sue me, but there’s no warning or way to tell that’s not allowed) which then login-looped every recovery option to try to re-enroll or remove the 2FA, requiring me to file a ticket and manually prove who I am which took 48-hours.

      Just the fact that they let me sign up before pulling the rug and revoking access with a hidden, time-bomb fail condition, really impressed me. It takes work to be that evil.

    • arudesalad@piefed.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      21 hours ago

      That sounds horrible. I hate that steam requires me to use their app instead of the authenticator app I use for everything else but at least it works every time

    • Leon@pawb.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      22 hours ago

      I feel this. And the endless fucking prompt to log in. Several times a day. Everywhere. We should bill Microsoft for the time lost.

  • saltnotsugar@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    1 day ago

    For some reason I read it as “I lost the love of my life to two factor authentication” and really wanted to hear how that was possible.

    • Jilanico@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      1 day ago

      Long distance relationship, locked out of email, can’t remember their email address 🥀

    • 0ops@piefed.zip
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 day ago

      heyy cutie, can I get your number? can you give me the code i sent to your phone number, hot stuff? you’re adorbs, is this still a good email to reach you with?

  • Programmer Belch@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    11
    ·
    1 day ago

    I store 2FA in the same place I store my password, I just need to copy one, then the other. I may have lost hours or even days to 2FA, the same amount I lose by having to authenticate with a password

    • thenextguy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      20 hours ago

      No thanks. I’m fine with passwords for most things, and MFA of my choosing for important things.

  • PeteWheeler@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    21 hours ago

    What really grinds my gears is when they require a password as well.

    Why did you require a password when your going to bug me about 2fa anyways? Why did you require me to change said password every 3 months if you bug me about 2fa anyways? Why are you asking me to switch my password with your dumb restrictions (no special characters, really BofA?) when it has been recommended for years to not require users to do that since it just makes the passwords less unique in the long term?

    2fa is fine, just remove passwords if your going to do it.

    • EmoPolarbear@lemmy.ca
      link
      fedilink
      English
      arrow-up
      15
      ·
      21 hours ago

      It’s not a second factor if you remove passwords, the password is the first factor.

      otherwise yes absolutely, password recycling should be dropped as soon as 2fa is implemented.

      • Randelung@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        21 hours ago

        That’s what bugs me about passwordless. It’s just 1fa again, except that the password is still there to sign in from other devices if you don’t have a passkey set up yet, so now you have more than one attack vector.

        • EmoPolarbear@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          21 hours ago

          Passkeys and Totp codes in my password manager make no fucking sense to me. And whoever is pushing passkeys as the new default needs to get a hard slap in the face, they’ve clearly never dealt with end users or my mom.

    • WalrusDragonOnABike [they/them]@reddthat.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      My utility account shows power use by 15 minute intervals. Technically someone could use that as a way of figuring out when people are home or away if you have a regular life schedule. Seems like a farfetched concern though.

    • shads@leminal.space
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 day ago

      Always had the same reaction to requiring a PIN to refund a transaction on an EFTPOS machine. Someone wants to steal my card and put money on it that’s cool, just stop them from taking it out and they can hold onto that card as long as they want.

  • Thatuserguy@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    23 hours ago

    I had a really fun one with my Google account the other day. It was the one where you had to select the number it was showing on “the other screen”. However it was trying to show it on my same phone I was trying to log in on, only to immediately overwrite it with the prompt to select the correct number. Cue me sitting there having to guess the right number like 6 times before finally getting access, getting logged back out every time I failed to guess right