Remix.run Logo
PaulHoule 12 hours ago

Never. 2FA is a suicide pact for any online service if it doesn't have high touch customer service like a bank. A certain fraction of users will be locked out without recourse each month and the user base will decay like a radioisotope. Every time a service requires 2FA I rethink if I want to stay with it.

rekabis 12 hours ago | parent [-]

> Every time a service requires 2FA I rethink if I want to stay with it.

I’m sure you feel the same about locks on your car and on your home. I mean, those silly keys, eh? They get so much in the way of going in and out and just using those things. Better if we dispensed with keys entirely, and just left everything unlocked and instantly available.

PaulHoule 12 hours ago | parent [-]

Look if I get locked out with real keys and locks I can call the locksmith and get the situation resolved.

If I get locked out of Google or Amazon or Facebook I can talk to the hand at best with no recourse at all. A lot of 2FA hardware is garbage, like the Yubikey I had that had the hole attaching it to my keychain worn out in less than two years -- it could have fallen away and been lost.

rekabis 9 hours ago | parent [-]

If you do 2FA without recovery keys or a recovery eMail, you’re doing it wrong.

Everything I have heard from you so far is draped with ignorance and misinformation.