Remix.run Logo
PennRobotics 2 days ago

One of the dumbest auth workflows I experienced in recent times: My partner texts me, "Mom lost her phone somewhere in the zoo." I go to log into Google Find My Phone with her password. It sends a mandatory verification SMS... to the lost phone. (It was eventually found, no thanks to Alphabet.)

I would be much more comfortable with passkeys and 2FA if there was almost always the option to log in with just a password as long as an email gets sent to me (perhaps relevant that I have paid email, not Gmail) stating I logged in to site XYZ without 2FA. Not a "click button to confirm you want to log in" email, just a "hey this happened" email containing a Shaggy link, "It wasn't me." Bonus points if that site's account settings (e.g. 2FA) cannot be changed as long as I'm only logged in with a password[+].

The odds of me not having a device to receive the email at the same time someone guesses my password and causes rapid catastrophic damage[++]... I would need to be specifically targeted or unlucky beyond the normal expectations of unluckiness. (Much more likely: I'd occasionally discover which sites have bad security practices or that I need to be more resistant to social engineering or more careful in public spaces; guessing a long generated password in just a few attempts when the password is never shown on the screen would be impressive!)

I've lost count of the number of times I need to enter a password using a unknown machine, log into my Bitwarden server, copy/paste the necessary password, ... "okay now you'll see a popup on your Totally Breakable Losable Connectivity-Unreliable Android phone"

-----

[+]: account info can't be changed w/ only password... unless I provide some verification ranging from personally appearing at an office with ID for money-related accounts to verifying ownership from a backup email address for low-stakes accounts like bulletin boards.

[++]: short of guessing my Bitwarden master password, which is one of the carveouts for "always always 2FA" and "several alternative, secure backup login methods, at least one which does not require technology"