| ▲ | dalyons 39 minutes ago | |
physical 2fa should be an option, but i can never agree that we should force billions of regular people to use a harder to use and more inconvenient system that they have already indicated they dont want to use, for some mild security benefits | ||
| ▲ | iamnothere 37 minutes ago | parent [-] | |
Why not? We “forced” everyone to use SMS/email second factor, now we’re moving towards “forcing” passkeys, and European banks used to “force” the use of an electronic HOTP/TOTP token. Decoupling logins from the big cloud providers is a clear win for freedom and protection against abuse. People are frequently cut off from their cloud accounts for whatever reason, and I expect this problem to increase as global disorder increases. (To be clear, I don’t think people should be legally forced to use tokens, but I do think that industry should be heavily encouraged in that direction.) | ||