I personally am fine with this.

you are viewing a single comment's thread
view the rest of the comments
[+] 34 points 3 years ago* (last edited 2 years ago) (8 children)
  • [–] 51 points 3 years ago

    Too many people were making poor choices. When there's an incident of an account that should have been secured but wasn't getting compromised, that's bad for the platform, ecosystem, and community. This is just another level beyond not allowing you to set a password of "password"

  • source
  • parent
  • [–] 3 points 3 years ago (1 child)

    Though people that have authority over important projects should have proper security, considering how large the internet is, with how many individual parts, the chance of someone being in charge of a large and important project - may it be a browser, compiler/interpreter, utility, library etc. is not even close to zero.
    So if a (co-)maintainer of a project included as standard utility in Linux Servers, let's say bash for example, is somehow breached, the attacker could push and force merge a malicious obfuscated commit, maybe even with normal content included. As it's from a reputable source, it's not going to be checked as thoroughly as commits from other people. One hour later, every Arch system, desktop and server, has a trojan. Four hours later also all Gentoo systems (got to compile it first). 2 years weeks later regularly updated debian servers now contain malware. A chain of events, fragile to being detected by people monitoring their own activity, other maintainers activity and people reading the source - eg. for security reasons -, but yet, not that unlikely considering the amount of packages present even in a standard install, and needed as dependencies for typical server packages.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 3 years ago

    Bitwarden has 2FA (for paid tier, like $10/year). I don't consider it "real" 2FA, but it's more secure than just a password, and super quick to copy code using browser addon. Useful for certain sites, that don't stay logged in, require every time, etc.

  • source
  • parent
  • [+] -20 points 3 years ago (2 children)

    they want your phone number so they can track you.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 3 years ago (1 child)

    how would they track you?

    The reason they want a phone number is, that it's a relatively cheap way to ensure people not signing up bots galore, as getting phone numbers en masse is a lot harder than getting email accounts

  • source
  • parent
  • hideshow 2 child comments
  • [–] -3 points 3 years ago (4 children)

    phone numbers are typically tied to your name/identity, and phone companies can locate you using their towers and such. Giving a company your phone number is identical to giving a company your full legal name and address.

  • source
  • parent
  • hideshow 8 child comments
  • [–] 0 points 2 years ago

    yeah, no idea why you're getting downvoted, it's clear why companies are so eagerly embracing and requiring 2FA -- if the benefits were only for the consumers, it wouldn't be mandated anywhere near this quickly. but when they know they get a real human phone tied to every account, that's a huge motivation

  • source
  • parent