I personally am fine with this.

top 50 comments

sorted by: hot top controversial new old
[–] 118 points 3 years ago* (4 children)

Yep, should be standard everywhere

..... for accounts you actually give a shit about

  • source
  • hideshow 8 child comments
  • [–] 39 points 3 years ago (5 children)

    While you are adding this anyway consider using an open source app instead of google auth like aegis. There are many others but I wish I knew about them sooner.

  • source
  • hideshow 6 child comments
  • [–] 7 points 3 years ago (1 child)

    I personally love keeweb. Passwords and 2fa all in one place.

    I mean you could argue that defeats the purpose of having 2fa, but it's convenient

  • source
  • parent
  • hideshow 2 child comments
  • [–] 6 points 3 years ago (1 child)

    It weakens it a bit, but in my opinion it still has strength where it counts. If an attacker gets access to your password outside your password manager (man-in-the-middle, keylogger, phishing), then you’re still protected. Maybe it’s hubris in my own ability to keep my password manager safe, but I’ve never been worried about storing MFA in my password manager.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (4 replies)
    [+] 34 points 3 years ago* (last edited 2 years ago) (17 children)
  • [–] 51 points 3 years ago

    Too many people were making poor choices. When there's an incident of an account that should have been secured but wasn't getting compromised, that's bad for the platform, ecosystem, and community. This is just another level beyond not allowing you to set a password of "password"

  • source
  • parent
  • load more comments (14 replies)
    [–] 23 points 3 years ago (1 child)

    Good, people are fucking stupid and if it effects others it's often better to choose the security for them!

  • source
  • hideshow 2 child comments
  • [–] 10 points 3 years ago (2 children)

    Yup. I'm actually a bit baffled by how much negativity/misinformation there's around 2FA even in a place like this, which should naturally have a more technically inclined userbase.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 13 points 3 years ago (2 children)

    2fa should be mandatory everywhere

  • source
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 4 points 3 years ago (6 children)

    2FA is the biggest bane to my productivity in the last 15 years, no part of my work life should require me to pull out my magic distraction device.

  • source
  • hideshow 12 child comments
  • [–] 6 points 3 years ago

    You can use KeePassXC to generate the TOTP codes on your PC. With the browser plugin, you can generate the code and fill the textbox with one click when the password database is unlocked.

    Sites that don't use standard TOTP for 2FA are a pain in the ass though.

  • source
  • parent
  • load more comments
    view more: next ›