• Abnorc@lemm.ee
    link
    fedilink
    English
    arrow-up
    4
    ·
    17 hours ago

    It’s hard, but not hard enough from what I’ve been able to gather. We should want something better IMO. I’m surprised that TOTP isn’t more common.

    • brie@programming.dev
      link
      fedilink
      English
      arrow-up
      3
      ·
      17 hours ago

      S7 will be retired or extended with access control. TOTP apps don’t work for edge cases like broken phone. Dedicated token devices get lost. SMS will continue being the main solution for 2FA.

      • JasonDJ@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        44 minutes ago

        Nah what we need is good privacy-focussed companies getting into the public IAM space.

        You know how you can sign into stuff with your Google or Facebook account? And get a 2FA push to your phone?

        Like that. Except by a company with a shred of ethics and morality. Like Proton.

        I do also think that we all should have a cryptographically secure federally issued identity for official uses such as signing documents or signing into financial accounts and other things that must use your official identity, and not an online pseudonym. Like SSN but on a smartcard. Basically CAC or ECA but for general civilian use.