Skip Navigation

How do you feel about mandatory 2fa policies?

Especially for personal accounts.

I get why a corporation would require it for employees...

But I hate it when Apple, Samsung, etc. are forcing you to have 2fa, especially by requiring a phone number.

Side note: Bitwarden will be requiring email verification codes starting in February 2025, for those who haven't enabled 2fa yet (see my Post in YSK). Most people store their email credentials in their password vault... so a lot of people are gonna get locked out of their bitwarden vaults. I kinda hate it, especially on such sort notice (less than 10 days).

44 comments
  • In today’s world, MFA (multifactor authentication) is a necessity for literally any account in which you store information you don’t want to be stolen by someone. I’m more upset that several services I use still don’t support it, or only support MFA via text or email, neither of which is secure enough to be of much use.

    You don’t want the place where you store your passwords, likely including your bank account, health insurance, social media accounts, etc. to be more difficult to hack? You live in a post-quantum world. Passwords aren’t enough.

  • I dislike it. I already have a unique, long, randomly generated password for every account. That's stored in a password manager with a unique, long passphrase. 2FA provides very little additional security in that scenario.

    Worse, many services won't let me use a standard TOTP authenticator. Some insist on SMS. Worse, some insist on their own app.

  • I don't have any intrinsic issue with 2FA, but via something like storing an OTP on a store I decide on, not if it involves needing to install Random Company's app on a phone or provide a phone number.

  • 2fa is like mandatory nowadays for security purpose. just use TOTP like lemmy with ente or standardnotes as an app. it is easy to just copy and paste TOTP to access your password manager.

44 comments