Especially for personal accounts.

I get why a corporation would require it for employees…

But I hate it when Apple, Samsung, etc. are forcing you to have 2fa, especially by requiring a phone number.

Side note: Bitwarden will be requiring email verification codes starting in February 2025, for those who haven’t enabled 2fa yet (see my Post in YSK). Most people store their email credentials in their password vault… so a lot of people are gonna get locked out of their bitwarden vaults. I kinda hate it, especially on such sort notice (less than 10 days).

      • guy@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 days ago

        You don’t have to store 2fa in your password vault, and even then, you can enable 2fa for the vault. It’s just more secure. Be confident that your login info will be leaked sometime, somewhere. With 2fa you’re still safe.

  • Brkdncr@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    15 days ago

    Disagree. So much money is lost because of simple password auth. Mandatory mfa fixes nearly all of it.

    • ERROR: Earth.exe has crashed@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      14 days ago

      Problems is, I still haven’t received any notice, and I’m assuming nobody received that notice either. Only knew because I happen to see it on the webpage.

      Imagine someone with only a phone (most people have their phone as their only device) and then lose their phone, then try to log in and… “Wtf is this?!?” and their email password is in the vault.

      There are probably a lot of people that this scenario will happen to.

      They should’ve gave at least 3 month of advance notice befote implementing this, this is rushed and a lot of people are gonna get locked out. (I know you’re supposed to backup, but like do you think the average person just expect Bitwarden to shut down, or just do a policy change with inadequate notice?)

  • RagingRobot@lemmy.world
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    15 days ago

    I hate it. It should be my choice. Not all of my accounts need to be super secure. It sucks enough already when my phone breaks or something I don’t need to be locked out of everything

    • weeeeum@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      14 days ago

      This is something thats actually scary. Phones are so necessary now that when it breaks you could be digitially stranded, unable to log in to anything

    • ERROR: Earth.exe has crashed@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      15 days ago

      Phone/SMS 2FA is a joke. You can tell which organizations need to be ditched.

      Oh… so you mean like… banks?

      🤔

      (Guess I gotta find a good mattress to put my money in… 😓 /s)

      (Seriously tho, everything like government stuff, taxes, university, everything now requires 2fa, most are sms 2fa 😡, I hate this.)

  • highduc@lemmy.ml
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    13 days ago

    I despise 2fa. I hate needing my phone within reach at all times, especially considering it’s a device I don’t own, I don’t have root on. There must be a better way.

  • Zak@lemmy.world
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    14 days ago

    I dislike it. I already have a unique, long, randomly generated password for every account. That’s stored in a password manager with a unique, long passphrase. 2FA provides very little additional security in that scenario.

    Worse, many services won’t let me use a standard TOTP authenticator. Some insist on SMS. Worse, some insist on their own app.

  • hedgehogging_the_bed@lemmy.world
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    14 days ago

    They been a disaster for the elder and homeless community. Many of them have no cell phone and only login once a week and 2fa makes it pretty much impossible for them.