molly0xfff, (edited )
@molly0xfff@hachyderm.io avatar

• enter password for password manager
• verify from email that it's me signing in from a "new location" (VPN)
• use security key
• use password from manager to sign into actual service
• complete image CAPTCHA
• receive text message with 2FA code
• unlock phone with fingerprint to get code
• access service

molly0xfff,
@molly0xfff@hachyderm.io avatar

don't get me wrong, i'm always happy to have the option to use 2FA/etc for my services, but holy moly that was a lot

noondlyt,
@noondlyt@mastodon.social avatar

@molly0xfff and yet I feel less safe

waimus,
@waimus@peoplemaking.games avatar

@molly0xfff holy Molly

Viss,
@Viss@mastodon.social avatar

@molly0xfff and in the end all you get is a cookie set?

memprices,

@Viss @molly0xfff a cookie that can be duplicated using the right software 👍

Viss,
@Viss@mastodon.social avatar

@memprices @molly0xfff smells okta-like.

OldTurk,
@OldTurk@mastodon.social avatar

@molly0xfff no cheek swab?!?

sj,
@sj@social.scriptjunkie.us avatar

@molly0xfff 😳 I thought this was a joke.

vfrunza,
@vfrunza@cosocial.ca avatar

@molly0xfff I made the mistake of signing up for a service using another service. So when I want to log in I:

  • type the password to my password manager
  • login to service A
  • wait for sms code for service A, type code for service A
  • get redirected
  • login to service B
  • wait for sms code for service B, type code for service B
  • use service

I don’t think I can get out of this hell.

kerrybenton,
@kerrybenton@ioc.exchange avatar

@molly0xfff it’s extra fun when you do all that and realize it’s for jerseymikes.com or whatever. Like, yes I know I needed to do all this For Reasons but ffs I just wanted a damn sandwich.

tinsuke,
@tinsuke@mas.to avatar

@molly0xfff does it feel different, as a Molly, to use "holy moly"?

I guess you wouldn't know, as you haven't used it as a non-Molly like the rest of us.

koehntopp,

@molly0xfff
Unfortunately, the number of sites doing that seems to increase daily. Logins "expiring" on well protected devices (desktop, mobile) does not help UX.

jason,
@jason@logoff.website avatar

@molly0xfff text based is so unergonomic I hardly consider it usable

mikelundahl,
@mikelundahl@mastodon.world avatar

@molly0xfff Same, I appreciate the security. But there must be a better way

art,

@molly0xfff Unfortunately, this also drives many people to take any easier route offered, any opt out or same password etc. On top of that, some forms of 2FA not working on some devices etc. There has to be a better way.

unlofl,
@unlofl@mstdn.social avatar

@molly0xfff Somebody on here pointed out that "MFA means it requires one thing that you can lose, and one thing that you can forget" and I keep thinking about that.

sabik,
@sabik@rants.au avatar

@unlofl @molly0xfff
... one thing you no longer are

mikej,
@mikej@mastodon.online avatar

@unlofl @molly0xfff And one thing you can never change if the service gets hacked. Try revoking your fingerprints.

bontchev,

@unlofl @molly0xfff
The 3 authentication factors:

  • Something you forgot.
  • Something you left in the taxi.
  • Something that can be chopped off.
samueljohnson,
@samueljohnson@mstdn.social avatar

@bontchev @unlofl @molly0xfff 🤦‍♂️🤦‍♂️😬

maz,
@maz@mastodon.online avatar

@samueljohnson @bontchev @unlofl @molly0xfff Someone with unsatisfied requirements or exquisite private issues involved in the proceedings 😈

resuna,
@resuna@ohai.social avatar

@bontchev @unlofl @molly0xfff

Something shared, something due, something secret, something you.

RogerBW,
@RogerBW@emacs.ch avatar

@bontchev @unlofl @molly0xfff Or plucked out.

chriscunningham,
@chriscunningham@mastodon.social avatar

@RogerBW @bontchev @unlofl @molly0xfff Welcome, Warden William Smithers. Be well.

ndm13,

@unlofl @molly0xfff My phone screen stopped working last week. This meant logging into Google required me to dig up an old tablet that was still signed in because:

  • I couldn't verify from push (can't tap the phone)
  • I couldn't verify from text (OTP doesn't get pushed to my watch)
  • I couldn't use Authenticator (again, phone)
  • I couldn't use email (requires signing in)
  • I couldn't find my physical key (fixed now)
  • my backup codes were out of date (fixed now)
molly0xfff,
@molly0xfff@hachyderm.io avatar

@ndm13 @unlofl the future is now!

europlus,

@molly0xfff you forgot the “enjoyable” bit:
• glance at one piece of data on first screen (which hasn’t changed)
• logout

Clearwater,

@molly0xfff
>get account temporarily suspended due to suspicious login activity :derpytongue:

MaybeMyMonkeys,

@molly0xfff a not insignificant number of the population does not have a viable biometric. Missing fingerprints, damaged retinas, missing digits or dna (twins/chimera).

chebra,
@chebra@mstdn.io avatar

@molly0xfff

At least 30 companies were involved in this login process.

muzzle,

@molly0xfff All so that you can purchase a ticket to an amateur talent showcase.

deeseearr,

@molly0xfff

  • "Your login has timed out. Please try again."
studiop,
@studiop@fosstodon.org avatar

@molly0xfff and at the end: "we'll just ignore the fact that you did MFA and lock you out because 'we noticed something different' (VPN) because we trust IP address more than actual security"

0xtero,

@molly0xfff This was in response to another thread, but seems we have a theme going.

https://ohai.social/@0xtero/111373533794503669

nickfoster,
@nickfoster@hachyderm.io avatar
Elishevacarl,

@molly0xfff wonder if there is a form of digital security that could utilize human network recognition- where you verify who you by showing who you know…. This feels really important for children and elders whose primary caregivers manage their digital data.

juliewebgirl,
@juliewebgirl@mstdn.social avatar

@molly0xfff
Wait wait wait... Your online password manager forces 2FA on you?? Not only that but it's email?? I like @keepassxc more and more every day. I keep the file where I want it.
@svenja

molly0xfff,
@molly0xfff@hachyderm.io avatar

@juliewebgirl no, I choose to use 2FA with my PWM, and I use a security key. But they do occasionally also add an email check if they think I'm somewhere unusual (which is somewhat often given the VPN), but that's not in replacement of the 2FA. The SMS 2FA was for the service I was eventually trying to log into

juliewebgirl,
@juliewebgirl@mstdn.social avatar

@molly0xfff
What happens if you lose your phone or it breaks?

molly0xfff,
@molly0xfff@hachyderm.io avatar

@juliewebgirl I don't believe any part of this is reliant on me having access to my specific phone

juliewebgirl,
@juliewebgirl@mstdn.social avatar

@molly0xfff

... SMS?

molly0xfff,
@molly0xfff@hachyderm.io avatar

@juliewebgirl recoverable if you replace the device. i think of all steps in that flow that are susceptible to unrecoverable loss, it'd be the security key, not the phone

juliewebgirl,
@juliewebgirl@mstdn.social avatar

@molly0xfff

  1. Phone breaks
  2. Pay $250 for insurance replacement.
  3. Wait some DAYS
  4. Use tablet for immediate things like bank
  5. Bank app freaks out because different IP (seriously, we're a mobile society with constantly changing IPs, this is really Failure Point 1™) and send an SMS
  6. You're in limbo till phone arrives.

Phone replacement takes days, possible weeks if you can't afford the deductible till your next paycheck.

Meanwhile you're in limbo.

1/

juliewebgirl,
@juliewebgirl@mstdn.social avatar

@molly0xfff
2/

Maybe you're traveling. Maybe your wallet and phone got stolen. Can't make phone calls. Can't use app on tablet.

But the thief sure as hell can! With your phone.

There are too many points of possible failure that can have serious repercussions.

I know a genius dev who had their ID stolen because... BECAUSE of 2FA. Without leaving their home.

It's great in theory.

It SUCKS in practice.

We need better.

/rant

molly0xfff,
@molly0xfff@hachyderm.io avatar

@juliewebgirl yeah, i hear you. i avoid SMS-based 2FA wherever possible

kev,
@kev@dragonscave.space avatar

@molly0xfff @pitermach I imagine the FBI does things like that all the time.

lanzz,
@lanzz@c.im avatar

@molly0xfff
• session lifetime is 15 minutes
• you need this service 12 times a day, every day

lffontenelle,
@lffontenelle@mastodon.social avatar

@molly0xfff reminds me of the comical scenes where a scientist needs retina scan and many other checks to access the lab

katzenberger,
@katzenberger@social.tchncs.de avatar

@molly0xfff The "new location / new device" thing is the nastiest. I never agreed to have my location or devices tracked.

zeitverschreib,
@zeitverschreib@social.zwoelfdreifuenfundvierzig.net avatar

@molly0xfff No iris scan?

dolmen,
@dolmen@mamot.fr avatar

@molly0xfff To unlock my password manager I have to login to the company Okta with password but also 2FA that involves answering a phone call on my mobile phone (which I have to unlock).

To access a software I use every day I also have to use the VPN.

martinvermeer,
@martinvermeer@fediscience.org avatar

@molly0xfff Feeling your pain. Now imagine standing in a blizzard by an EV charging point and your battery is at 12%.

0xdj,

@molly0xfff yup, my daily experience

anderskahlke, (edited )

@molly0xfff My collogues look at me like im an idiot when i do my 24 step process when logging in from a new device... and its understandable... but it brings peace to my soul :)

thetechtutor,
@thetechtutor@me.dm avatar

@molly0xfff and they can STILL get because they’re still running a NT that hasn’t been patched since 1897.

brianrepko,
@brianrepko@hachyderm.io avatar

@molly0xfff Security via gauntlet

timorowe,

@molly0xfff still better than having the same password everywhere and do not use 2FA though 🤷🏻‍♂️

bassplayer,
@bassplayer@mas.to avatar

@molly0xfff Bitwarden also does TOTP.
My flow is

  1. Browse to site
  2. Presa ctrl shift l to autofill
  3. When prompted for the TOTP code, presa ctrl v
  4. Press enter
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • GTA5RPClips
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • tacticalgear
  • ethstaker
  • JUstTest
  • InstantRegret
  • Leos
  • normalnudes
  • everett
  • khanakhh
  • osvaldo12
  • cisconetworking
  • modclub
  • anitta
  • tester
  • megavids
  • provamag3
  • lostlight
  • All magazines