• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

I HATE 2FA!

bholder

Affable Sociopath
Gold Supporting Member
Supporting Member
Sep 2, 2001
32,357
87,036
Vestal, NY
Disclosures
Received a gift from Sire* (see sig)
I absolutely HATE these new(ish) 2FA schemes requiring a one-use code sent to text or email! Stupidly disruptive, and often extremely inconvenient - I'm probably on the browser app built into the mail app, so I can't keep the browser window open and go check new mail.

So aggravating. I'm very nearly at the point of saying I'll take the security risk, whatever it is, that's how irritating 2FA is.

Am I the only one??
 
I absolutely HATE these new(ish) 2FA schemes requiring a one-use code sent to text or email! Stupidly disruptive, and often extremely inconvenient - I'm probably on the browser app built into the mail app, so I can't keep the browser window open and go check new mail.

So aggravating. I'm very nearly at the point of saying I'll take the security risk, whatever it is, that's how irritating 2FA is.

Am I the only one??
Bothered me for a little while but not now. BUT I know eventually I'll need to log in to do something important and not have my phone with me. Then it will be a problem.
The extra security for things like my primary email, bank accounts, paypal etc. is worth the hassle to me. Even better when they use something like Duo that doesn't require text or email - just links to an app and a quick approval notice pops up you have to accept or decline. My employer uses this.
 
  • Like
Reactions: LP Custom
Me too. And it’s objectively dumb that they send a code to my phone and that code automagically populates into the field. If the goal is to make me have to carry 2 devices and be less productive that misses the mark.
Actually, no, it doesn't. If someone wanted to hack an account of yours, they'd have to have (1) your ID and password, and (2) your phone and passcode.
 
I absolutely HATE these new(ish) 2FA schemes requiring a one-use code sent to text or email! Stupidly disruptive, and often extremely inconvenient - I'm probably on the browser app built into the mail app, so I can't keep the browser window open and go check new mail.

So aggravating. I'm very nearly at the point of saying I'll take the security risk, whatever it is, that's how irritating 2FA is.

Am I the only one??

For an all-Apple user (desktop, phone, tablet) 2FA is very easy if you configure the other side send the code via text. The device receives the text and offers to insert the 2FA numbers into the dialog box for you. Couldn't be much easier.

No idea how Windows handles this.
 
  • Like
Reactions: Hoochie Coochie Man
Having to change phone numbers could mean getting locked out of just about every account you have, which would obviously be a nightmare.
The last time it happened to me I was unable to get into a few accounts for a long time, in a couple of cases I just gave up, because they won't answer their phones, either.
 
Having to change phone numbers could mean getting locked out of just about every account you have, which would obviously be a nightmare.
The last time it happened to me I was unable to get into a few accounts for a long time, in a couple of cases I just gave up, because they won't answer their phones, either.
There are some websites where they're still using a phone number that I largely abandoned 5 years ago. I had to go in and have a guy at T Mobile spend an hour to get that number transferred over to a new phone when the old one went down. In many cases it's darn near impossible to change the contact phone number.
 
  • Like
Reactions: E2942
Having to change phone numbers could mean getting locked out of just about every account you have, which would obviously be a nightmare.
The last time it happened to me I was unable to get into a few accounts for a long time, in a couple of cases I just gave up, because they won't answer their phones, either.
Make sure all of your accounts with MFA have another method besides a text to your phone for you to authenticate. For example, sending you an email.
 
I will admit, my frustration with 2FA isn't across the board, some implementations are less obnoxious than others. The one used by my medical service provider is particularly egregious. FWIW, Windows and Android here.

Things should just work. Argh.
 
2FA/MFA is now a reality of the digital world we live in today. Do I love it? Not really, but I am thankful for it. I too work in information security, and I can't keep up with the always changing threat landscape (like that there, dropping some cool guy IT lingo :) )
As @MonetBass mentioned regarding changing banks, we don't have any online accounts that do not require us to use 2FA. Yes, that created some inconveniences for us, but the alternative is not appealing.
On another note, protect your phone number. A hacker can intercept your 2FA signal if you're not careful. One way of not being careful is answering those random texts you get asking what seems like legit questions that you think came to you on accident, or the random 'hi' texts. Do not reply. Block and report as spam.

-Mike
 
Meanwhile...
Guitarist tells his birthday, cell, and home address to a stranger at the club.
An hour later, Drummer airdrops a pick of himself to the same stranger in between social media posts.
Bassist 2FAs his Venmo to securely purchase his 19th bass.
Singer loses her phone.
 
I'd also mention to be careful about some of those online quizzes or fun games that get passed around on social media, asking you random things like your first concert, favorite color, etc. These ones are tricky since they usually come to you from someone you trust,.
While they can be innocent, those are also sent out by threat actors (more cool IT guy lingo) in an attempt to build a profile on you. They collect some answers to what may end up being secret questions to your logins as well as learn much about you and your online presence.
The thing about hackers, they are patient. They wait and gather details about us. Sometimes they use it themselves, other times it makes them money when they sell off their collection of profiles to other hackers. Think about it, your profile will grow in value with the more confirmed data they know about you. When we contribute that data, we increase our attack surface (daily double of cool IT guy lingo). Don't make their jobs easier willingly handing over the info they need.

-Mike
 
Short listed song/band name: The Threat Actors

2FA is probably another individual tracking vector, leaving a history of sms receipts and log entries in the requisite 2FA apps.

The hair on the back of my neck went up when I saw my first, "or Sign in with FB" o_O
 
Last edited:
If you're specifically talking about TB 2FA, yes, it sucks on a phone. You have to use an email link that opens the browser through gmail, but it closes out before you can enter the confirmation code. I found an unintuitive way around it last time but legitimately forget what I did. Only annoying every few months and normally requires multiple codes to be sent. Otherwise 2FA and credit freezes rock for ID theft. Actually just freeze your credit. 2FA is cool but that's iron-clad.
 

Latest posts