Or even an account for that matter

  • PeteWheeler@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    2
    ·
    1 day ago

    What really grinds my gears is when they require a password as well.

    Why did you require a password when your going to bug me about 2fa anyways? Why did you require me to change said password every 3 months if you bug me about 2fa anyways? Why are you asking me to switch my password with your dumb restrictions (no special characters, really BofA?) when it has been recommended for years to not require users to do that since it just makes the passwords less unique in the long term?

    2fa is fine, just remove passwords if your going to do it.

    • EmoPolarbear@lemmy.ca
      link
      fedilink
      English
      arrow-up
      15
      ·
      1 day ago

      It’s not a second factor if you remove passwords, the password is the first factor.

      otherwise yes absolutely, password recycling should be dropped as soon as 2fa is implemented.

      • Randelung@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        That’s what bugs me about passwordless. It’s just 1fa again, except that the password is still there to sign in from other devices if you don’t have a passkey set up yet, so now you have more than one attack vector.

        • EmoPolarbear@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          1 day ago

          Passkeys and Totp codes in my password manager make no fucking sense to me. And whoever is pushing passkeys as the new default needs to get a hard slap in the face, they’ve clearly never dealt with end users or my mom.