View Single Post
Posts: 1,417 | Thanked: 2,619 times | Joined on Jan 2011 @ Touring
#10
Originally Posted by sicelo View Post
A lot of 'new' tech is of arguable value, but I think 2FA is really worth it to enable on any service where it's supported
It seems reasonable except that the failure of the electronic device you rely on to combine the secret seed and time to output the verification code means destruction or failure of the device is an automatic lockout.
This is a great solution if we are talking nuclear missiles but I prefer other methods which don't have such a glaring failure mode.
I ended up having that exact failure thinking I had already transferred out what I needed and sent the closure request. I had to show up in person a very long ways away to correct the issue.
Had that been an on-line only account I would have lost my funds or perhaps have been liable for years of fees sometime in the future.
Between military rescue and aviation I just assume everything I rely on will be broken when I really need it most and 2fa relies on a single or several precious devices. Perhaps it is possible to cut/paste the seed for later use, but I think many systems that offer this service do not have a way to recover or worse will kill/reset the 2fa too easily making it a false security.
I really feel that this whole experience was a big show of security theater towards the end where things were reset too easily during the day I was going to the financial institution to confirm the transfer and closure of the account personally. It exposed too many people with admin authority who could be social engineered into opening my account to be emptied or just doxxing my info.
To explain my security mindset I give the example of a friend who lost their protonmail password. they did the password recovery and could read the email subject lines but they lost their crypto key in the reset, a bad actor who had taken the email account couldn't then read any of the messages. Protonmail fails safe. they might even offer 2fa, but with just username and password even a refugee who showed up in Europe or Canada naked could still use an account user/pass stored in their own mind to access communications or even recover a crypto currency wallet.

Last edited by biketool; 2021-12-09 at 15:12.
 

The Following 2 Users Say Thank You to biketool For This Useful Post: