• confusedbytheBasics@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    More like using a key that hasn’t been used in I over 30 days and needing to wait on a text/email.

    Also text or email is a bad second factor and an implementation problem. TOTP is better. Passkeys way better and are so simple once you start using them.

      • confusedbytheBasics@lemm.ee
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        Yep your rarely used vacation house needs an extra step given how rarely it’s used.

        Passwords are a miserable and lazy solution. The point was; they are cheap and easy to implement. I highly recommend dropping them whenever possible and switching to Passkeys, oAuth, SAML anything even a tiny bit harder to compromise.