What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my life easier.
What about text messages? Google voice. Which of course has a desktop interface. I've been doing this for years. It's nice not to have to rely on a watch, or phone entirely - although they do make my life easier.
Whatever technical solutions can be made don't really matter unless normal people can and do use them correctly. In any case, simply setting up another non-phone computer to do the job of the smartphone doesn't change the fundamental issue, it can still break, or get stolen, or some account can get closed for spurious reasons.
We're all here to make our own decisions. We're all here to seek enlightenment. I've made it very clear that the decisions that I have made have placed me where I don't have the same issues as OP.
I'm enlightening OP, and everyone who reads these comments, I'm not "blaming" anyone.
You are offloading decisions to the consumer, decisions that the consumer shouldn't have to take. They should be solved by systems design already.
You are blaming them in your first sentence. You're both blaming and informing, your message would come off much more friendly without the first sentence.
To name and shame: BNP Paribas, one of the biggest banks in France.
My bank sent me a super key (some colorful QR code) to setup new 2FA devices, which I need to securely store somewhere.
A standard TOTP QR code can be used on multiple devices or saved and printed (and stored in a safe or something). There is no expiration date encoded in the QR; it is simply the shared secret for the TOTP app to use and some extra metadata like labels. See https://www.rfc-editor.org/rfc/rfc6238
It is a good idea to enroll multiple devices as a backup against failure, or to store it somewhere safe.
Anecdotally, my bank (Wells Fargo) will not accept VOIP numbers for 2FA.
There of course is a major problem that Gvoice seems to be special, in that many places will accept Gvoice but not standards-based VOIP competitors. I even had a problem with someone on "Comcast mobile" not being able to text a Voip.ms number of mine.
Chase owns the Amazon card, and 5% rebates on Amazon are worth dealing with the drama.
I have no idea why generic TOTP with backup codes is not an option for every site on the planet.
Fantastic. A lot of banks (at least here in Canada) ONLY have text or phone call for 2FA (which is awful, but welcome to banking).
* mandate MFA
* use proprietary and/or insecure phone-based mechanisms
I agree with all my heart that TOTP with backups is ideal. I discovered Authy a few months ago, and only because of that app did I enable 2FA on Amazon, Discord, AWS, and a number of other sites that offered it.Ask me how many of the six banking and investment apps I use support generic TOTP.
Since Authy requires an SMS verification for setup, now you’ve made yourself vulnerable to SIM jacking. A better approach would be to use a TOTP generator that doesn’t verify you by SMS.
In general, there’s no point in people dissing SMS OTP as insecure and at the same time adopting a service that uses it.