Ask HN: What are some counter-productive security practices?
I spent the night copying my passwords into Gmail from my phone app (bad for security).
A support request got 2FA disabled and I got into my vault, but I won’t be turning it on again (bad for security). I’ll also be exporting my passwords.
An ostensibly good idea (make company admins approve turning off 2FA) has resulted in less security. I can imagine employees having a single bad experience and then swearing off password managers.
What are other examples of “smart” ideas that actually reduce security?