As a user I just despise MFA. I hate having to keep my phone with me while I work. I hate the disruption in flow logging into everyday services like AWS.
Passwords are so much better.
As a user I just despise MFA. I hate having to keep my phone with me while I work. I hate the disruption in flow logging into everyday services like AWS.
Passwords are so much better.
Once you’ve done the second factor dance on a new device once, and assuming the MFA setup has been done well, you shouldn’t need to reach for the MFA code again (at least, not often).
Of course, you'd lose most security benefits of TOTP, but if all you want is to ignore security concerns and log in without a phone, there are tons of ways to accomplish this. Just set up authy or krypt.co and be on your way.
IMO the MFA codes aren't even the problem. The fact that you need to reauthenticate multiple times per week is the real issue. Session tokens valid for longer than four hours seem to be considered a sin in most big tech companies for some obscure reason.
You'll get the best security if you don't have the TOTP secret on a device that also contains your passwords, just in case you get hacked, but even with TOTP on-device it provides a little bonus security.
At least my password isn't changing anymore but I never understood that policy if you made a strong password. It was overkill.
Some websites still require it though, and that's nonsensical and annoying. Just randomly generate one and keep it in a password manager.
And for services (like AWS) that don't (yet) support passkeys, a hardware token like a YubiKey is also an option.
I use a desktop app for most time based authentication tokens, there are plenty that sync up across mobile and desktop.
House keys are a minimal inconvenience because the lock on your front door also affords minimal security. Just ask the Lock Picking Lawyer how long it would take a determined intruder to get into your home, whether by picking, force, or finding a weakness such as open window.
If your home had high security, I can guarantee that you'd feel the inconvenience.
A password, in theory, could work the same way. Except that the normal password UX involves people remembering the password, which entails a huge security compromise.
Yep, I'd call that a significant inconvenience (for a home that someone like me lives in).
MFA irritates me because usually it isn't my choice.
Part of it consists in the incredibly varied ways it can manifest. I could receive an SMS code, an email code, I could generate a TOTP code (choice of two Yubikeys), I could use U2F/FIDO (choice of 3 Yubikeys), I could get a Magic Link, I could use Sign in with Google, I could punt and use a code on my emergency backup paper. Don't forget to pass a CAPTCHA, and your password probably expired while you were away, as well.
Of course this all transpires after I've unlocked my password manager's vault, which has its own style of 2FA security, its own timeouts, and its own UI/UX quirks.
So you can see the sheer dizzying possible mutations of the MFA flow. Sometimes you don't even know what they'll hit you with until you try to log in!
What amuses me is "We sent a code to your email. This message will self-destruct in 10 minutes." when email used to arrive on the scale of 5-7 days if the server was overloaded or busy. Oftentimes I find myself racing multiple timeouts to run the gauntlet of MFA in whatever way has been mandated.
— Frankmin Benjalin