Ah, but it only shows devices logged into my account. Well, let's log into hers. Which required 2FA from... her device.
Sooo useful.
Ah, but it only shows devices logged into my account. Well, let's log into hers. Which required 2FA from... her device.
Sooo useful.
Just don't log out. Let us collect your data forever and at all times. No need to restart your computer, ever.
You're dumb because you didn't create hard copy two factor backup codes! User error.
Some potential explanations by people who don't want to resolve this admittedly difficult problem to solve. I find these issues difficult when also considering security keys like Yubikey. Like you can't clone a yubikey and that's considered a feature not a bug. So what, you want me to have everything on a usbc device that barely pokes out of my laptop? That's very easy to lose. Fall off my keychain? I've had many usbs do that (__especially__ the small ones).I am really happy that there are people doing security and making things more secure, but the truth is that usability is necessary too. The reason Signal is so great is not just because encryption, it is because my Grandma can use it. Not aware of any other encrypted text message system besides iMessage and WhatsApp that has that usability and those come with strings. I really think there needs to be something similar for MFA. Consider the user.
Edit: A possible suggestion for FindMyDevice is to have trusted users. That you can give your wife, friend, whatever permission to find your device without needing to sign into your account or any other permissions. This seems like a relatively obvious solution, is there something wrong with it? Google devs, can't you patch this in in a few weeks (or less? But we all know, bureaucracy exists)
>> I find these issues difficult when also considering security keys like Yubikey. Like you can't clone a yubikey and that's considered a feature not a bug.
Yes, I am quite aware of this. My complaint is that I cannot expect my grandma to be able to perform this action. It would even be difficult if there was a cloning program, but without it, this is certainly an insurmountable task.
Sure, you can make the argument that my grandma is dumb and tech-illiterate, but the truth of the matter is that this is the bar for the average person. You, me, and other Hacker News users would have no issues with these tasks, but this is not representative of the general FIRST WORLD population. Not to mention those in developing countries.
The technical aspects are great! But they also need be made available for the average person. Be that by bringing the average person up to sufficient level or through careful design to bridge this gap. But what is clear is that the current state of things is insufficient. Especially consider that this is Apple's main value: design.
But I absolutely don't want it to work without 2FA, and if your only 2FA is your phone you have other problems.
If you don't get that message because you don't have your device that means you're not being tracked / are looking for your device and if you get that message because you have your device you've now been warned that someone has breached your account.
All Google had to do here was copy Apple's solution of having access to that one feature work with only the user name and password.
Hackers were able to steal private photos of half of Hollywood in 2014 because someone at Apple decided that 2FA is not needed for one particular iCloud function.
Perhaps some combination of no 2FA IF you are a trusted contact that I've specifically added to the account would be safer.