> I still don't know why apps think a device I carry in the streets is safer [...]
Because MFA requirements have never been about security, only security theater. It's the modern version of the "you must change your password every 30 days" rule.
Because MFA requirements have never been about security, only security theater. It's the modern version of the "you must change your password every 30 days" rule.
MFA is like infinitely more secure than your username/pw that Tim from accounting writes on his notes and reuses the same password everywhere.
How is that not common knowledge?