60 karma · joined June 19, 2019
And for services (like AWS) that don't (yet) support passkeys, a hardware token like a YubiKey is also an option.
I fail to understand how educating billions (?) of people about proper password hygiene is faster or simpler than moving all authentication to a “tap this button to magically log in” method.
“Someone who works at Meta reached out and advised me to rename the filters asap.” [1]
So maybe the issue is simply that Pixelfed is using identical filter names.
If the number is not actually validated in a secure (enough) manner, there's no point in using phone numbers at all.
It might not be an issue for some types of usage, but sounds risky if used for account security/recovery/etc.
The reality of operating a big site/service on the internet in 2022 is that it’s sometimes necessary to use methods that annoy a few people (with very non-standard browser settings) in order to protect the service as a whole from a million bots trying to attack it at any given time.
For example, if an automated system thinks an account is sending spam, enforcing a (very low) outgoing email rate limit would be a much more reasonable first step.
Or, more simply: Slack (and other similar products) are not just “chat applications”.
I see Slack as an incredibly full-featured app. As always, many people might not use all the features, but that doesn't mean that nobody does…