Comment by browningstreet
17 hours ago
I really thought this would be a 12 layer MFA demo showing the absurdity of our current painful & unsustainable MFA trends.
17 hours ago
I really thought this would be a 12 layer MFA demo showing the absurdity of our current painful & unsustainable MFA trends.
Every time I leave my phone in the other room to “finally get some work done”, please enter this goddamn number we sent to your SMS, and I close my laptop.
The most obnoxious aspect of that: I specifically have my texts accessible on my laptop, but some 2fa authentication texts get blocked via that mechanism in favor of a message saying "look at this message on your phone".
Gets worse. A lot of accounts were set up by my boss so it's all his 2FA. Then some of these require the phone to scan a QR-Code. We work remotely.
That drives me crazy. The RBC app does this although it eventually times out and gives me the number.
The worst part is: why are they sending me an SMS when I never agreed to it and didn’t configured that as an MFA option?
My work uses “okta verify” for everything which is very helpful, as I can sue my work PC as a trusted device or fall back to a yubikey if not. 100x better than random SMS
I used to solve this with the Authy desktop app, now discontinued. I firmly believe MFA shouldn’t live in your password manager (what’s the point of MFA, then?). Thoughts on MFA options?
Okay so this may sound odd but this is literally my whole life right now...
Can you explain why do you feel MFA is painful/unsustainable? How would you fix it?
Google pushes "password" down 2 layers of their interface. If you really want to use a password to authenticate, it's not always a first class citizen.
Both Google and Microsoft call their apps Authenticator, so two identically named apps on my iPhone distinguishable only by logo.
Furthermore, if you login to 20 things a day (which I do), the codes are going to these apps, SMS, and email. Each different.. so if I'm on my Linux box, my Watch doesn't really help. If I leave my phone in the other room, I can't use the apps to get the code without going to the other room. If multi-tasking is expensive for the brain and attention, MFA is the computing surface equivalent.
You may have built a great MFA workflow, but I have to live with 3-10 variations of workflows all day long, including puzzles. And it's more aggravating when I have to MFA to your service to get my information. My machine is in my house and nobody's been in my house but every_single_login requires me to pretend that in every moment of every day someone may have stolen my laptop and my finger.
My work machine will let me auth with my fingerprint, but the typical enterprise integration of all the things means I still have to click through 3-4 screens to get to where the fingerprint is accepted.
Services and APIs don't MFA.. they have keys and other restrictions for seamlessness. Where's the seamlessness solution for humans?
Passkeys are cool, but they're not ubiquitous enough yet, and the interface between desktop and mobile (even using 1Password for universal passkeys) wouldn't qualify as solved in my book.
MFA as whack-a-mole UI sucks.
The problem is the "M." Anything beyond a single factor is unnecessarily painful. Make the single factor good (passkeys or FIDO2 or whatever) and the problem is solved without "M."
Personally I hate when I use a passkey but then still get hit with an SMS second factor step. A passkey should be enough, unless I'm changing my recovery email or withdrawing a million dollars or something. Also there's still a lot of really bad UX around passkeys, both by browser/OS vendors and by individual apps, and unimplemented features like sharing.
Passkeys are the right thing but they need more work.
I totally believe that someone has gotten it this wrong, but personally I've never seen an SMS 2FA on a Passkey authentication. My most common Passkey complaint is that a service doesn't support them yet.
The worst part is: why are they sending me an SMS when I never configured that as an MFA option?
We should return to physical metal keys that are unique to unlock the computer.
> painful & unsustainable MFA trends.
This very web-forum was a very big proponent of those politics a few years ago.