this post was submitted on 21 Dec 2024
101 points (97.2% liked)
technology
23383 readers
270 users here now
On the road to fully automated luxury gay space communism.
Spreading Linux propaganda since 2020
- Ways to run Microsoft/Adobe and more on Linux
- The Ultimate FOSS Guide For Android
- Great libre software on Windows
- Hey you, the lib still using Chrome. Read this post!
Rules:
- 1. Obviously abide by the sitewide code of conduct. Bigotry will be met with an immediate ban
- 2. This community is about technology. Offtopic is permitted as long as it is kept in the comment sections
- 3. Although this is not /c/libre, FOSS related posting is tolerated, and even welcome in the case of effort posts
- 4. We believe technology should be liberating. As such, avoid promoting proprietary and/or bourgeois technology
- 5. Explanatory posts to correct the potential mistakes a comrade made in a post of their own are allowed, as long as they remain respectful
- 6. No crypto (Bitcoin, NFT, etc.) speculation, unless it is purely informative and not too cringe
- 7. Absolutely no tech bro shit. If you have a good opinion of Silicon Valley billionaires please manifest yourself so we can ban you.
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Why can't services just use TOTP for 2fa. It's more secure, more convenient and less work.
Steam's preferred 2FA is getting a code from their app. It looks like it might be TOTP technically but they don't freely give out the secret for use in another app, but there might be ways to extract it.
Google offers TOTP and used to let you set it as the default, but now I guess they want to push their own in app prompt so you have to pick the "try another way" option every time.
Dark patterns are for cowards. Either remove the feature like you want to or just keep it.
Yeah for Steam you have to use 3rd party tools or pull a file off your mobile device/emulator and extract the TOTP secret (and use plugins for password managers to render the alphanumeric code with the characters they want, it's just a non-standard TOTP representation and sucks so much).
The maker of that "Authy" shit that's just TOTP generator/backup once again locked behind your fuckin phone number deserves a special place in hell. It's Twilio, a virtual phone/SMS API provider... and owner of Sendgrid. Same deal as with Steam where they'll add the TOTP secret to the Authy app and you have to extract it manually to use in a different app/password manager. At least the codes are part of the IETF standard. Just generated with an uncommon <30s step interval for rolling over and I believe are 7 digits instead of 6. KeepassXC natively had configuration for it at least.