this post was submitted on 21 Dec 2024
103 points (97.2% liked)

technology

23383 readers
252 users here now

On the road to fully automated luxury gay space communism.

Spreading Linux propaganda since 2020

Rules:

founded 4 years ago
MODERATORS
 

Installed Steam on a new computer. Signed in. It sent a passcode to my GMail. I signed into GMail. It wanted me to 2FA because I hadn't signed into Google on that device. It sent a notification to my phone, which I never received. I had it resend the notification twice, still nothing. Tried again with my phone's offline passcodes. Neither worked. Tried the QR code/Bluetooth connection, and that finally did it.

At least I got through in the end, but fuck, it's annoying.

you are viewing a single comment's thread
view the rest of the comments
[–] quarrk@hexbear.net 6 points 1 day ago (1 children)

Security theater is an overstatement. If your password manager has a data breach (which happened a couple years ago with LastPass) then 2FA offers an extra layer of protection. E.g. if hackers get your email password, and it’s short enough to be decrypted, then 2FA would save you. Of course a longer password makes 2FA less necessary, but redundancy doesn’t really hurt anything

[–] hello_hello@hexbear.net 3 points 1 day ago (1 children)

which happened a couple years ago with LastPass

That's the thing, I use KeepassXC which is a local-only libre password manager. So someone would need physical access to my machine in order to copy the encrypted password database file. I'm the only one responsible for syncing the file across my devices.

Why someone would trust a proprietary always-online password manager that requires personal information and probably has ties to the Zionist entity is beyond me.

[–] quarrk@hexbear.net 3 points 1 day ago

Like most things, it’s a balance between security, convenience, and reliability. A local password manager is a great option and I’m glad it exists, but I wouldn’t recommend it for everyone. If your password manager is locally stored and you have a hardware failure (say, you live in Asheville and your hard drive is underwater with your house) then you’re completely screwed. A cloud option is a bit more disaster proof because those services typically have mitigation plans to prevent that kind of disaster. Plus you have the convenience of device agnostic passwords.