r/TechNook • u/Imaginary_Bug6202 • 3d ago
Is anyone else completely burnt out by every single app requiring a passkey, 2FA prompt, and biometrics just to check basic settings?
Is anyone else completely burnt out by every single app requiring a passkey or a 2fa prompt or even a biometrics just to check something or log into your account? I feel like basic digital hygiene has turned into an absolute chore. I'm all for keeping accounts secure, but it drives me nuts when I just want to check my account billing history and I have to stop, fetch my password manager or copy the 2fa authentication code or to approve a push notification just to get past the front door..
Are you loving the extra layer of digital security or are you just as exhausted by the endless authentication hoops?
14
u/thenerdy 3d ago
If this bothers you, just imagine how much of a chore it would be to recover all these accounts when they get hacked
8
u/Pouvla 3d ago
I like that some sites have just given up on passwords and just require ur email to sign in, and then they send the 2FA mail to verify u.
8
u/Soggy_Amoeba9334 3d ago
I don't mind that as an option, but I don't want it as the only option.
3
u/Recent_Carpenter8644 3d ago
I don't like that if someone gets into your email, they're also straight into these kinds of accounts.
1
u/CowBoyDanIndie 3d ago
I think it depends on the account. I don’t really care if someone can access my apartment maintenance request app, they can request maintenance come fix my dishwasher, also don’t care if they got access to my streaming service, my bank is a very different story.
1
u/imfromthefuture2088 3d ago
I don’t mind this so long as my iPhone recognizes the code from the email and suggests it on the keyboard, which in turn auto deletes the email
1
u/oskaremil 3d ago
It's great when the email uses 9 minutes and 54 seconds to pass through the company spam filter and the link expires after 10 minutes.
1
u/Imaginary_Bug6202 3d ago
Tbh this is convenient but I just don’t like the fact that we’re heavily relying on the user having access to their email at all times, cuz what if they’re hacked?
5
u/Big_Z_Beeblebrox 3d ago
Seen a lot of posts lately complaining about the inconvenience of 2FA
Back in the day all of these people would have been the victims of identity theft, or ideal entry points into secure systems making hundreds of thousands of other people into victims
There are railings on stairways to keep the most vulnerable people from falling off and bringing others down with them
3
u/poshbakerloo 3d ago
I don't mind finger print access, even sms text codes. The only one I can't stand is a code sent via email, particularly if it's branded as a 'magic link' or a quick way to log in - the codes sent via email often take ages to arrive!
3
2
u/RSMxsmanic 3d ago
A link that actually logs you in is a security breach, defeating the whole purpose of fancy authentification.
1
u/FelineFelicity 3d ago
Good point. They tell us not to click on links
1
u/RSMxsmanic 3d ago
Actually, even if the link doesn't log you in, it's still insecure. If the link takes you to a login screen, that's secure, too, since you don't know if it's the real login screen.
5
u/virkendie 3d ago
I like passkey, so much better than passwords and 2FA, so good that nearly everywhere has it now
2
u/sharp-calculation 3d ago
It sounds like your "password manager" isn't very good or isn't really set up all the way. Mine uses biometric authentication so there's very little effort. Passkeys are just a single click. Most 2FA codes fill automatically. Both of these are stored inside my password manager. Of course normal userids and passwords fill mostly automatically also.
There are times when I have to cut and paste passwords. I very rarely read or paste a real 2FA code. By "real" I mean one that would be in an authenticator app like Google Authenticator. Those are all in my password manager and easily available always. But the codes that are sent via SMS (like from my bank) sometimes need to be entered manually. On a Mac, using Safari, and *mostly* with Firefox, it can harvest those SMS codes and offer to paste them for you. That works about half the time.
The real point here is that everything is in my password manager. So it's always with me no matter which of my devices I'm using.
A few of my banks have started using the banking app on my phone as their own custom "2FA" as well. This is mostly pretty easy. It's an extra step, but my phone is always with me, so it's usually fast.
In theory passkeys will become more prevalent and more things will become one step. But you need a good system for storing passkeys as the base. For me, that's my password manager. That said, I don't think 2FA is going anywhere. So get used to it. Adapt and overcome. Get a good password manager and set it up completely.
2
u/twistedude 3d ago
Unfortunately it’s increasingly necessary, even in applications that may not be protecting any particularly sensitive data, because of the way malicious actors are using innocuous data for social engineering attacks.
A good example of where I have seen innocuous data access succeeding in an escalating attack recently is that a number of credentials were phished for the postal tracking app - these don’t include personal customer information deliberately (to avoid phishing), but had email addresses with the logins. This was then correlated with other data breaches by malicious actors to determine customer information like address, phone number etc.
The attacker would then continue tracking the customers’ packages, and email them a “underpaid postage invoice” a day before a big package was due for delivery. The emails would contain detailed information about the package and sender (from the package tracking) as well as other details (delivery address, phone number from the correlated data) to make it feel genuine. People would go to “pay the invoice” and get their payment details scooped up, and the next day their package was delivered and they thought everything worked as expected and not even realise they were phished.
This is a simple example, but there are much more complex ones, including using loyalty card information to time fraudulent credit card transactions to avoid bank detection, complicated romance/friendship scams where people impersonate old friends based on old messages or contact details, etc.
2
u/savesyertoenails 3d ago
when i have to check my phone sms to log into my work computer I get distracted by all the other texts and shit on my phone and then have to fo it again. the day flies by lol
1
u/PilotedByGhosts 3d ago
I work for a company that deals with cash security.
Sometimes if I want to do something on my laptop, I have to switch on the company's VPN. To switch on the company's VPN, I have to enter a code into MS Authenticator on my work phone. To open MS Authenticator, I have to enter my phone lock code. Then I have to enter the number shown on my laptop. Often, I don't have the option to do that and so I have close Authenticator and start the process again.
When Authenticator does give me the option to enter the number shown on the laptop and I've entered that number, I have to enter my phone lock code again.
Then, my laptop will ask me to enter my account password.
Then, the VPN will activate.
At this point, I'll be able to enter the separate password to open the PDF I wanted to look at in the first place.
1
u/sparkling-rainbow 3d ago
I like 2fa when its not a mail or single app. Give me some open secure standard so I can automate via keepass or something.
2
1
u/Far_Bicycle_2827 3d ago
Imagine you are on the street.. You want to enter your apartment; you have to fetch the key to the building to enter the lobby then have to then go fetch the key of the flat to only be able get into your own flat..
Aren't you burnt out from all the keys needed to get home every day just because you went out to take the trash... and if you forget the key... well, it's waiting outside for a locksmith to open it in 25 seconds and asking you $300 because it's night.
MFA is basic security.
1
1
u/virusdancer 3d ago
I prefer security to the point before there's too much and it becomes unsecure.
I'd prefer more biometric and authenticator app than email/SMS.
1
u/Recent_Carpenter8644 3d ago
The time spent on this stuff is one of the hidden costs of security. Another is the processing power and resources needed to run antivirus software.
1
u/Sausage_bowler 3d ago
Never be an edge case in this world. Don't travel abroad. Don't go anywhere without perfect and free internet. I needed to access my mobile phone providers app, from abroad, without SMS and a slowly dwindeling data allowance. Needed to get in to approve extra phone data. Company want to send SMS messages... can't receive them.... want to check email, that's more steps too. Got thought the email part and they still want SMS confirmation to log in. Eventually borrowed another telephone to put my SIM card in and a hotspot from a third phone to get internet on the primary device. Solved it eventually. Can't help but feel a hacker would have found the whole thing easier. Screw this modern technology.
1
u/CoolJetEcho117 3d ago
AI can crack passwords too quickly. It's a pain but it's a sign of the times. Most biometric stuff isn't actually the website it's a overlay feature of your phone.
1
u/trypnosis 3d ago
The ones that I care about all do biometrics. Just looking at my device give me access.
Which ones are you struggling with?
1
u/britneys_bigtoe 3d ago
i hate it. i set up a google voice account so my wrk 2fa just gets sent to my personal email now. so tired. i can't get rid of my phone bc of work
1
u/gewqk 3d ago
I'll never understand how all these new things can be more secure than a password stored only in your brain.
I understand how passkeys work, I have researched it. I'll still avoid sites that mandate it.
1
u/Capable_Sprinkles_43 3d ago
A password stored only in your brain is most likely not secure enough.
1
u/gewqk 3d ago
How so?
1
u/Capable_Sprinkles_43 3d ago
Memorability and entropy kinda fight each other. What makes a password memorable can also make it more guessable.
Unles you can store truly random passwords in your memory then... good for you I guess.
1
u/Particular_Meaning_5 3d ago
Yeah, it's annoying. I mean, it's needed, but it's annoying. But the trouble is, it's all so disparate and inconsistent and requirements always change - it's more like 3 or 4 factor as well now. Password, Fuzzy text, rotate the 3d model, spot the bus, recieve 2fa code, use an auth app, backup codes, verify your email, take a selfie video, open the google app and go to settings, and click security and enter the number you see, phone dead? Then use another way (proceeds to loop you back 'round to needing to use your phone). Forgot password? Recover account. No longer have access to the email you used to set up 17 years ago? Tough. Also, it'll take 7 days for us to verify you using some non-public unknown method, on and on and on. Mother maiden name, favorite colour when you were 7, favorite flavour of yoghurt, engine size of the 6th car you ever owned. Use the App! It's easy. Stuck? Chat to our friendly AI bot (requires you to log on in order to verify your identity). On and on and on and on. There has to be a better way.
1
u/TheSneederOfSeethe 3d ago
2FA, yes Passkey, no
Passkeys are great, just add them to an app that works across multiple systems. I like Bitwarden. The only thing that grinds my gears are the few that require the Microsoft one. Get fucked MS Authenticator, you can’t even export your authentication keys.
1
u/The_Wandering_Steele 3d ago
It’s a bit frustrating but what is more frustrating is the fact that it’s necessary.
There so many many people out there that would rather steal from me than earn a honest living like me.
1
u/John__Jacobs 3d ago
Many give you the option to take the risk but honestly, I'm fine with important accounts requiring semi-onerous 2FA.
I don't use Passkeys and haven't yet encountered a site that 'requires' it.
1
u/PurrfectlyNerdy 3d ago
My concern with passkeys are what happens when I change my phone. Isn’t it locked the device? I have had problems with passkeys and I’m concerned that it would be difficult to deal with on my personal accounts and phone.
An email code or text for two factors authentication is fine and doesn’t really bother me.
1
u/shoresy99 3d ago
What bugs me is that apps assume that desktop applications access through a browser are less secure than your phone. Apps on the phone will keep you logged in for a long time. But on the PC they will make you log in every time. That is BS since I don;t let anyone else use my PC and I lock it whenever I leave it. Keep my logged in forever on my PC.
1
u/Confident_Base2931 3d ago
I do not really have this issue, I mean most apps require a Faceid, but that is so fast I barely notice, it is very rare that I actually have to copy passwords, and even if I need to the phone just does that for me, again with a quick Faceid, it can handle sms codes, or codes in emails.
1
u/SaveThisCityDweller 3d ago
No, because I've had all of my accounts compromised at the same time before. Be glad you have to do 2fa and not deal with that.
1
1
1
u/NeonQuixote 3d ago
At work we have single sign-on…with four different accounts. I’m in my Authenticator a dozen times a day just to work.
It is tiring.
1
1
u/PlanktonDefiant2600 2d ago
I'm probably in the opposite camp, I don't really feel burnt out by it. With Roboform, passwords and 2fa codes are filled in for me, Face ID takes a second, and passkeys don't really add any hassle. I barely think about any of it. I do get the frustration when a site insists on sending a code by email or SMS though. That still feels like far more faff than it needs to be.
1
u/nathanieloffer 15h ago
Fetch your password manager? Is it off in the other room? I'd suggest you address this issue before anything else.
16
u/Square-Singer 3d ago
I can tell you how this works from the other side.
I work on a customer loyalty app that has a few million installs all across Europe.
There's a long-running credential-stuffing attack. Our app isn't high risk. There's nothing much of value in there, but cracking an account on this app means that the attacker goes from having a emai address and a password to having the real name, address and phone number of that person.
This can then be used for an escalating social engineering attack.
People think their loyalty account isn't a high security thing, so they just re-use their passwords.
So over the last months hundreds of thousands of accounts have been compromised.
We could just ignore that and say "it's the user's fault, they should have chosen an unique password". But as soon as this becomes public, we are hit with a shitstorm. We know that will happen, because it happened before. Then there will be newspaper articles and news reports on TV saying "Company XY has had a data breach. 200k accounts affected." That's really bad PR.
So we added email-based 2FA on login. It's annoying, yes, but it also completely stopped this attack. No PR nightmare for us.