this post was submitted on 20 Mar 2025
5 points (100.0% liked)

Hacker News

981 readers
320 users here now

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

founded 6 months ago
MODERATORS
top 7 comments
sorted by: hot top controversial new old
[–] Infernal_pizza@lemm.ee 5 points 23 hours ago (2 children)

It always annoys me that SMS is less secure than other methods, yet 90% of sites seem to want you to add a phone number as a recovery method anyway meaning you can just bypass everything else

[–] WhatAmLemmy@lemmy.world 4 points 19 hours ago

It's to track you, plus it's the easiest to implement, so it's win win for them. Without some sort of regulation against it, companies will always do what is most profitable.

[–] Whitebrow@lemmy.world 3 points 19 hours ago

It’s not about security, it’s about data mining

[–] bigboismith@lemmy.world 1 points 17 hours ago

You're password is 100% non crackable assuming the services you use take password security super seriously

Spoiler alert: they don't

[–] rumschlumpel@feddit.org 1 points 1 day ago* (last edited 19 hours ago) (1 children)

I'd be more inclined to use 2FA if the second factor wasn't usually a mobile phone, which can easily (much more easily than a laptop or desktop pc) be lost, be stolen or break, is harder to repair, and generally running software that is far more insecure than what is running on my PCs, especially if you get into the specifics of how that 2FA works - SMS isn't secure, and authenticator apps generally require the official app store (Google or Apple), i.e. they don't work well on something like LineageOS or GrapheneOS.

You can probably use something like Yubikey or a more privacy-friendly authenticator app on Github, but many other services won't give options like that.

[–] ThrowawayPermanente@sh.itjust.works 1 points 19 hours ago (1 children)

Aegis is compatible with Google Authenticator, works with Graphene, and allows encrypted backups.

[–] faintwhenfree@lemmus.org 1 points 18 hours ago

Aegis also let's you be power user, you can share your 2fa generators with other people, I've been needing independent way to access many accounts with a family member and aegis makes it the easiest.