Comment on FLOSS communities right now
myxi@feddit.nl 9 months agoThey force you to enter your phone number if your IP address is fishy, or if your email provider is not popular.
Comment on FLOSS communities right now
myxi@feddit.nl 9 months agoThey force you to enter your phone number if your IP address is fishy, or if your email provider is not popular.
banneryear1868@lemmy.world 9 months ago
Enforcing two factor because of suspicious indicators isn’t bad on it’s own though, it’s privacy concerns about Discord preceding this which makes it a bad thing in this context.
technom@programming.dev 9 months ago
Using phone numbers as second factor authentication is neither secure, nor is it in good faith. Force the customer to use something more anonymous and secure - like Fido keys or even TOTPs. Sneaking in ways to force the customer to reveal their personal details, in the name of security is a sinister dark pattern.
banneryear1868@lemmy.world 9 months ago
Phone number is the weakest form of 2FA but it’s still an improvement. I’ve never had to use my phone in Discord though, I don’t how Discord would even verify someone’s phone number as legitimate. But like I said I have a couple Discord accounts with different emails, probably on 30-40 servers, and have never run in to this. So if they’re collecting personal details in this really granular and specific manner, it seems like they’re not doing a very good job at it.