If you think forcing everyone to carry an object other than their phone around so they can use 2factor with it when they already have their phone so they can use it for 2factor with other things you are delusional. Or if you said I need to go to my laptop when I’m logging in on my phone and vise versa… that’s nonsense too.
Authy on my phone is just as “dumb” as Keychain on my phone.
How else are you imagining this should work that you could get normal people to do?
WolfLink@lemmy.ml 7 months ago
Traditional 2FA (assuming you mean apps with codes) can be done from the same device (if you have the app with the codes installed on that device).
It doesn’t defeat the purpose of 2FA. The 2 factors are 1. The password and 2. You are in possession of a device with the 2FA codes. The website doesn’t know about the device until you enter the code.
plz1@lemmy.world 7 months ago
Yeah my point is it does not protect the local device well. It does protect well from remote compromise though.