this post was submitted on 17 Jun 2026
244 points (94.9% liked)

Technology

85515 readers
4205 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Grimy@lemmy.world 18 points 15 hours ago (2 children)

I changed banks when they asked for 2FA.

[–] Natanael@infosec.pub 6 points 11 hours ago

In Sweden the banks offer a choice between an app and a hardware token. You can just go with the token then.

[–] yestalgia@lemmy.world 9 points 14 hours ago (2 children)
[–] eager_eagle@lemmy.world 2 points 7 hours ago

Probably SMS or in-app 2FA. That's what annoys me about banks: they claim to do things for security -- which in their case it makes sense because they don't need to harvest data to make money -- but then go ahead and roll their own instead of using standards.

[–] Grimy@lemmy.world 17 points 14 hours ago* (last edited 14 hours ago) (2 children)

I refuse to have a phone line. I only get one for a month when I'm looking for a job. Got tired of paying a subscription fee just to get spam calls. All my communication is done through messaging apps and the only time I don't have access to wifi is when I'm driving.

[–] pageflight@piefed.social 15 points 13 hours ago* (last edited 13 hours ago) (2 children)

And because SMS 2FA is actually opening a common attack vector. I have yet to find a credit union I qualify for that uses TOTP or Yibikey.

[–] Cethin@lemmy.zip 3 points 12 hours ago

That still requires getting personal information about the user, which is often enough without 2FA. 2FA still makes it more secure than not having it. It's still a vulnerable step though, so users should be aware of that.

[–] Frozengyro@lemmy.world 2 points 12 hours ago

Start talking to someone at the credit Union. They are run by people, you might be able to convince them the risk and implement a safer method

[–] Cethin@lemmy.zip 2 points 12 hours ago (1 children)

Just a heads up, you can get a free phone number from Google, and probably other providers. If you've got a computer of some kind and an internet connection, you can make calls and texts from there. If that's all you're getting a phone for, don't bother with the actual device.

https://support.google.com/voice/answer/115061?hl=en&co=GENIE.Platform%3DDesktop

[–] cecilkorik@piefed.ca 4 points 9 hours ago (2 children)

I don't know about Google's "free" numbers, but third-party VOIP numbers are usually blocked for 2FA verification. I've tried that. Most places won't accept it, because they know you're trying to get around the tracking. The 2FA isn't the point, and the cost of the phone isn't the point, the tracking is the point, and Google's "free" numbers are absolutely tracking you just as effectively as any telecom is.

[–] Cethin@lemmy.zip 1 points 57 minutes ago

Yeah, it isn't good for 2FA, and obviously your data is being collected. If all you need it for is job applications though, it does that.