• 2 Posts
  • 74 Comments
Joined 2 years ago
cake
Cake day: July 9th, 2023

help-circle




  • I appreciate that 2FA can be annoying, but I’ve personally had my info leaked in various breaches, and (software) 2FA has been the thing that’s saved my important accounts. They manage to get as far as the TOTP and stop, because it’s an additional lock that’s harder to bypass than a static password. It’s easy to say it’s just a pointless hurdle when you’ve been lucky enough to have avoided having your data leaked.

    I know none of the other things they do come out of legitimate care for their users and I know this isn’t ultimately any different

    You are right that companies don’t care about users like us, but many of these protocols came from cryptographers and software engineers who do care. The Diffie-Hellman-Merkle key exchange underpins most of public cryptography, and it wasn’t created for big business. Regardless, big companies do care about big clients, who are often desirable targets for hackers.

    So these locks and protocols exist because a relative few people genuinely care about security, and the big companies implement them as correctly as possible, because they care about not getting sued for negligence by a big client or losing their business.

    You’re right to be cynical about corporations, but that doesn’t mean we can’t get mutual benefit from their self-interest.