I see google security site now seems to have a new option ... I probably need to explore that, or yubikey
17/06/2020 19
Securely signing in to Google just got easier
Google is improving 2-Step Verification so you can use Google prompts to sign in securely and better protect your account.
Prompts are push notifications that are sent securely to your phone. Because they don’t use SMS, they’re safe from emerging SMS-based threats.
Google sign-in prompts will be able to reach every eligible phone where you’re signed in after July 7, 2020. In most cases, other 2-Step Verification options will continue to work as backup second steps.
Google is going to automatically enroll 150 million users and two million YouTube creators into using two-factor authentication for their accounts by the end of the year, it announced on Tuesday.
Buy a cheapo throwaway mobile and a £10 SIM card and use that for 2FA - Job doneI'm wary of it as too many have used 2FA as a data harvesting excuse and you then get SMS spam of sales and other irrelevant junk - usually with a premium rate number needed to stop it. They'll only get my number when I know I'll do regular business with them.
This. I treat any 'account' I have on anything without MFA as essentially not secure.If I can enable 2 factor authentication to secure something, I always do.
When we rolled out MFA at work, the sheer number of users getting confused as to what the # key was, was shocking.
Microsoft either say the hash key, or the pound key.......hundreds of our users contacted the helpdesk asking what it was....despite the user guide saying "press the # key"
In the end, we had to include a photo pointing to the # key.
found it
I bet the next time you did instructions you remembered to put an "EXAMPLE" across the example image and a note underneath "Scan the image that looks similar to this that appears on screen"I did instructions for one of my clients and one of the user was trying to scan the QR code on the instructions rather than on screen. There's only so much you can do!
I did instructions for one of my clients and one of the user was trying to scan the QR code on the instructions rather than on screen. There's only so much you can do!
Sort of ironic that of all the sites online you don't have to hand over anything to use porn sites not even age verification.
Authy makes things pretty simple for me, so I tend to have it control 2FA for all sites that are either important or can access some kind of payment / banking data.
I don't like using the phone 2FA because someone could sim swap and gain access to your texts or you could lose your phone or have it stolen. I've found having hardware keys is the best because you can have spares ones encase you lose it, and nobody can hack it.