Either by sending a code to SMS or Email, you are able to sign into your account without ever needing to or being able to add a password. Why has this become a thing recently?
Either by sending a code to SMS or Email, you are able to sign into your account without ever needing to or being able to add a password. Why has this become a thing recently?
Because the password still needs to be correct. What if the thief has your phone but no password
If a thief already has your phone unlocked then nothing else matters, you’re fucked and all your accounts are compromised.
There’s lots of factors for everything isn’t there. If a thief has your phone unlocked then yes you’re pretty much knackered
There’s no other factors when a thief already has your phone unlocked, which is why it’s a bad point to use against passworldess authentication in this argument.
Password reset?
But they don’t have access to your email in this instance.
If the thief has your email and password and phone then you’re SOL
If they’ve got your phone with your 2FA they’ve also got your email on your phone lol
If they don’t have email access, why is a passwordless magic link sent to an email bad then?
The tech “enthusiasts” of Lemmy are really showing their arses in here lol. They have a “I took 2 semesters of computer science so I’m somewhat of an expert” level of understanding and mentality.
There’s a reason most big tech companies are starting to move to passwordless logins. If 2FA is the ultimate protection about unauthorised access, the password is ultimately irrelevant - and given all we know about password reuse and data breaches, getting rid of them is a good thing.