Hacker News new | ask | show | jobs
by mindslight 1503 days ago
Why not a law that prohibits companies making people jump through any of these arbitrary hoops in the name of "security" to begin with? Authentication requirements should be straightforwardly understandable, future-predictable, and fully changeable by the user. Not opaque, always changing, and top-down set by the company for their version of "security". This goes doubly when there is no customer service to sort things out with.

PS stop validating their top-down model by referring to SMS nags as "2FA". It's snake oil for the corporate motive of demanding identifying information.