google authentication: my account now fragilised by mandatory shitfrastructure second factors
Here's a kick up the arse to finally migrate off google services: they've made my account authentication two-factor, with the second factors inevitably being shitfrastructure elements. There was no way to prevent it happening.
Losing my phone is probably annoying. If everything else depends on it, and thus stops working at the same I lose my phone, then it's way more annoying.
The available "second steps" are:
- SMS to a mobile number I may not have for much longer
- confirming on an android device I am currently evaluating and do not want to be tied to, and can not carry in my pocket because it's so huge
- generating a one-time code on same android device
So my access to email, calendar, contacts, documents, and a load of other stuff is now contingent on temporary shitfrastucture elements still being in place.
This kind of thing must be "best practice", because everyone does it. It must be hard to argue against a legal argument that the service provider is liable for an incorrect login because having such a second step would have or could have prevented it. But the existing mechanisms commonly offered are not the solution.
Relatedly, my Paypal account was already conveniently disabled, and had been for some time, because they made login depend on a defunct mobile number of mine, with no way to rescue the account (according to some, you can find their phone number and call them, should you still for some reason want to have an account there).
Comments
Post a Comment