Hacker News new | past | comments | ask | show | jobs | submit login

It used to be opt in until the icloud hacking saga where the public demanded something be done. So it was decided users want mandatory security by default. Almost all of these services provide backup codes you can write down on paper as well.

Sure, some people are going to lose their only device and the bit of paper, but at that point if you have literally nothing to identify yourself with, it's going to be hard to provide a secure service to you.




It can still be opt out with a fallback on the old approach of security questions. The name of your first pet, your favorite teacher, etc.

It doesn't matter how much in general 2FA works out better for most people, there are lots of people for whom it is not viable. They know who they are. Give them an option that doesn't make their life worse.


> They know who they are.

OP knows who they are, but I would not be surprised if many poor/homeless users wouldn't realize they need to opt out of something until they find out the hard way when they're locked out and can't get back in.


>Give them an option that doesn't make their life worse.

This is the sort of thing that really should be handled by government


That might help for a certain subset of people in this scenario, but there are also people with subtle mental conditions that, while capable of living productive lives, are also unable to deal with MFA. There are also the elderly and non tech-literate.


Optional != opt in

Just make it opt out... You 2fa, do a song and dance, and 2fa is gone




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: