I’m so fucking sick of Google and other sites ratcheting up ““security”” and bullshit steps to “”“”“”“”““protect””“”“”“” me when they don’t give half a rat’s ass about any individual welfare or security. like they literally don’t give a shit about any of us but this stupid fucking forced 2FA crap and mobile-tied-to-all-account-actions-on-desktop Google got aggressive on is pissing me off beyond anything else. this shit is forced on us only to remove themselves from any claims of liability.

I use a password manager for years (keepassdx & keepassxc) to generate absurdly long random passwords and change them at least yearly. no shady downloads on my PC, no pirated stuffs of any kind, I’m computer savvy in general and run a tight ship. recently trying to clean up (log out) some old mobile sessions on my Google account, and change my main account password, things I’ve done quickly and without hassle in the past. suddenly being asked for password AND forced to tap the stupid fucking number sent to my Android phone, which of course I don’t receive because it’s sending to some stagnant Android session that was overwritten by my various Android and GrapheneOS installs (tinkerer).

completely stonewalled on my own account now. can’t change password any more because the shitty little kindergarten secret passcode doesn’t send to my current accessible Android install, can’t log out old devices to keep it from being sent to those. tangential note, last year the rent payment portal for my shithole apartment added forced 2FA to all accounts too, never had it before and shit was just fine, but now an extra step and waste of my fucking time just to pay the do-nothing landleech who lives in a different fucking state.

so fucking pissed I could break someone’s face rn. fuck everything. fuck capitalist-infected software. fuck techbros. fuck Google. fuck AI. fuck Flock. so tired of this endless fucking bullshit that keeps getting worse. thanks for hearing my TED talk.

  • SootySootySoot [any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    17 hours ago

    Some systems force you to use push notifications. But for most things, if you’re on Linux (maybe there’s a Windows equivalent) you can actually use the oauthtool command to (half-)pretend you’re doing MFA.

    You usually have to say “give me a code for my authenticator app”, then run oauthtool --totp <code> and get the code that way. Still a pain but the joy is that you don’t need any second device included at all.

    I’m suddenly not certain - possibly you can just keep that code like a second password and run oauthtool on any device to get a valid code? I’m not sure but huge if true.

    • citations_wheated [none/use name]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 day ago

      yeah it was great! it came out of nowhere, no warning or announcements, no consent requested or opt-in offered.

      I added an exception to my cookie and data clearing extension for the portal which, naturally, decides at random times to invalidate the session data, so I have to do the 2FA challenge anyway.

  • Lussy [he/him, des/pair]@hexbear.net
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    Is there even a point to passwords anymore? Apparently, every password I’ve ever made has been leaked and I need to change them asap. Had a password that was the alphanumeric equivalent of a Polish last name, even that was stolen

    • doubledealer [none/use name]@hexbear.net
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      Passwords are low cost, easy to set and replace, and provide some level of assurance that is appropriate for some use-cases. They’re also totally valid as a second factor (something you know) to work with a second factor (something you have like an OTP generator, or something you are with biometric representation).

      Is there a point to password complexity and periodic rotation? Something you can’t memorize or know like )*%KOPohinOaifniionaf probably doesn’t provide more security than a passphrase like LargeBatteryHorseStaple.

      Single names or words with numeric substitutions fall into the category of “easy to guess” password and are used in dictionary attacks, especially when those passwords are discovered in password database breaches. You, the end-user, have no idea how well I am protecting your password in my service, I could have them all in a plaintxt file on an open fileshare. You can have the most complex secure 256 character password of all time but if it’s not adequately protected by the service provider it’s worthless.

      The mitigation for this without 2FA is having a unique password for every account so that when somebody’s password database is breached, they can’t go use your password somewhere else.

      If you can afford a Yubikey that’s honestly a great option if the service provider supports it.

      • chgxvjh [comrade/them, he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Is there a point to password complexity and periodic rotation? Something you can’t memorize or know like )*%KOPohinOaifniionaf probably doesn’t provide more security than a passphrase like LargeBatteryHorseStaple.

        That’s nonsense.

        4 words from a dictionary of 50k words are 50000^4 permutations.

        20 characters from a dictionary of 26 lower case + 26 uppercase + 10 digits + 12 special characters are 74^20.

        log10(50000^4) = 18.8

        log10(74^20) = 37.4

        The 20 random character password has roughly as much entropy as a password made up from 8 random words not 4.

        If a weak hashing algorithm is used the 4 word password can be cracked in a year on a single GPU. The random character password is practically uncrackable.

        • SootySootySoot [any]@hexbear.net
          link
          fedilink
          English
          arrow-up
          2
          ·
          17 hours ago

          Point being that nobody cracks passwords anymore, sitting around running dictionary attacks on your GPU is not a very common attack vector. Most systems are using more complex, salted hashing now. Most common attack vector, far and away, is reused passwords being leaked.

          So long as you’re using unique passwords, 4 words is, in real-world conditions, almost exactly as safe as random characters.

        • VoOe704c@lemmygrad.ml
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          Yes it should not be 4 words, the recommendation is 7 words I think, or 6 words + one number. Otherwise the point is correct, for passwords you need to memorize a passphrase is usually better from a human perspective.

          Related: https://xkcd.com/936/

          • chgxvjh [comrade/them, he/him]@hexbear.net
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            Randall Munroe is comparing to a way weaker password. Just one word with some snapped out character and some special characters.

            I don’t think 7 words are practical to type in any more. And honestly 4 words should be fine, more important that you don’t reuse the password. And you have to trust the provider to no longer use md5 in 2026.

      • Lussy [he/him, des/pair]@hexbear.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        If you can afford a Yubikey that’s honestly a great option if the service provider supports it.

        First time hearing about this, can you expand on this to a baby brain?

        • doubledealer [none/use name]@hexbear.net
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          They have a pretty good picture and description showing how one would use such a key as a second factor for authentication:

          From https://fidoalliance.org/specifications/

          I’m pretty sure Amazon, Google and Microsoft still support using these. It is kind of a crapshoot after that if a business or site will support it.
          It’s also $30 for one you have to stick into a USB port, or $60 for one with NFC that you can just wave over your phone. I have 2. Key #1 for everyday use and Key #2 that’s stored separately in case anything happens to Key #1 like losing it or the dog eating it.

  • doubledealer [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    14
    ·
    2 days ago

    The 2FA isn’t to protect you, it’s to reduce the cost Google has to pay to recover accounts and mitigate any damage somebody stealing accounts could do, and to limit their liability if personal data was somehow compromised due to SFA. It also makes it easier for them to use your account for fuckshit in the future, like banking or healthcare if and when they choose to go there.

    I migrated off Google about a year ago for email when there was the fake scare about them using email data for AI training. Now I just use Google for Youtube. Self-host my own cloud, Jellyfin, etc. etc. It’s tradeoffs but IT is a skillset and hobby I like, and its nice not being beholden to any Big Tech besides my email provider. I highly recommend it if the option makes sense to you.

    • citations_wheated [none/use name]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      yeah I’m with you on the rationale these companies use to force 2FA on everyone. I understand lots of internet users are sloppy and uneducated about the risks of easy and shared passwords and it has basically always been like that. I’d like to gtfo Google for good but this is not the moment for that (can’t delete the account anyway while it’s soft locked like this). and my current problem, I fear, is either never going to get fixed or will be at the mercy of whatever LLM bot Google has put in charge of support tickets.

  • StalinsGiantSpoon [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    10
    ·
    2 days ago

    I use a password manager for years (keepassdx & keepassxc) to generate absurdly long random passwords and change them at least yearly.

    the vast majority of people don’t do any of this, hence the need for 2fa. there’s like 8 ways you can get a code from google, just set it up to send you a text message with a code. your rage over 2fa is pretty funny to me, it’s not that serious. you can probably put TOTP into keepass or whatever too so you dont need your phone for 2fa. i do that for plenty of sites with 1password. take a deep breath.

    • citations_wheated [none/use name]@hexbear.netOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      it’s not that serious.

      yeah, it is. this never happened before and now I literally can’t change anything on my account to break out of this verification loop. it always worked in the past, always. and it hardly ever came up unless changing CC info or something sensitive. now I’m on stock, fresh installed official Android 17 and nothing is working, not even the alternate methods they offer to verify work. either an error or just… nothing. this is a fucking joke. quick search on reddit confirms others dealing with this exact scenario starting around 9 months ago.

      it’s cool that this is all entertaining for you though, glad to hear it.

      • doubledealer [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        7
        ·
        2 days ago

        True. OP or anyone considering will need to evaluate their risk posture and tolerance. If somebody wants to steal my Google account, have fun posting spam on Youtube I guess?

        Having a second password database for the TOTPs in a second location and separate from the username/pw database could be a decent compromise.

        • mattdaemon [none/use name]@hexbear.net
          link
          fedilink
          English
          arrow-up
          6
          ·
          2 days ago

          Having a second password database for the TOTPs in a second location and separate from the username/pw database could be a decent compromise.

          That’s what I do.

            • doubledealer [none/use name]@hexbear.net
              link
              fedilink
              English
              arrow-up
              3
              ·
              1 day ago

              The issue is that personal password databases aren’t unique, they can copied (and I’d argue should be, securely, for backup purposes) and the usernames, passwords, and TOTP seeds contained within can also be copied and stored anywhere. So proving unique possession of a KeePass database is impossible and it wouldn’t be a real second factor, like say a hardware Yubikey with a digital certificate unique and bound to only that hardware Yubikey.

              In this case of a keepass database storing TOTP seeds, it’s single factor with 2 different “something you know” authenticators. Which to your point isn’t nothing, but it’s not to the same level of security of real multifactor authentication.

              To your last point about device encryption password as a subsequent factor, you’re describing authentication in the chain of access. Oldschool security design used to say that if something was behind a VPN, and your VPN required MFA, that would be good enough. The problem is that getting around a VPN isn’t impossible. So chain of access authentication is only as strong as the weakest link, and isn’t near as secure as requiring MFA.

  • tombruzzo [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    We need to login to all this shit to prove we’re human yet the website at work is getting slammed with direct traffic from Singapore which is probably all AI bots. What is Google doing about them?

    • reader [they/them, she/her]@hexbear.net
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      They’re doing their best to make hardware keys suck too

      I’m literally a professional and ““passkeys”” (FIDO2) still fuck me over every 2 weeks or so despite me intentionally never using them

      want to use your yubikey in U2F mode to sign into the google account you configured it as a 2nd factor for on a new machine? TOO BAD, microsoft windows has decided you must use FIDO2, with a PIN, and even then it’s just going to give you a cryptic error about “hardware key not recognized”. (and yes I know, my fault for using windows, but every so often I have to, it’s not my daily driver)

      Same problem on Android, the FIDO2 rollout utterly broke U2F, and FIDO2 is an overcomplicated turd that isn’t a direct replacement for U2F and has limited support from sites/services…

      And that’s on top of the issues OP is experiencing, which is MFA rollouts being done without user consent, often in invasive and insidious ways (vendor lock in is everywhere), or in ways that actually reduce security rather than raise it (looking at paypal here, among other sites)

      All this to say, yubikeys are pretty good but they definitely won’t stop you from pulling your hair out about 2FA