Elektrine lite

← Feed

@s0@cathode.church

Post #2534153

2026-05-14 07:38 UTC

My bank just emailed me to say that because I haven’t used my two factor auth recently (they only require it for specific actions), they’re disabling it on my account. What kind of a batshit security posture is that?!!

Replies (19)

  • @mike@social.chinwag.org 2026-05-14 07:40

    @s0@cathode.church if it leads to fewer support calls, it's gotta be good

    Open ##2894294

  • @arichtman@eigenmagic.net 2026-05-14 07:43

    @s0@cathode.church (slow clap)

    Open ##2894296

  • @daedalus@eigenmagic.net 2026-05-14 07:53

    @s0@cathode.church amazing. I should send their CISO one of my Security Bandage stickers.

    Open ##2894297

  • @futzle@old.mermaid.town 2026-05-14 08:01

    @s0@cathode.church This is MyGov levels of Can’t Computer. Edit: No, it isn't, because MyGov can at least do TOTP now.

    Open ##2894298

  • @jpm@aus.social 2026-05-14 08:22

    @s0@cathode.church lol that’s fucking amazing

    Open ##2894304

  • @maloki@rage.love 2026-05-14 11:11

    @s0@cathode.church that's the dumbest thing I've ever heard

    Open ##2894305

  • @0@corteximplant.com 2026-05-14 11:45

    @s0@cathode.church oh no.

    Open ##2894306

  • @apz@some.apz.fi 2026-05-14 13:09

    @s0@cathode.church This seems like the logic where they realised 2FA is a lost cause for an average non-technical person and they try to pre-emptively solve all the login issue tickets by applying a fix like this.

    Open ##2894307

  • @s0@cathode.church And if you still don't do anything, they'll give access to your account to 13 random people?

    Open ##2894308

  • @thatgalsilver@zoner.work 2026-05-17 06:53

    @s0@cathode.church Sadly I've seen worse. Had an account that wouldn't let me log in without e-mail verification, despite acknowledging I had two factor authentication, because it couldn't verify that the two factor authentication was secure. It's because they only "approved" of Google Auth and I used Ente Auth, so they treated my two factor auth as invalid.

    Open ##2894311

  • @gurkan@has.siktir.in 2026-05-17 10:31

    @s0@cathode.church was 2fa optional? You know what.. I don't want to know, I'm not sure which answer is worse :cry_flork:

    Open ##2894312

  • @sockke@chaos.social 2026-05-17 11:40

    @s0@cathode.church I can't remember which bank it was, but i once couldn't change my online-banking password because changes to the profile were only allowed from 10:00 to 16:00

    Open ##2894313

  • @deborahh@cosocial.ca 2026-05-17 13:08

    @s0@cathode.church @JoBlakely@mastodon.social bank-internal austerity theatre? "Look, we saved all those 2FA calls!" (that weren't being made, anyway) 😵‍💫 What?!

    Open ##2894314

  • @s0@cathode.church 2026-05-17 21:57

    @JoBlakely@mastodon.social @deborahh@cosocial.ca not this one. It’s TOTP 2FA. Which they’re paying way too much to Symantec for

    Open ##2894315

  • @xinit@mastodon.coffee 2026-05-17 16:09

    @s0@cathode.church weird. Our approach was "enable 2FA or we disable your account"

    Open ##2894317

  • @s0@cathode.church 😐

    Open ##2894318

  • @SteveClough@metalhead.club 2026-05-17 19:05

    @s0@cathode.church Ridiculous. I think 2FA may well reduce the number of times you use those features that require it - which is a positive development. It makes you think twice. So I would consider that a significant reduction in use is a positive. Removing it for any reason (without your say-so) is bonkers.

    Open ##2894319

  • @hub@cosocial.ca 2026-05-17 19:36

    @s0@cathode.church mine decided to send me 2FA SMS without even asking if the number was still valid.

    Open ##2894320

  • @CauseOfBSOD@wetdry.world 2026-05-30 22:11

    @s0@cathode.church your bank doesnt enforce 2fa?

    Open ##3013722