npm: set up 2fa on your account
me: can't be bothered, it's not like I publish packages anyway
npm: 2fa! 2fa! 2fa!
me: FINE
<go to login page, enter username and password>
npm: For your security, we've sent a one-time password to your email address
me: <enter one-time password from email>
npm: 404
genius work, npm people.
@sil sending otp to the same email that gets password reset tokens gains nothing.
@sil That is well it might practically work but it's a problem that shouldn't happen. If you lose your OTP tokens (because you store them on your phone only and lose that) then you should forever lose access to your account.
Being able to get access back by social engineering is a security issue.
@juliank @falken that is rather hostile. People lose their phones. A service built for users to like should deal with that, rather than using it to further punish you. If you lose your wallet, you can ring your bank and cancel the cards and get new ones. If e we can’t even be as user-friendly as banks, who are notoriously customer-hostile, what are we doing as an industry?
@sil Banks are getting really problematic at least in Germany with their user-friendliness.
They have taken the mantra "your phone is your 2nd factor", so now all you need is aside from login details, is to pair your phone with an SMS code, and then you register your fingerprint and then you use the fingerprint to log in to your phone, log in to your app, and approve transactions.
It's a real shit show.
But as for cards, they don't send you new virtual ones. They mail physically.
@juliank @falken my point here is: we should be, in my opinion, attempting to be friendly and planning how to deal with mistakes when they happen, rather than taking the attitude that if someone screws up then they lose. I think you're taking the opposite approach, which I don't agree with. My fault for using banks as a rhetorical flourish; you're right that they're also terrible, which was the point of using them as an example that we could be better than, but it's derailed the discussion.
@sil There are various different levels of security needs, and some of them may very well be life and death, or at least professional life and death.
Like you should not be able to recover my GitHub account without any of my 3 registered 2FA tokens.
my work SSO account.
my medical insurance account.
Like it is reasonable if you use electronic identity document functions or do a video call where you present ID but not "hello I am Julian and I was born on ... I lost my 2fa codes"
@sil answer: use the back up codes we gave you, or get a new account. Sometimes falling back to physical verification would be acceptable but it depends what were talking about securing. Some random site ? Just get a new account.
@falken if it's some random site where you don't care about abandoning the account and getting a new one... why bother having extra-secure 2fa OTP codes for it?
@sil you'd have to ask Microsoft they run npm
@falken what happens if you lose your phone? Answer: you have to email everyone to get the codes reset. Your email account is the ultimate fallback.