YohanYukiㆍ요한・謝雪
I'll never understand why banks in the Philippines, as well as FinTech (coughtechcough) companies, love to use the weakest(!!) and most expensive(!) TwoFactorAuthentication: SMS / Text.

It's mid-2024 already. /facepalm

Privacy Security 2FA
SkyKnight2
Maybe because everyone in Pinas has access to SMS, the same can't be said for other methods of 2 factor a. How many people in the Philippines use yubi keys?
YohanYukiㆍ요한・謝雪
Yubi keys are generally used by companies only, and only by companies who values their security.
YohanYukiㆍ요한・謝雪
2FA is available for everyone. Since most people have an Android or iOS smartphone, they can install any 2FA app. There are plenty of reputable ones to choose from too.
YohanYukiㆍ요한・謝雪
It is also more secure and practically free to setup on the provider's side. I for one can set it up in any server in less than 30 minutes. Compared to SMS-based, which is the weakest and expensive (you have to pay for each request).
YohanYukiㆍ요한・謝雪
I worked with one coughITcough BPO once. When they got a client that started to use 2FA to access their tools, they complained a lot. Too expensive. Too much of a hassle. Too much this and that.
YohanYukiㆍ요한・謝雪
I was only an ordinary agent, and regardless, I intervened, I asked them what their alternative is, and this BPO company said they have an IT team and processes that can secure access.
YohanYukiㆍ요한・謝雪
Immediately, I showed them how the client's 2FA is easy to use, and won't cost them anything (on the BPO side). And even if their IT and processes fail, the 2FA can still secure access. Unless someone kept the QR code or secret key in an unencrypted way (which they did any way, LOL, because they refused to use encryption).

In any case, they were convinced.
YohanYukiㆍ요한・謝雪
They just refused to learn it first because they rely too much on old systems, and always think there's cost involved. On the contrary, it's practically free with the added benefit of it being more secure. ^_~
SkyKnight2
Which 2FA app do you recommend? Preferably, non-google ones. I don't trust google, none of my phones or tablets have google.
SkyKnight2
It seems we can't like comments here on Plurk. too bad.
YohanYukiㆍ요한・謝雪
For 2FA, I suggest using an offline one: KeePassXC supports 2FA; and you don't have to save the QR code file itself.
YohanYukiㆍ요한・謝雪
You can then upload it to an encrypted cloud service to sync it with your other gadgets. Or setup Syncthing for direct offline sync'ing.
YohanYukiㆍ요한・謝雪
If Twilio's Authy wasn't compromised multiple times, I would've recommended it. ^_~
YohanYukiㆍ요한・謝雪
Today, the best is to keep important data offline and try to sync it offline/directly instead of passing through a cloud storage (especially not the no encryption ones like Bing, Google, Dropbox, Box, etc.)
載入新的回覆