Conversation

Replying to and
Twitter doesn't even allow you to use a security key if you don't have app-based 2FA. If you disable app-based 2FA, it disables your security key. They've historically pushed people to use SMS 2FA with TOTP as an additional step. They used to treat TOTP as they do security keys.
2
6
Their choice to force users to buy specialized hardware to use security keys and to disallow using keys without enabling SMS or TOTP. Needing to input a code is a terrible user experience. It's less convenient in addition to being far less secure. SMS has availability issues too.
1
1
I use 2FA across a ton of sites and only a few like Google and OVH allow you to only use security keys. Google are the only ones allowing you to use the phone's TEE/HSM as a security key. Standard feature available to any app without any special privileges. Why not use it?
1
Show replies