Accounts that send a 2fa code to your email rather than using the 2fa code generator you've already setup for that account - eviltoast

Recent examples Twitch and Firefox 🤦

  • Fubarberry@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    18
    ·
    1 month ago

    A bank I used for a mortgage has mandatory text message 2fa if they think you’re on a new device (won’t allow google auth/etc). And web browsers like firefox/brave block enough cookies/etc that it requires the “new device” authentication everytime I log in.

    Problem is, for a couple months there was some delay with their text messages. It would take 10-20 minutes to send your 2fa code, and the code would expire after 5 min, meaning that by the time you got the code it was always expired and unusable.

    Made it completely impossible to log in to pay my mortgage payments. Led to some really frustrating talks on the phone about how I didn’t want to pay with a credit card over the phone, I wanted them to fix their damn system so I could log in and pay via bank transfer like usual.

    • JohnWorks@sh.itjust.worksOP
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 month ago

      Ah yeah I remember I had a service that had a delay with sending the 2fa code (can’t remember if it was email or sms) but it got to the point where it was basically gambling on if I’d get into the account on that day or not lol. Glad it wasn’t as important as mortgage payments though that sucks to hear.

    • Mr_Blott@feddit.uk
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 month ago

      What century do you live in where you have to actually log in to pay your mortgage?! 😂