Call me paranoid, but I have a hard time seeing the push for 2FA as anything other than a plot to collect valuable user data
Exactly. Mostly when I see companies like Google, Facebook, etc constantly trying to trick me to activate it. And yes, I say trick: The option to ignore/skip is always hidden/disguised, totally ignoring the UX and accessibility needs.
This and the fact that the input text fields already have my phone number populated on them ...and are just waiting for my consent.. this does not inspire trust, no.
Another interesting thing most people don't realize is that if you switch IP addresses Google demands a phone number for Gmail login, even if the account has no 2FA and no phone number was specified initially. "Give us some phone number to log in". Isn't that strange from security perspective?
Comments
Call me paranoid, but I have a hard time seeing the push for 2FA as anything other than a plot to collect valuable user data
Exactly. Mostly when I see companies like Google, Facebook, etc constantly trying to trick me to activate it. And yes, I say trick: The option to ignore/skip is always hidden/disguised, totally ignoring the UX and accessibility needs.
This and the fact that the input text fields already have my phone number populated on them ...and are just waiting for my consent.. this does not inspire trust, no.
Another interesting thing most people don't realize is that if you switch IP addresses Google demands a phone number for Gmail login, even if the account has no 2FA and no phone number was specified initially. "Give us some phone number to log in". Isn't that strange from security perspective?
Exactly: the dark-pattern design speaks to the true motivation behind this push... and it ain't security.