1522

4 pane comic of dolan on the left and spooderman on the right

pane 1 (dolan): cum join opensurce cummunity!
pane 2 (spooderman): shure! how joyn?
pane 3 (dolan): Here discord! (with discord logo)
pane 4 (spooderman with tears in eyes): y u do dis?

you are viewing a single comment's thread
view the rest of the comments
[-] myxi@feddit.nl 8 points 4 months ago* (last edited 4 months ago)

They force you to enter your phone number if your IP address is fishy to them, or if your email provider is not popular.

[-] banneryear1868@lemmy.world 2 points 4 months ago

Enforcing two factor because of suspicious indicators isn't bad on it's own though, it's privacy concerns about Discord preceding this which makes it a bad thing in this context.

[-] technom@programming.dev 1 points 4 months ago

Using phone numbers as second factor authentication is neither secure, nor is it in good faith. Force the customer to use something more anonymous and secure - like Fido keys or even TOTPs. Sneaking in ways to force the customer to reveal their personal details, in the name of security is a sinister dark pattern.

[-] banneryear1868@lemmy.world 1 points 4 months ago

Phone number is the weakest form of 2FA but it's still an improvement. I've never had to use my phone in Discord though, I don't how Discord would even verify someone's phone number as legitimate. But like I said I have a couple Discord accounts with different emails, probably on 30-40 servers, and have never run in to this. So if they're collecting personal details in this really granular and specific manner, it seems like they're not doing a very good job at it.

this post was submitted on 09 Feb 2024
1522 points (95.6% liked)

Programmer Humor

18244 readers
1 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 1 year ago
MODERATORS