Brutkey

bamfic
@bamfic@autonomous.zone

Dear banks:

If I am using an authenticator app or even a modern day passkey to auth to your website, STOP REQUIRING EMAIL OR SMS 2FA ON TOP OF THAT YOU FUCKING DINOSAURS.

Thank you for your kind attention to this matter.


bamfic
@bamfic@autonomous.zone

After some time on the phone with tech support, and some experimentation, I have concluded that modern day banks have totally given up on web browsers and making their websites accessible, and only support apps anymore. I fucking hate apps. I don't want apps. But if you are using a browser, you are apparently considered a security risk and they don't want you around.

🧠🧠 Austin
@austinross@social.lol

@bamfic@autonomous.zone that’s totally backwards. I hate the corporate web.

bamfic
@bamfic@autonomous.zone

@austinross@social.lol Brain-melt moment: tech support person said: "The workaround is, now that you we have you validated and logged in, don't ever clear your cookies on your browser". As soon as they said that, they seemed to immediately realize how stupid it sounded, and backpedaled, adding "even though clearing cookies is good security practice". Right. It is, and that's why I do it. Made it very clear that their security systems are not designed to support browsers at all. It's apps only.