Reply to post: Re: Maybe sites need two factor authentication

Some credential-stuffing botnets don't care about being noticed any more

Gene Cash Silver badge

Re: Maybe sites need two factor authentication

I downvoted you because of the ultra-shitty way most sites do two factor authentication.

For example, I got a new credit card from Capital One. Their website needs a code to log in, since it's a new unrecognized computer. Fine.

I have an option to text my phone. However it says it's not my phone... the address/name/phase of the moon doesn't match and refuses to use the number.

I have an option to have it call a number and say the code. However, when it calls, it says "no input was received. good bye" and hangs up.

I have an option to call support, and have them give me the number.

So I call, and it's one of those fucktarded systems that insists on you saying the number, instead of hitting the phone button.

Except it doesn't understand me, and tells me it will hang up on me if I don't choose something.

So you can bet I pounded some numbers, got a human on the phone, and canceled my brand new card.

And that's just the latest in a series of encounters with 2FA.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon