• 0 Posts
  • 125 Comments
Joined 2 years ago
cake
Cake day: January 1st, 2024

help-circle


  • A feature that will not do anything unless you explicitly press a button to start using it is quite literally opt-in, though? Opt-in doesn’t mean “I won’t even know the feature exists without hunting through the settings”. It just means that it won’t start doing things without your consent. Presenting a way to provide that consent in a more visible place than buried deeply in the settings does not make it opt-out. It might be a bit annoying to you, but it has no effect on your user choice or privacy, especially if there’s also a way to globally hide it and any other features like it, including new ones that might be added in the future.


















  • even if you steal my password (database)

    That’s a big leap you’re doing there, equating stealing a password to stealing a password database. Those are very different. Stealing a password can be done through regular phishing, or a host of other methods that don’t require targeted effort. Stealing a password database, if properly set up, is a lot harder than that. It depends of course on what password manager you’re using, but it usually involves multiple factors itself. So equating that to just a password, no matter how strong and random, is just misleading.

    Mind you, I agree that it’s less secure than “proper” MFA, and I’m not saying that everybody should just use MFA through a PW manager. I am using physical security keys myself. But for a lot of regular people that otherwise just couldn’t be bothered, it’s absolutely a viable alternative that makes them a whole lot safer for comparatively little effort. Telling them they just shouldn’t bother at all is just going to create more victims. There is no such thing as perfect security, and everyone has a different risk profile.