Because it’s too tightly bound to a mobile device. It seems I’ve lost access to one of my email accounts for an indefinite amount of time. I’ll skip the name of the service, it’s not very important. Today I tried to log in and failed because of their 2FA.
- Their mobile app somehow lost my account. That sucks.
- I still know the password, I can’t log in without going through a recovery process.
- Their recovery process requires access to my old SIM card.
- Luckily I have it and got the SMS
- Then it asked for a PIN. I don’t have one. I assume they introduced PINs after I set up my 2FA account. Fine, I can skip this step.
- Next, I had to answer a default security question like “What’s the name of the street …”. I know the answer, but I don’t know whether it’s case-sensitive.
- Anyway,The system refuses to accept any of my attempts.
- Now I have to go through a long process of convincing their security team that it’s actually me.
- I’m not sure it’ll work out. I hope as the last hope I’ll be able to send them my passport data
So, why do I hate 2FA? Because it’s supposed to be a security measure. But instead it’s almost always a suffering measure.