Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Beware the Atlassian's SSO "2 factor authentication" (2fa).

I remember asking them every month years back their hand over to Atlassian - to create / enable backup codes functoonality.

Several months ago after changing countries and phones I discovered that my backup codes didn't work.

Their "support" offered me a "solution" - to delete all my boards associated with my email so that I could create fresh ones.

Zero apologies, zero explanation as of why my perfectly double-backed up 2FA codes were not working, all blames on me the user.

There were sensitive details for approx 16 projects collected daily over the span of 5 years.

That SSO 2FA is flawed the same way across all Atlassian products.

Never again would I trust my data to Atlassian.

WeKan is open source and welcome.



THIS.

AVOID whenever possible sms-based 2fa. Use totp codes.

SMS makes your phone a single point of failure [1].

I currently use the OTP feature of keepassxc, so that I can still generate otp code but can have those codes replicated on my trusted devices. You can save the seed of the TOTP and re-install the otp on other devices too.

[1] plus you should really try and depend as little as possible on your smartphones. smartphones are the leash of the third millennium. the less you are dependant on it, the free-er you are.


nowhere does the parent mention SMS - they're talking about backup codes, which exist regardless of whether you use TOTP or SMS or something else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: