this post was submitted on 09 Feb 2024
1480 points (95.5% liked)

Programmer Humor

18961 readers
1121 users here now

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules

founded 1 year ago
MODERATORS
 

4 pane comic of dolan on the left and spooderman on the right

pane 1 (dolan): cum join opensurce cummunity!
pane 2 (spooderman): shure! how joyn?
pane 3 (dolan): Here discord! (with discord logo)
pane 4 (spooderman with tears in eyes): y u do dis?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 8 points 6 months ago* (last edited 6 months ago) (1 children)

They force you to enter your phone number if your IP address is fishy to them, or if your email provider is not popular.

[–] [email protected] 2 points 6 months ago (1 children)

Enforcing two factor because of suspicious indicators isn't bad on it's own though, it's privacy concerns about Discord preceding this which makes it a bad thing in this context.

[–] [email protected] 1 points 6 months ago (1 children)

Using phone numbers as second factor authentication is neither secure, nor is it in good faith. Force the customer to use something more anonymous and secure - like Fido keys or even TOTPs. Sneaking in ways to force the customer to reveal their personal details, in the name of security is a sinister dark pattern.

[–] [email protected] 1 points 6 months ago

Phone number is the weakest form of 2FA but it's still an improvement. I've never had to use my phone in Discord though, I don't how Discord would even verify someone's phone number as legitimate. But like I said I have a couple Discord accounts with different emails, probably on 30-40 servers, and have never run in to this. So if they're collecting personal details in this really granular and specific manner, it seems like they're not doing a very good job at it.