I personally am fine with this.

You are viewing a single thread.
View all comments View context
4 points

twitch has TOTP

permalink
report
parent
reply
17 points
*
Deleted by creator
permalink
report
parent
reply
3 points

Before I deleted my accounts there, I remember twitter and facebook deactivated your account for “suspicious activity” if you did not provide a phone number when making it, and the only way to reactivate it was to give them your phone number.

permalink
report
parent
reply
0 points

true. But I think that’s mostly to make bots harder to create. Not as easy to get a phone number than an email address

permalink
report
parent
reply
4 points
*

A convenient scapegoat for getting your PII so they can sell your data at a higher value.

permalink
report
parent
reply
3 points
*
Deleted by creator
permalink
report
parent
reply
2 points

I had a lot of success with this: https://phonegenerator.net/

permalink
report
parent
reply
5 points
*

As the other commenter said, only if you give them your phone number, and only through that garbage authy that does not use standard TOTP, but some proprietary crap, specifically made for twitch.

And if you give them a phone number, which another user will also try to use in the future, then the secret used for TOTP can change in any moment, which means if you exported the secret to e.g. Aegis and deleted that tracking filled garbage that is named authy, at one point the codes just won’t work anymore, and you’re practically locked out. Apparently support should be able to help, but they don’t give a single fuck.

permalink
report
parent
reply
4 points

and only through that garbage authy

you can use any TOTP app. I use bitwarden

permalink
report
parent
reply
2 points

How? How do you import the secret key to it? Are they finally showing a proper QR code when setting it up?

My account is still locked to authy, and the support pages I have read are written as if it would still work through authy for everyone.

permalink
report
parent
reply
1 point

What’s wrong with Authy?

permalink
report
parent
reply
4 points

First of all, that they are totally unnecessary for twitch to be able to provide 2fa authentication.

Other than that, their app has tracker components, all secret keys are stored in the cloud, who knows whether that’s encrypted, but on your phone’s storage surely not, if yours is rooted you can just view it in a file manager and copy it to a normal code generator app.
Generally they support standard TOTP code generation, but for twitch they are using some weird shit that generates 8 long numbers (instead of the standard 6), of which the middle 2 is the same so they drop one of them, and then also codes expire in third the time as it is normally.

permalink
report
parent
reply

Technology

!technology@lemmy.ml

Create post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

Community stats

  • 3.5K

    Monthly active users

  • 2.9K

    Posts

  • 43K

    Comments

Community moderators