top | item 34775657

(no title)

kl4m | 3 years ago

1 - Create a Twilio account.

2 - You need to add a phone number and receive a SMS challenge, before setting up any other 2FA method

3 - With the Authy app installed on your phone, the token is instead instantly added to your account upon reception of the SMS. This cannot be disabled. Use a very particular combination of steps in the account settings to convince it to let you use a simple offline TOTP app instead.

4 - Use your recovery code every month and repeat the whole thing because somehow all other 2FA methods break simultaneously for all Twilio accounts set up with that phone number.

The experience was so awful I had to delete the App and the account.

discuss

order

rsync|3 years ago

Agreed.

Their process is ridiculous and is matched only by the insane password requirements that they recently implemented (I think they required a 18 character password ? Or 24 ?)

However, I am entwined in their ecosystem for all of my texting and calling and message management, etc., so I am forced to deal with it.

In fact, their clownish requirements were the impetus behind the 2FA Mule[1] experiment which I now use across almost all services.

[1] https://kozubik.com/items/2famule/