Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think 2FA should be mandatory. Leave that decision to me, the user.


The potential impact of a breach doesn't just affect you, and their security decisions should be made with a wider consideration of concerns than the short lived frustrations of users.


It varies, I guess. For a normal end-user account on a system where no interaction between users is possible, it pretty much just affects you.

For some kind of admin account with privileged access to other users' data, then it definitely affects others.

One might expect increasing mandatory security measures correlating with increased potential damage of a breach. Similar to safety measures on mass transit vs. personal vehicles.


Your liberty starts where mine ends. By the same logic password complexity should be left up to the users as well, but what responsibility is this user willing to shoulder when they are the reason sensitive information leaks?

I’m sure most people on HN have great passwords stored in password managers, but 99.9% of users are not like that, so mandatory 2FA does not only make sense, it’s the only reasonable choice for sensitive information.


Agreed! Any service with mandatory 2FA isn't one I want to use. I'm just fine with passwords so far.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: