The answer is yes, and the TL;DR is not to use them, use 2FA, and not share personal details online (which is hopefully all obvious advice)

cross-posted from: https://lemmy.world/post/12060980

  • flatbield@beehaw.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    9 months ago

    Security is always porous. The article really had no suggestions. They say 2FA but account recovery is often a combination of access to you email account or questions. None of this stuff is particularly secure.

    So yes security is an advanced feature usually not provided and normal users do not even try at being secure no do most systems insist on it.

    Edit: Some sites are doing away with passwords and just sending and email with a link to login. Totally not secure but account recovery has long used the same method so it may not be actually reducing security much since there never was much security.