So, apparently , which does not offer token or app authentication, uses easily-spoofed browser-provided data to determine whether or not to trigger its SMS authentication.

It's insane to me that a ** of all places could be such a failure on basic measures.

Guess I need to start shopping around for a new account.

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.