I have always refused to use 2FA and I don't feel the need and I'm not actually interested.
I know it's just an extra security layer but I'm fine and I don't want anything extra. At my own risk, I know it. I don't want to bother to look at how it works, to use a google product and to waste my time searching how to use an alternative that may be not working for all websites.
Trully, that's good for Kraken but not for me, I may ever look at another alternative. Even banks don't use it.
Hi LeGaulois. I would highly suggest
reading up on 2FA. What happens if your email is compromised? The hacker could very easily see that you're signed up for cryptocurrency exchanges, request your username & password, log into your account and take the balance in it's entirety. Even if your email has a very long and strong, randomly generated password that doesn't protect you from
data breaches affecting your email accounts.
do they still allow a static password for a 2fa? i remember that was true several years ago but i'd be amazed if they haven't removed that option. it's really insecure. proper 2fa is composed of "something you know" (password) and "something you have" (like TOTP authentication on your phone).
i thought this statement from the OP meant you need to use one-time passwords at kraken:
Now, Two Factor Authentication has been made a requirement by the exchange. There are now two options available to the clients—Google Authenticator and YubiKey.
Hi figmentofmyass. Static passwords are still an option, but aren't recommended if you have access to Google Authenticator or Yubikey. As you mentioned, they are the least secure option out of the three.
Also, interesting that Kraken haven't added SMS/phone calls as a means of 2fa verification. Perhaps setting that up would present too much of a cost for them? I'm not sure, but there are certainly people who would prefer SMS over authentication apps.
Hi magneto. While I should never say never, it's extremely unlikely that Kraken will ever offer SMS/phonecall 2FA. If this is the only option on other websites, it's better than no 2FA, but it's certainly
not as secure as other methods. On Kraken the most secure option would be a Yubikey, followed by Google Authenticator.