A bit like the awful workflow around developer agreements in App Store Connect. Every few months our CI breaks because Apple has updated one agreement or another and someone has to go pester the executive who's marked as the account owner and has legal authority to sign new agreements to unbreak our CI.
It's also impossible to delegate this authority to anyone other than the account owner, and there's no concept of shared or service accounts, so nobody other than the account owner, with access to their 2FA method is able to do this.
Heaven forbid if the account owner was ever to put their 2FA method as a personal device / phone and then leave the company.
All of these, too.
Then for some goddamn reason i no longer can just input the username and password: for one of the developer accounts it has decided that i also have to decide wether i want to authenticate with an apple device, or by password. So it's another couple of clicks i can't get rid of
Years ago when the ARM China CEO held the company hostage with the company seal, there was much reporting that exoticized seals. But I was just thinking, the modern systems we've built with 2FA aren't much different!
(Product idea: seal that also prints time and TOTP?)
It's also impossible to delegate this authority to anyone other than the account owner, and there's no concept of shared or service accounts, so nobody other than the account owner, with access to their 2FA method is able to do this.
Heaven forbid if the account owner was ever to put their 2FA method as a personal device / phone and then leave the company.