3 ms·
Please critique this wild-ass idea of mine: When the user makes their first purchase, print out five identical business cards and send it to them by snail-mail
by desdiv 9y ago
Please critique this wild-ass idea of mine:
When the user makes their first purchase, print out five identical business cards and send it to them by snail-mail. (If you're selling physical products then obviously ship it with the product).
The front of the card is a regular business card; the back says "Use this code for a 10% discount on your next checkout: correct-horse-battery-staple-OTOP-backup-code" and a OTOP QR code.
When the user uses the discount code during checkout, offer them a 20% discount if they scan the QR code and successfully setup 2FA.
This way you "trick" the user into properly setting up 2FA and also holding five physical copies of their OTOP backup code in a fairly innocent looking format.
- mcgrath_sh 9y agoI throw out every business card I get with a package. I never scan the QR codes. I can only imagine the nightmare of recovering 2FA for someone who was tricked into setting it up without really understanding it. Just getting my relatively technically savvy mom on a passowrd manager took some work.
- desdiv 9y agoIt's fine if the user throws it out. The whole scheme is optional and the code is never activated until the user types it in first. The user can either: 1. Throw it away. Then nothing happens; no 2FA is set up. 2. Type in the code in for a 10% discount. Again, no 2FA is set up so the user's security is never worst off than before. 3. Type in the code and setup 2FA. This is case the user is tech-savvy enough to properly setup 2FA and successfully authenticate with it (in order to claim the 20% discount) so they (hopefully) realize the importance and convenience of the pre-printed physical backup codes and will (hopefully) stash them away somewhere safe.
- recursive 9y agoThe problem happens when someone claims the 20% discount, but doesn't understand that they need to keep the card.