4 ms·
We deal with this almost every week, as in, we get into systems by searching through email:password leaks and use them. There are a number of mitigating contro
by iraklism 9y ago
We deal with this almost every week, as in, we get into systems by searching through email:password leaks and use them.
There are a number of mitigating controls that can be applied here. Most will hamper usability, some will not.
There is a “simple” solution. Enforce 2FA. If not at the login, then before “dangerous” actions (transfer funds , change password , buy X/Y/Z )
- methodover 9y agoThat was one of the ideas that we pitched to the CEO. Only sensitive actions would require 2FA. CEO shot it down, saying it would require too much work on the part of the customer.
- lphartley 9y agoThat's a simple solution from a security perspective. From a business perspective the most simple solution is guaranteeing that you'll cover all the damage customers might possibly suffer.