4 ms·
As I recall, for some consumer facing applications, the concern isn't about targeted attacks, but more about automated attacks that try to re-use passwords. In
by jf 8y ago
As I recall, for some consumer facing applications, the concern isn't about targeted attacks, but more about automated attacks that try to re-use passwords. In a scenario like that SMS is to slow down automated attacks.
Keep in mind that I don't endorse that approach! Just giving an example of a narrow case where that applies.
That said, I appreciate your feedback and will personally take your feedback to our product group.
- daveFNbuck 8y agoThat's a good answer, but it doesn't sound like a reasonable threat model for corporate single sign on. Thanks for taking my feedback to your group. I hope it helps.