3 ms·
One thing not mentioned that I like is having 2FA be non-enforced for a set period of time after enabling it. So you still have to enter it the next N days, but
by C4K3 8y ago
One thing not mentioned that I like is having 2FA be non-enforced for a set period of time after enabling it. So you still have to enter it the next N days, but if you set it up wrong or did something stupid you can disable the 2FA without authenticating with it within that period. The only place I can think of where I've seen this is facebook.
That also prevents scenarios like the one given about the user never writing down their 2FA details. (Though the recovery codes should not work for enabling 2FA in the first place.)
Thinking about it, it might make sense to have it non-enforced for the next N logins rather than basing it on time. Or perhaps make it non-enforced for the first login that happens 24 hours after 2FA setup. I haven't seen it implemented this way anywhere yet.
- carbocation 8y agoThis doesn't make sense to me. Either you confirmed that it's working (by tapping your key or entering your token) or you didn't. Why prevent the user from actually securing themselves in this fashion?
- tedunangst 8y agoUsers don't actually realize the implications of "you will never login without this key" until they forget the key. That doesn't happen at the moment of enrollment, but only the day after.
- C4K3 8y agoI see it as an improved method of confirming that it's working. For power users it may be pointless, but for the average user who probably has never used any kind of 2FA (perhaps besides SMS) it makes them go through the real motions of authenticating with 2FA before turning it on for real, which will prevent many stupid user mistakes (which I admit I've done myself once.) I think it's a major improvement for ease of use in exchange for having a small once off window where you're not protected by 2FA.