3 ms·
Where I work they use RSA 2fa keys. I have the app on my phone. You would receive a link in the work email, and by clicking it, it would add the token to the RS
by devn0ll 7y ago
Where I work they use RSA 2fa keys. I have the app on my phone. You would receive a link in the work email, and by clicking it, it would add the token to the RSA app and give you the 2fa keys every 30 seconds.
After a few months, I bought a new phone so I had to get a new link (I thought). But even the IT guys are saying: Nah man that's too hard. Just use the same link you received months ago.
It worked. There is no time-out on those links!!!!. A link we receive in a plain-text email!!! Some of our inboxes are shared / have a PA attached.
But nooooo, this is not a security problem AT ALL... :-(