3 ms·
Isn't the idea you would have 2 factor auth on your account preventing any web brute force. Then generate API keys on a per project reducing the attack surface
by nullandvoid 6y ago
Isn't the idea you would have 2 factor auth on your account preventing any web brute force.
Then generate API keys on a per project reducing the attack surface in the case of breach?
- Nextgrid 6y agoYes that’s correct, but if you choose to not use 2FA for whatever reason I don’t see why password auth shouldn’t be supported on the API instead of making you waste time generating an API key that won’t actually improve security in any way (since attackers can brute force the account anyway).