7 ms·
A session token is "something you have" and paired with the password being "something you know" it's still 2fa. Whether making that conversion or allowing disa
by eldridgea 6y ago
A session token is "something you have" and paired with the password being "something you know" it's still 2fa.
Whether making that conversion or allowing disabling of 2fa without requiring the user to do a full authentication with both their password and a code is debatable. But 2fa is two of something you "know", "have", or "are" which password + session token meets.