4 ms·
Sounds like the website is too friendly and should implement dumb security questions and multi factor device authentication instead.
by smellsinore 5y ago
Sounds like the website is too friendly and should implement dumb security questions and multi factor device authentication instead.
- Crosseye_Jack 5y agoNo real need to. However they should be storing hashed passwords instead of plaintext. If they are not, I dread to think what the underlying account codebase is like. 2FA is nice for extra account protection but this site doesn’t jump out to me as something that _needs_ it. Not a fan of recovery questions personally. Recovery questions are just an extra step to password recovery. The thing is, they are generally either answers that are publicly a available if you know who the account belongs to or they are filled with red-hearings which often just gets forgotten by your “average jo/e” because they are rarely used. However I wouldn’t say this website is very friend to data security. It’s well know that your average joe will reuse passwords. It only takes one DB dump to now have email/passwords which can be spammed into other more sensitive sites.