3 ms·
If I cannot present any of our agreed methods of identification (login + 2FA, login + 2FA recovery code or login + recovery email) then I do not want a human to
by proactivesvcs 4y ago
If I cannot present any of our agreed methods of identification (login + 2FA, login + 2FA recovery code or login + recovery email) then I do not want a human to be able to unlock my account. That's how we get compromised. This is exactly what 2FA is designed to protect against.
- smt88 4y agoI had this issue despite having full access to multiple other factors. I was stuck in an automated fraud detection loop.
- derbOac 4y agoAlthough I more or less agree with you, I think the intuition is that some "common sense" method of identification should work. E.g., you should be able to identify yourself with government-issued ID somewhere or something. I think the frustration is that at some level, e.g., the 2FA device is being privileged over something like a notarized government verification of identity by a living human. So although I agree that you shouldn't be able to just e.g., call on the phone and ask nicely, it seems like for important accounts there should be some protocol for doing it involving some real-world chain. When everyone has 2FA, 2FA backup keys become kind of impractical in the same way it becomes impractical to remember all your passwords.
- suramya_tomar 4y agoYou realize that it is fairly easy to create false ID's right? There are services that do that for you with minimal fuss. > When everyone has 2FA, 2FA backup keys become kind of impractical in the same way it becomes impractical to remember all your passwords. This statement makes absolutely no sense. If you can't remember your passwords (and even if you can) you should use a password manager. The same can also hold your recovery keys. I also have a printed copy of the recovery codes in a file as well.
- proactivesvcs 4y agoI'm in two minds about this. Look at the abusive, popular services that demand government-issued ID when signing up or "because of suspicious activity". Once that data is breached, which is only a matter of time, how useful are such IDs as proof of ownership? In theory (and in practice for those who care) recording recovery data is simple and quick but for the same reasons passwords are failing us, seem to rarely be recorded.
- pohuing 4y agoCouldn't you just have centrally managed identities that Google can call upon? If I lose my German id, I'll get a new one and the old keys associated with that one will no longer work for the state run identity verification provider iirc