4 ms·
While I think this is great overall, I think it’s terrible they’re just going to disable 2FA on accounts with no other options come the deadline. They should ha
by Operyl 4y ago
While I think this is great overall, I think it’s terrible they’re just going to disable 2FA on accounts with no other options come the deadline. They should have just kept it enabled, but force the change on next login (or user interaction) so at least there is _something_ protecting them until the switch can be forced. If the fraud allegations are to be believed, just rate limit the attempts to once an hour and identify the fraud accounts (seems they already have) to take action on.