3 ms·
> to always using the most secure method available. If they can't use the method they were prompted to use, they can choose a different MFA method to sign in I
by firstlink 3y ago
> to always using the most secure method available. If they can't use the method they were prompted to use, they can choose a different MFA method to sign in
It doesn't work that way, and everyone who has thought about the problem space for 10 seconds knows it doesn't work that way. What a farce. MFA is only as secure as the least secure set of factors which will let you in; for multiple choices of a second factor, that means it is only as secure as the least secure choice available. It is misleading to reference "the most secure method available" because security is not a function of the initial choice of method, only of the whole available set.
That's not to say there's not a use to this sort of change, but it is second- or third-order: keep users on "the most secure method available" so that the others can be disabled soon.