3 ms·
If the user logs in from a device we haven't seen before, or they haven't logged in for more than a year (or six months, or two weeks etc), send them an email c
by evan_ 3y ago
If the user logs in from a device we haven't seen before, or they haven't logged in for more than a year (or six months, or two weeks etc), send them an email challenge.
Maybe the email address on file is also cracked but it'll make it harder, and it's more work for the attackers.
- g-b-r 3y agoKeep in mind that will force everyone who doesn't keep cookies to have to do that at every login. Github is like that right now, and it's quite a pita; sure, it's not a great idea to continually delete all cookies without exceptions, but in some cases it's currently hard to avoid it (low-end smartphones where Firefox is too heavy)
- JeremyNT 3y agoIt's a perfectly reasonable compromise though if you can't force MFA for some reason. There are many sites which do this today. You don't even need to rely on the cookie if you're worried about the ux for cookie clearers. You could also whitelist an IP address (or even a subnet) when they verify the email, and it would have been "good enough" to prevent this particular situation.
- g-b-r 3y agoYes true (if you do use cookies though it's probably better to let the user disable the check, after explaining the risks)
- evan_ 3y agoThat's true. Also, if I cut my keyboard in half, it's a lot harder to use Google Docs. I sympathize, but at a certain point if you've gone out of your way to disable the features that the developers have added to make your life easier, you just don't get to complain about it.
- g-b-r 3y agoAt least don't tell me it's "developers making my life easier"...
- fennecfoxy 3y agoBut then that kills UX for people on VPNs.
- evan_ 3y agoDo VPNs break cookies? Not sure I follow. Personally I’d rather be a little bit annoyed when I log in to my account than have my DNA stolen or whatever.