4 ms·
> a 2FA email confirmation with random 6-digit code would be sent where? To _my_ email, not theirs. So you set up an email account specifically for those, and
by zrm 3y ago
> a 2FA email confirmation with random 6-digit code would be sent where? To _my_ email, not theirs.
So you set up an email account specifically for those, and put the credentials for it in the documentation. You probably want that to be hosted somewhere else though, because needing the code to access your email system so you can get the code is not a fun kind of circular dependency.
That's not limited to self-hosting though. You lose your device and therefore the saved password for Provider A, to reset it they want to send a code to Provider B, to sign into that they want to send a code to Provider A. 2FA circular dependencies are actually kind of a scourge.
- jasode 3y ago>So you set up an email account specifically for those, Sorry I wasn't clear. I wasn't looking for a "solution". I was trying to explain how one can be blind to future failure scenarios (e.g. 2FA behavior is just one example) and thus, the "admin procedures documentation" can be inadvertently flawed. It's because the owner never had a 2FA verification email for years and so completely forgets that their friend will get an unexpected 2FA random code request in the event of a disaster recovery. I edited my comment to hopefully make that more clear. >The interconnected dependencies are complicated and invisible because the recovery procedures are not stress-tested.*
- zrm 3y agoWhat I'm asking is, how is this unique to self-hosting? You set them up on Cloud Email and it asks for a phone number to create an account, then they find out some debtor used to have their phone number and they're getting calls from debt collectors, or they move and want a number in their new area code, so their phone number changes. No one thinks to update it with the email provider until they insist on sending a code to the phone number you used to sign up ten years ago. Or you set it up for them and it prompts for a backup email, which they don't have because the one being created is their only one, so you use yours thinking something is better than nothing, and now they still need the code sent to yours. How does the hosting method affect any of this?