4 ms·
Two-factor is getting to be a necessary feature for sites... HOWEVER, there are always ways around two-factor auth. Some sites have some special codes that you
by mathrawka 13y ago
Two-factor is getting to be a necessary feature for sites...
HOWEVER, there are always ways around two-factor auth. Some sites have some special codes that you are advised to print and carry around with you. Some sites let you verify your personal information to turn it off.
What it comes down to is how secure are:
- the methods of disabling two-factor auth
- the methods involved when you lose your two-factor auth token/device
And let's not forget:
- the methods invovled when you forget your password
- customer service intervention methods (i.e. social engineering)
Putting a "Look we support two-factor auth! We are super secure!" message out there is always a red flag for me, as to how they have counter measures in place for the above scenarios are very important... as that is what the evil people will do.
- rdl 13y agoI wish there were an "account recovery as a service" company to handle this kind of thing, since everyone gets it wrong. Just a cheap outsourced callcenter or web service for low end consumer services, all the way to an in-person or onsite (notary or bank equivalent) for the really important things.
- kumarski 13y agoI wish the same thing specifically for domain names and hosting.