2 ms·
I'm a strong believer that any system that contains anything meaningful to a user should incorporate reasonable two-factor authentication. The problem is that
by reduxredacted 17y ago
I'm a strong believer that any system that contains anything meaningful to a user should incorporate reasonable two-factor authentication.
The problem is that folks in security tend to forget that they have to pay attention to the business side of things. It's e-mail.
A certificate plus pass-phrase, and a three attempt fall-back to mandatory phone authentication would be way more than enough assuming that everything under the hood was sound (DNS, SSL, etc ... which have all been shown to have weaknesses recently). Why hammer your way through a steel door when you break open the single pane window in the basement.