3 ms·
Isn't 2FA the best approach? I'm just asking. A problem here where I work is that every application must have a different password and it must change every 90
by Gargoyle888 12y ago
Isn't 2FA the best approach? I'm just asking.
A problem here where I work is that every application must have a different password and it must change every 90 days. Consequently everyone has a spreadsheet with his passwords written down because nobody could possibly remember them all.
It seems to me that with 2FA, one simple password is adequate. Two independent devices need to be compromised and brute force is ineffective since the turn around time is at least several seconds between tries.
- tjbiddle 12y agoOne simple password is never adequate as that then trains the user to continue doing that across other sites - regardless of their use of 2FA. I've found the best solution for me is to use a password manage (Personally, I use LastPass) and enable MFA/2FA across everything that allows it.