Especially when you generate one-off passwords with enough entropy to busy an attacker until the heat death of the universe. OTPs are not meaningfully increasing security in that scenario.
A password is something you know, but password reset is a bypass for that factor. They could drop the option of password reset and thereby eliminate that vulnerability, but I presume they don't because that would inevitably result in people getting locked out of their accounts.
That's not something fundamental to passwords. It's just that the culture of security in the industry seems to be more willing to lock people out of their account when they lose the factor they have than when they lose the factor they know.
It's just that the culture of security in the industry seems to be more willing to lock people out of their account when they lose the factor they have than when they lose the factor they know.
It could be that losing what you have is easier for people to remedy than a forgotten password, but somehow I suspect that it probably comes down to which one generates the fewest angry customers/calls/support tickets. Maybe it's easier for us to blame ourselves if we forget to carry a token or our cell phone?
Comments
MFA is inconvenient
Especially when you generate one-off passwords with enough entropy to busy an attacker until the heat death of the universe. OTPs are not meaningfully increasing security in that scenario.
That statement directly contradicts the article.
A number of accounts would have been accessed were it not for 2FA.
The best password won’t save you if a reset email is intercepted.
Something you have plus something you know should be what we cone to expect from any service that deals with anything of importance.
A password is something you know, but password reset is a bypass for that factor. They could drop the option of password reset and thereby eliminate that vulnerability, but I presume they don't because that would inevitably result in people getting locked out of their accounts.
That's not something fundamental to passwords. It's just that the culture of security in the industry seems to be more willing to lock people out of their account when they lose the factor they have than when they lose the factor they know.
It could be that losing what you have is easier for people to remedy than a forgotten password, but somehow I suspect that it probably comes down to which one generates the fewest angry customers/calls/support tickets. Maybe it's easier for us to blame ourselves if we forget to carry a token or our cell phone?
That doesn’t make too much sense. An intercepted password reset email requires access to the email account. That’s a whole different scenario.
If both the email and DO account are behind strong, unique passwords, that won’t happen from a mere DO email leak.
Now, if the same, weak passwords are used for both accounts, sure. That’s terrible practice. But it’s also not what the GP was talking about.
The article is about a security breach at a company which sends emails. This scenario requires access to the email, the email account is irrelevant.
I am astonished by the amount of people commenting under an article they obviously didn’t read…
You must be new here.