Skip to content

Comment on Ask HN: Best practices for stolen session detection?parent

Comments

This is where you want 2FA really.

Each time the user logs in from a new "client" ask for a 2FA code from something like their phone.

Things like Authy and Google Authenticator make this relatively painless to implement.

We already implemented 2FA, but it's not yet forced for everyone. You don't want to patronize your customers ;)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.