@funnymonkey I kinda get it. There's some threat modeling involved. The risk here is that someone steals my laptop and manages to unlock it. That's a much less likely event than someone compromising a login DB and trying to auth with my creds from Serbia.
Conversation
Notices
-
Embed this notice
Tek say resist (tek@freeradical.zone)'s status on Friday, 27-Dec-2024 02:16:59 JST Tek say resist
-
Embed this notice
funnymonkey (funnymonkey@freeradical.zone)'s status on Friday, 27-Dec-2024 02:17:00 JST funnymonkey
Why, oh why, do sites do this?
When we evaluate the customer facing security of sites, "features" like this need to be explicitly flagged as undermining basic security practice -- in this case, underminig 2FA.
-
Embed this notice
Tek say resist (tek@freeradical.zone)'s status on Friday, 27-Dec-2024 02:31:39 JST Tek say resist
@funnymonkey For sure. OTOH, 2FA probably doesn't add much but anger to domestic abuse.
-
Embed this notice