If maybe 5% of the accesses the site requires authentication (the other 95% passthru cause you have the cookie) - make that 5% use a text code to your phone. EDIT: App on yr phone, not an SMS
No more passwords.
If maybe 5% of the accesses the site requires authentication (the other 95% passthru cause you have the cookie) - make that 5% use a text code to your phone. EDIT: App on yr phone, not an SMS
No more passwords.
https://www.wired.com/2016/06/hey-stop-using-texts-two-facto...
There's plenty of stories around of spear phishing attacks involving attackers taking over the victim's phone number. Mobile operators are notoriously vulnerable to that sort of shenanigans.
I'm not sure about Microsoft, but Google supports several other 2FA mechanisms in addition to SMS.
1. every site to obtain some automatable way to send text messages, which can get mildly expensive,
2. people to acquire at least one burner phone for authentication because they don't want $randomwebsite to have their real phone number, and
3. users to give up some degree of anonymity because the country of origin can't be hidden behind a proxy, as the phone number gives it away.
This sounds like an overall loss for everybody to me.