It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.
It’s free, and requires a tiny bit of additional configuration to enable. No reason not to offer it.
With large enough numbers, you'll see everything, but you don't even need large numbers to get people whose lives are made more difficult by technology.
This, coupled with a "I know what I'm doing, never let support reset my password" option that disabled changing the user's password for anyone without direct write access to the production database was pretty good for security, I feel.
It great for keeping people using scripted attacks against a huge list of accounts. It isn’t really to keep people specifically after your account out.
If somebody wants your shit and specifically your shit.... they’ll get it...
How? I don't think Brian Krebs has been hacked, even though he's extremely targeted by hackers (his site is literally the benchmark for performing DDOS attacks on).
Configuring the seed, remembering an extra password to use the OTP... For me it's not that hard, but probably my mom will need some help in order to remember all the steps...
I know some services require SMS in order to force collection of user’s phone number, for data selling purposes and to prevent bots.