Sending an email as a notification would serve the same purpose.
Sending an email as a notification would serve the same purpose.
We implemented this at Mercury recently to stop phishing attacks, and I believe Coinbase implemented it for the same reason [1].
TOTP authenticators are super ineffective at combating phishing. If a user is willing to give their email and password to a phishing site, there's very little standing in the way of them also providing their TOTP code.
WebAuthn solves this by working with the browser to tie authentication to a particular domain, but not everyone has a WebAuthn authenticator yet.
Meanwhile, email verification links are a really simple and effective way to shut down these phishing attacks. The phisher can't click the links, because they don't have access to the user's email. The user can't click the links on behalf of the phisher, because clicking the link only verifies the device that clicks the link.
1. https://www.reddit.com/r/Bitcoin/comments/2rp9o4/beware_coin...
> The phisher can't click the links, because they don't have access to the user's email.
Something here doesn't add up.
Seems like that is the problem they're trying to improve by using 3FA instead of 2FA.