That will probably help the community help you.
If you go with passwords, you already have a risk vector for resetting passwords. Skip the password and the reset.
Make the login link expire after 10 minutes so they attackers only have a short window.
* Something you know (memorizing a password, PIN, whatever)
* Something you are (biometrics)
* Something you have (2FA, passkeys, OTP keys)
I think all three have been done in various combinations, and each have their pros and cons. Of those, I personally find Passkeys to be the easiest to use, especially with password manager that can sync across devices.
I’m on vacation in a city hundreds of miles from home. My plane ticket is on my phone. I drop my phone and break it, needing a new one. How do I get logged back in on my new phone, to get access to my ticket, so I can catch my flight home?
In my particular situation, 2FA was forced upon me by Apple some time earlier. Through dumb luck, I happened to bring an iPad on my trip which I was able to use for 2FA to get logged back in and get home. If I hadn’t brought a 2nd device, or wasn’t in my home locations (with the setup you mention), what do I do?
A lot of people have a phone as their only device these days. 2FA, or location dependent 2FA seems really bad. I don’t know how people recover when a primary, or their only, device is lost/broken?
I have since setup a recovery key with Apple. I’m planning a trip in a couple weeks. I’m thinking I need to write down my recovery key and keep it in a money belt, so if something goes wrong I have a way to get at my data, so I can get home. But is the average user going to do any of that? No way. This all seems like a huge risk.
>>>pinged last phone battery 0%? oki >>>zero signs of activity? on all logged in devices?yes? oki >>>last time of signs of phone activity on all devices? device 1, 2:00pm device 2 5:00pm device 3 10:00pm?+++prompt the user someone is trying to login from out of oh hey but the user usually goes to sleep around this time...... account for that too...
+++360 video selfie of yourself with saying your simple phrase? super manual... has to be reviewed by a human. super anti- ai >>you got a new phone should be no problem right?*** +++time specific passcode:: time sensitive lets say the user picks 12:05pm to 12:10pm on their time the ui matches this with the time whatever country their in. >>>if the user doesn't login in their phone within the last 72 hours something maybe less idk >>>as for the keys your right is not seamless how about a passcode interface that ---how many times do people go about not** bringing their phones vs breaking their phones on another country? ----prompt what country their going to? ----ping the user on all logged in devices with activity thats someones trying to log in. i think google and amazon already uses this called 'OTP' they send it over to your email(mind you, you have to be logged in your email) ---lets check off all of these first and then give you this option.kinda thing -----an idea of a wireless SSD ring auth comes in mind for super auth purposes scenarios like this only. vs having to write down what recovery key. but this is super specific scenario... i too have encountered 2FA like... when my phone battery died. i was trying to login on the library computer...maybe prompting the user of simple 4 digit number combo before the phone dies? 2 image combo out of 9 images presented at front?
have a button appear which allows restricted access only...
Yes, I could have talked to the front desk at the hotel and had them call a cab, and pay for that with a credit card. And then also do something like that when I got home to get back to my house.
It’s a lot of extra steps and extra expense. Last time I took a cab from the airport it was almost 5x the price of an Uber, and I had to listen to the cab driver talk shit about Uber the whole time.
tree#5737cherry۲ bird#115٨lime۲ those fancy symbols are arabic numbers they act as seperators : ۲ = 2 || ٨ = 8
with my my name oompa loompa:: L#oompa٨149۲ oompa#L۲149٨ #Loompa٨O۲115 the original idea was alot more complicated but harder to burn ::: banana#4680٨yellow۱۲ tree#5791٨cyan۱۲cherry =======
tree#cyan۲cherry -----ticket backup only!!!\ not 2FA! --- i added emojis here but hackernews wont display em
Who gives a shit if someone logs in as me on that site? And why would anyone bother?