While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.
While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.
It's about email as single factor auth, which has become very trendy of late. You just enter your email address, no password, and the email you a code. Access to your email is the only authentication.
- Enter an email address or phone number
Thats not just email, that's also SMS.
That's not MFA. MFA stands for multi-factor authentication. If the authentication only requires a code sent to an email OR phone number, that's just a single factor.
I must be in the wrong bubble, I have not encountered any site that does this since the 2000s. It was a minor trend around then IIRC.
Patreon can do that too, depending on how you sign up.
The entire email login flow is completely retarded. It’s not even secure.
Email link to reset is better, email link + another auth (usually sms) is even better.
Its super odd if you land on facebook.com-profilesadfg.info/login thinking its just Facebook and try to login but get a "password reset" email. Most people would be confused as they don't want to reset their password.
Having it for every login means that just missing the website URL, everything else is 100% legit.
It’s about single factor, password logins, using a one-time-token
The very first bullet point states: Enter an email address or phone number
That insinuates email OR SMS.
It doesn't just mention email only.
The authentication factors of a multi-factor authentication scheme may include: 1. Something the user has: Any physical object in the possession of the user, such as a security token (USB stick), a bank card, a key, a phone that can be reached at a certain number, etc. 2. Something the user knows: Certain knowledge only known to the user, such as a password, PIN, PUK, etc. 3. Something the user is: Some physical characteristic of the user (biometrics), such as a fingerprint, eye iris, voice, typing speed, pattern in key press intervals, etc.
Email and phone are both in category one, comprising only one unique factor.
If you have access to the phone, you can log in. OR if you have access to the email account, you can log in.
You don't need to know the user's password, you only need access to one of these inboxes and nothing else. One-factor authentication, but worse, because there are multiple attack surfaces.