You are a two factor app. I should never be in a situation where there is an unexpected login I need to verify.
You are a two factor app. I should never be in a situation where there is an unexpected login I need to verify.
If there's a chat app I installed 3 years ago, with no intention of giving it camera access, and I suddenly need to use that app for a video call, I don't want to be stuck debugging broken camera issues for two hours. I'd much rather have the app tell me that it doesn't have camera access.
I can actually confess that this hit me. Almost nothing on my phone has permission to use my camera, including my web browser (why???). I assume this was done in a fit of pique upon discovering that the setting even existed.
Roll on (god knows how many years later) and I cannot get into the gym with the link I was emailed to have my browser read a QR because my browser is just a grey screen. It was only when the member of staff suggested permissions that I realised what was going on.
I'm the problem, it's me
Unfortunately Google isn't really exposing this to users, so you need something like App Ops or adb to set it up.
There’s a similar thing going on with emails. Dozens of services ”decide” that you need to update your email address, because ”they can’t reach you”. Many of them even stop sending you emails you explicitly subscribed to, perhaps to maintain an archive, ”because you don’t seem to open them”.
No, dear Linkedin and others, you’re reaching me just fine, and it’s none of your business whether, when and where I open them. Maybe I just read my emails offline and strip your tracking links (and avoid clicking on links in emails in general).
Inexplicably LinkedIn’s UX for changing the old email address, the one they cannot reach you at (!), to a new email address, starts with confirming your current email address (THE ONE THEY CANNOT REACH YOU AT). Brilliant.
On the one hand it helps avoid "permissions fatigue" that the user just has the one permission to manage ("enable notifications"), but on the other hand it does lead to these questions about why an entire class of applications (banking apps and security apps) whose role should be mostly never to send notifications (because that can be a FUD/fear/fraud vector) need notifications enabled to work securely.
Isn't that kind of the point? If someone else is trying to login somewhere with your credentials, your two factor will ping up?
I guess you can make the argument that you are then made aware of login attempts, but that feels more like something the host service should control.
Because to get that far they entered your password? Which you might like to change?
You did mention: "You are a two factor app."
If they've got past your first factor, you might want to know.
1. Introduce passwords
2. Introduce email-based reset flow
3. Introduce 2FA (optional)
4. Someone says "take the password reset flow, trigger it automatically when a user tries to log in and has only given their email, hide the password field during login, and after the email is validated drop the user back to their previous journey instead of having them set a new password"
5. You see #4 as #3 failing, but when #3 was never applied it's not quite that. Aside: making #3 mandatory would be smart.
This has been going on since at least 2006.
Startups will "growth hack" by buying e-mail lists and feeding them into their password recovery tools.
A certain percentage of people will then follow the links and end up creating a new account on a service they had no interest in that now has their confirmed contact information, a new user, and a plausible reason to bombard them with marketing email.
The account was supposedly registered for an organization whose name was somewhat similar to mine, so I thought somebody fat-fingered their coworker's email (the initial email was an invitation to create an account and join the org), but it might have very well been the tactic you described.