Isn't that kind of the point? If someone else is trying to login somewhere with your credentials, your two factor will ping up?
Isn't that kind of the point? If someone else is trying to login somewhere with your credentials, your two factor will ping up?
I guess you can make the argument that you are then made aware of login attempts, but that feels more like something the host service should control.
Because to get that far they entered your password? Which you might like to change?
You did mention: "You are a two factor app."
If they've got past your first factor, you might want to know.
1. Introduce passwords
2. Introduce email-based reset flow
3. Introduce 2FA (optional)
4. Someone says "take the password reset flow, trigger it automatically when a user tries to log in and has only given their email, hide the password field during login, and after the email is validated drop the user back to their previous journey instead of having them set a new password"
5. You see #4 as #3 failing, but when #3 was never applied it's not quite that. Aside: making #3 mandatory would be smart.
This has been going on since at least 2006.
Startups will "growth hack" by buying e-mail lists and feeding them into their password recovery tools.
A certain percentage of people will then follow the links and end up creating a new account on a service they had no interest in that now has their confirmed contact information, a new user, and a plausible reason to bombard them with marketing email.
The account was supposedly registered for an organization whose name was somewhat similar to mine, so I thought somebody fat-fingered their coworker's email (the initial email was an invitation to create an account and join the org), but it might have very well been the tactic you described.