Actually, the "lost password" flow already assumes email as a single point of failure, so I suppose my 2FA comment is moot (in other words, we should be pushing for 2FA for accounts regardless of their password approach on other accounts).
Actually, the "lost password" flow already assumes email as a single point of failure, so I suppose my 2FA comment is moot (in other words, we should be pushing for 2FA for accounts regardless of their password approach on other accounts).
This is already the case right now. An attacker who has access to your primary email account can gain access to any of your accounts using Forgot Password.
> the "lost password" flow already assumes email as a single point of failure,
Exactly. I think that was the inspiration for the idea. If we have a single point of failure anyway, why not just use it directly to login?
This is not the case when using two factor authentication.
If the goal is to separate the need to remember complex passwords from the application, then a password manager makes much more sense (ideally with 2FA).
In the long game of improving token-based security, this is a step sideways at best.
That is to say, yes, a compromised primary e-mail _is_ catastrophic, but seems like an already accepted risk. Why is this worse?
I didn't mean to imply that this was worse, only that it doesn't really change the threat.