🔒 Риски и ограничения двухфакторной аутентификации
Я
давно и
последовательно рекомендую #2FA в блоге и канале. В статьях я главные грабли расставлял, конечно, но тут мне попался хороший #longread, который методично раскладывает их по полочкам:
Before You Turn On Two-Factor Authentication…Цитаты для затравки (про риски):
You may be unable to recovery your second factor if your security key, or the phone with your authenticator app, is lost, stolen, or broken.
... timely access to some services can itself be important to user safety. For example, you may no longer remember the phone numbers of the close friends and family members you would want to contact in a time of crisis.
Researchers have already shown that ... users required to employ a second factor (a fingerprint in their study) chose weaker PINs (numeric passwords) than those who were not.
Attackers might steal your security key when you are in a public place
If you plug an attacker’s lookalike device into your computer and allow it to install a driver, it can take control of your computer