5 ms·
This doesn't really solve the problem causing GitLab to enforce this change; I highly doubt the cost of providing support to users for MFA had any bearing on th
by samtheprogram 6y ago
This doesn't really solve the problem causing GitLab to enforce this change; I highly doubt the cost of providing support to users for MFA had any bearing on this discussion.
Meanwhile, Gray's suggestion would provide any attacker within enough capital to a backdoor, while legitimate users need to pay to unlock their account without any benefit to them from a security perspective.
I strongly disagree with such a concept -- unless, as you mentioned, payment could be used to verify the identity. That said, I think that's the same reason GitLab is now only offering MFA for paying customers, because they have a bit more PII to confirm your identity if you're a current customer -- in which case, why require payment at all?