7 ms·
Very short, badly written article. It can't even describe phishing correctly... At least label your threat model correctly. While the premise is correct -- it'
by pandorobo 1y ago
Very short, badly written article.
It can't even describe phishing correctly... At least label your threat model correctly.
While the premise is correct -- it's easy to complain but the author also provides zero recommendations on what is a better form of MFA.
- ipython 1y agoThe first factor is access to your email. The second factor is…?
- max__dev 1y agoThe article is not about MFA. It is about using email as a single factor.
- pandorobo 1y agoThats simple a lie or you didn't read the article. The very first bullet point states: Enter an email address or phone number That insinuates email OR SMS. It doesn't just mention email only.
- sophiebits 1y agoHalf factor authentication, then, since either one will work.
- max__dev 1y agoThe following is copied from wikipedia. The authentication factors of a multi-factor authentication scheme may include: 1. Something the user has: Any physical object in the possession of the user, such as a security token (USB stick), a bank card, a key, a phone that can be reached at a certain number, etc. 2. Something the user knows: Certain knowledge only known to the user, such as a password, PIN, PUK, etc. 3. Something the user is: Some physical characteristic of the user (biometrics), such as a fingerprint, eye iris, voice, typing speed, pattern in key press intervals, etc. Email and phone are both in category one, comprising only one unique factor.
- stavros 1y agoIt's still a single factor.
- ulysss 1y agoAgree with you
- anonymars 1y agoWhat is the minimum number of things you need access to in order to log in? If you have access to the phone, you can log in. OR if you have access to the email account, you can log in. You don't need to know the user's password, you only need access to one of these inboxes and nothing else. One-factor authentication, but worse, because there are multiple attack surfaces.
- donatj 1y agoYou misread the short article. It's about email as single factor auth, which has become very trendy of late. You just enter your email address, no password, and the email you a code. Access to your email is the only authentication.
- pandorobo 1y agoThe first bullet point mentions phone number. - Enter an email address or phone number Thats not just email, that's also SMS.
- eddythompson80 1y agoEmail OR SMS is still one factor. Its not multiple factors. How are you not getting that? Do you know what MFA means?
- max__dev 1y agoEven if it was Email OR password, that would still be one factor due to the OR. I do not think they are discussing in good faith.
- pandorobo 1y agoClearly I didn't misread that. It's literally the very first bullet point?
- deleted 1y ago[deleted]
- Thorrez 1y agoThe first bullet point is "Enter an email address or phone number". That's not MFA. MFA stands for multi-factor authentication. If the authentication only requires a code sent to an email OR phone number, that's just a single factor.
- Ferret7446 1y ago
- wodenokoto 1y agoThe article is not about multiple factor authentication. It’s about single factor, password logins, using a one-time-token