so... here's something weird about modern security culture we spent the last decade making password recovery "secure" right? - phone number verification ✅ - email verification ✅ - backup codes in your password manager ✅ - old-style security questions (lol) and yet: - SMS codes are SIM-swappable - email is compromised if your primary device is - backup codes get lost/forgotten - OSINT-prone security questions get answered by your LinkedIn profile the recovery flows designed to HELP you are now the weakest point of your entire security model turns out "prove you're you" is really hard when all the old proofs are broken 🔺
From Twitter
Disclaimer: The content above is only the author's opinion which does not represent any position of Followin, and is not intended as, and shall not be understood or construed as, investment advice from Followin.
Like
Add to Favorites
Comments
Share


