Discussion about this post

User's avatar
Alan Smith's avatar

Great article!

One thing I don't see discussed enough in regards to 2FA is how important it is to either layer up or have some way (however much a pain) to bypass it in case it breaks. This obviously weakens the value of it, but imagine this: any time you need to get money out of your bank account, you need to put in a code (SMS, TOTP, whatever) in addition to the usual. However, for some reason, that system breaks - the SMSs aren't arriving, the TOTP device has broken or catestophicalyl desyncs, whatever.

All of a sudden, you can't get money out. Now, in the real world you can probably go into the bank with some ID or whatever and get access or get it fixed or whatever, but in the case of things like email and such we can see this being harder to fix.

This isn't to say 2FA isn't good! It really is great! But like any security system you have to make sure of the problems it introduces and how to address them (TOTP, back up your seeds, SMS be able to change the number if you really need to, email definitely keep access to the inbox involved, etc)

Expand full comment
2 more comments...

No posts