|
|
|
|
|
by Buge
2986 days ago
|
|
Whenever you make the recovery process easier, you make it easier for attackers to "recover" victims' accounts. Switching from pseudo-AI to humans isn't necessarily better. I had an attacker successfully social engineer a support person into changing the email associated with one of my videogame accounts which had some valuable items. Preventing attackers from getting my password is something I can do myself. Preventing attackers from "recovering" my account is not something I can do myself. So I prefer services to have difficult recovery. |
|
Only if you define easier as 'badly designed process'.
> I had an attacker successfully social engineer a support person into changing the email associated with one of my videogame accounts which had some valuable items.
That is unfortunate, but why do you believe this will always be the case?
>So I prefer services to have difficult recovery.
Maybe this can be an opt-in for the more 'security-minded' minority. There is no reason to have the same process for every user. Both of the positions "Preventing attackers from getting my password is something I can do myself." and ". Preventing attackers from "recovering" my account is not something I can do myself." rely on humans not making mistakes. We can improve on both (service & user) sides to reduce mistakes.