Hacker News new | ask | show | jobs
by lozenge 2726 days ago
Don't use email or SMS as it weakens the security to that of their email or - yuck - phone company customer service.

Manual review with proof of ID is the only way. Anything else will just have people not following instructions and requesting manual review anyway.

If anybody asks for higher security you can add a profile option to disallow manual review for their account. This should be visible on the settings screen but I would suggest making them write a request to turn it on. This can then open into a conversation about security if you are interested. And prevents people who don't understand it from turning it on to "increase security".