|
|
|
|
|
by silversmith
1477 days ago
|
|
So add a step that requires "knowledge transfer" between the login device and confirmation device. Microsoft does this in their authenticator app showing essentially three confirmation buttons with different numbers on them, and requiring you to press the one being shown on the login screen. Worst case you now have one-in-three-clicks account compromise rater than one-click. And hopefully this also causes the user to ask why they are being required to log in if the app is not displaying the confirmation data. |
|