|
|
|
|
|
by FiloSottile
1341 days ago
|
|
Bingo. The support cost of MFA, especially non-SMS methods where some of the recovery process is delegated to the mobile operator, is the top-level bit. It’s frustrating to see technical people discount or ignore that side of the deployment work, because that’s the kind of issue that actually blocks most security and cryptography measures in practice. If I had a thousand dollars for every time I heard “just make the user keep a key safe” I could fund so much UX research :) |
|
* generate, authenticate, distribute, back up