|
|
|
|
|
by chii
993 days ago
|
|
a theatre is where you have the feeling of security, but you don't really have it in reality. You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure, because if a password was leaked, and not discovered, then this measure doesn't prevent it. But it is imposing a cost, which cannot be measured against effectiveness. Change the whole process to 2FA is secure because there's provable guarantees for the costs imposed, and therefore, you can make an objective decision on whether it is worth implementing. |
|
> You cannot claim that just because some users are 'saved' as evidence that this is an effective security measure
Why not? Saving people from insecurities is almost by definition a measure of effectiveness
> you can make an objective decision on whether it is worth implementing.
You can't since the value factors in your "provable guarantees" and costs involved are subjective and also depend on the users' characteristics