You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Folks will sometimes get locked out when they lose their phone etc. Resetting a 2nd factor would ideally be independent of resetting the password, but for low-access accounts email might be better than nothing.
For high-privledge accounts, verification over video conference might be a secure option.
Maybe we require having 2 methods enabled, to reduce support requests.
Related WordPress/two-factor#485
The text was updated successfully, but these errors were encountered:
We could ask during 2fa signup that folks provide the w.org username of 2 people that can vouch for them. If they ask for recovery, we could contact those folks, ask them to confirm the original user in person or video chat, and then reply back to us. That whole process could be automated.
That’s assuming the other accounts aren’t also compromised, though. We’d also need to periodically email folks to make sure it’s still current.
For privileged accounts we’d probably still want to do it manually.
Folks will sometimes get locked out when they lose their phone etc. Resetting a 2nd factor would ideally be independent of resetting the password, but for low-access accounts email might be better than nothing.
For high-privledge accounts, verification over video conference might be a secure option.
Maybe we require having 2 methods enabled, to reduce support requests.
Related WordPress/two-factor#485
The text was updated successfully, but these errors were encountered: