






























In my day job, we had similar discussions around forcing 2FA on all users. In the end, management decided that the risks of not having 2FA were greater than the perceived pain of having 2FA.
There were lots of complaints when we first forced 2FA on, but people quickly adapted. Systems that weren't great at handling 2FA were either rapidly updated or replaced.
Since we turned on 2FA, our CISO has noticed a dramatic drop in the number of accounts compromised by password stealing. (Down over 90%) So a good outcome. In turn, the attackers have pivoted to malware to steal session tokens/cookies. And so, the eternal battle continues.
Note: you can avoid this step in the future by logging into your LWN account.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。