View Single Post
Old 17 Oct 2018, 11:18 AM   #9
BritTim
The "e" in e-mail
 
Join Date: May 2003
Location: mostly in Thailand
Posts: 3,090
Quote:
Originally Posted by PON View Post
A time delay before SMS kicks in as a fallback authentication approach seems to me a potential double-edged sword when you need access to mail NOW and don't have a Yubikey -- your keys are missing or whatever.
I can well believe some would prefer the slight security risk of an account hack over the possibility of being locked out for a limited period. That is why I suggest the time delay should be a user controllable option. Personally, I feel more concerned at the (admittedly slight) risk of my account being hacked, the password changed, and losing control permanently than the inconvenience of temporary unavailability of the account if I fail to plan ahead.
BritTim is offline   Reply With Quote