Solved

App and 2-factor authentication

  • 6 May 2020
  • 1 reply
  • 119 views

Userlevel 1
Badge +3


When we log in with 2-factor authentication every time we must get the authentication code. Maybe it is an idea to ask ones a month and not everytime we login. 

icon

Best answer by Anne Buit 7 May 2020, 11:56

View original

1 reply

Userlevel 7
Badge +5

Hi Ronald,

The 2-factor authentication is intended to only allow access when you know something (password) and you have something (e-mail account, phone, totp device).

When you allow leniency when it comes to ‘having something’ for a month, you also allow the attacker who knows your password access for a month. After submitting a correct 2FA authentication after the month has passed, you'd grant the attacker access for another month as well.

Reply