Skip to main content
Solved

App and 2-factor authentication

  • May 6, 2020
  • 1 reply
  • 129 views

Forum|alt.badge.img+3


When we log in with 2-factor authentication every time we must get the authentication code. Maybe it is an idea to ask ones a month and not everytime we login. 

Best answer by Anne Buit

Hi Ronald,

The 2-factor authentication is intended to only allow access when you know something (password) and you have something (e-mail account, phone, totp device).

When you allow leniency when it comes to ‘having something’ for a month, you also allow the attacker who knows your password access for a month. After submitting a correct 2FA authentication after the month has passed, you'd grant the attacker access for another month as well.

View original
Did this topic help you find an answer to your question?
This topic has been closed for comments

1 reply

Anne Buit
Community Manager
Forum|alt.badge.img+5
  • Community Manager
  • 637 replies
  • Answer
  • May 7, 2020

Hi Ronald,

The 2-factor authentication is intended to only allow access when you know something (password) and you have something (e-mail account, phone, totp device).

When you allow leniency when it comes to ‘having something’ for a month, you also allow the attacker who knows your password access for a month. After submitting a correct 2FA authentication after the month has passed, you'd grant the attacker access for another month as well.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings