Skip to main content
Solved

App and 2-factor authentication

  • May 6, 2020
  • 1 reply
  • 134 views

Forum|alt.badge.img+3


When we log in with 2-factor authentication every time we must get the authentication code. Maybe it is an idea to ask ones a month and not everytime we login. 

Best answer by Anne Buit

Hi Ronald,

The 2-factor authentication is intended to only allow access when you know something (password) and you have something (e-mail account, phone, totp device).

When you allow leniency when it comes to ‘having something’ for a month, you also allow the attacker who knows your password access for a month. After submitting a correct 2FA authentication after the month has passed, you'd grant the attacker access for another month as well.

This topic has been closed for replies.

1 reply

Anne Buit
Community Manager
Forum|alt.badge.img+5
  • Community Manager
  • 688 replies
  • Answer
  • May 7, 2020

Hi Ronald,

The 2-factor authentication is intended to only allow access when you know something (password) and you have something (e-mail account, phone, totp device).

When you allow leniency when it comes to ‘having something’ for a month, you also allow the attacker who knows your password access for a month. After submitting a correct 2FA authentication after the month has passed, you'd grant the attacker access for another month as well.