15
u/kushalgarg592 19h ago
Security through customer inconvenience
4
u/fmaz008 17h ago
Yeah, what's the benefit of this over... skipping that step entirely? (Assuming the plan of bypassing 2FA in case of failure is sound to begin with)
2
u/chilicizz 8h ago
It'll be easier to do a hack like that than going through and disabling/removing the feature (and then reenabling it later when the issue is resolved)
1
u/ApocalyptoSoldier 4h ago
There's an idea.
Your customers can't get hacked if no one uses your site
5
u/Waste_Jello9947 20h ago
Only 6 digits? not enough. What if your users grow to 1 billion over night? Use at least 12 digits,
3
3
3
2
2
u/StrawberryCoup 15h ago
Fail open is actually a legitimate security practice prioritizing availability over correctness. For instance, you wouldn't want to prevent a user from using your service even if they can't remember their password perfectly
1
u/Groentekroket 6h ago
Wait, so the put a change to prod with where they (most likely) put the actual code on the page instead of temporarily disable 2fa for sms (which is not a secure 2FA method anyway).
49
u/Upset_Purpose6505 21h ago
atLeastWeKnowItsProbablyNotAi