Discord Security Issue: SMS 2FA broken under specific conditions.
Filed as a bug report tech support told me to come here with this there is a issue with the SMS 2FA back up for the 2FA system. As stated above the button "Set your phone up as a back up 2FA method in case you lose your authentication app or backup codes". This will not help if you no longer have access to your current password because when greeted via email to reset the password an clicking on the hyperlink, filling in the password form, and finally clicking "change password" you're greeted with a 2FA wall where SMS is not a option therefore you can not have a code sent to your listed phone even if you have SMS 2FA Enabled in the event you lost the other two. This leads to account lock out because customer / tech support will not send you the sms code to your listed phone for the account even if SMS 2FA is enabled.


Please sign in to leave a comment.
Comments
0 comments