2FA Lockout Potential Solution
I think I don't need to describe the situation to anyone. But let me tell an example anyway:
You forget your password because you don't really log into discord that often, as at most places you are already logged in. You press the button that sends you the magical email for a new password and you type in whatever you wanted. Suddenly you are met with the 2FA verification screen, but you didn't receive an SMS and the 8 digit code is on a drive that died on you. To add insult to injury discord suggest that you disable 2FA from a device where you are logged in, but because of the password change you get kicked out on every device.
I feel like there are multiple potential solutions to the issue. The one that immediately pops into my mind is that you could verify yourself with the phone number you set up 2FA on or even better, have an SMS sent to that number so you can recover your account. Even some security questions regarding your account could be asked too.
The point I'm trying to make is that the fact that an 8 digit code, which is probably sitting on some device completely unencrypted, is capable of unlocking an account, but the legit email or phone is incapable, is somewhat laughable. In a tragic sense at least.
I do think that there needs to be a system in place to fix this, as this issue is very much growing in its size as more and more people are joining discord. I don't think that deleting the locked out account is something considered a solution.
Please sign in to leave a comment.
Comments
0 comments