Permanently Deleted

  • git [he/him, comrade/them]
    ·
    4 years ago

    Sure, as soon as you implement TOTP and U2F/FIDO2 support.

    With the current setup an attacker only needs to compromise one factor, the email inbox, to take over the account via password reset.