View Single Post
Old 11-05-2015, 09:02 PM  
Vendot
Confirmed User
 
Industry Role:
Join Date: May 2002
Location: Malaysia
Posts: 3,376
Quote:
Originally Posted by rowan View Post
If you're logging in via the phish site, which then relays your username, password and a valid 2FA token to the registrar, they control your session.
Oh I see. Now I understand.

So if the domain site detects login from unusual IP location, that gets flagged and prompts domain site to force a second 2FA request and require a second verification via logging in through browser rather than email link. Is this what you are saying? I do think it addresses something which people should be strongly advised against doing anyway which is logging into their account via email link.

It needs work but its a good idea - I will also suggest this one.
__________________
"In a Time of Universal Deceit, Telling the Truth is a Revolutionary Act." - George Orwell
Vendot is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote