Re: Wiki 2FA

Поиск
Список
Период
Сортировка
От Greg Stark
Тема Re: Wiki 2FA
Дата
Msg-id CAM-w4HNZTYoVmX+RCqRyuafiii7RGuE8hRRrs8S9c9m2p9T6CA@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Wiki 2FA  ("Joshua D. Drake" <jd@commandprompt.com>)
Ответы Re: Wiki 2FA
Список pgsql-www
On Sat, Jan 23, 2016 at 11:25 PM, Joshua D. Drake <jd@commandprompt.com> wrote:
> No. I meant the idea of having Google Authenticator required (which is open
> source). It works on any Android device as well as others (windows). I
> believe it would help with the autoscripting edits?

Why? It doesn't in any way prevent automated scripted spammers. They
can automatically generate TOTP codes from a script just as easy as
the app can. A SMS-based 2FA scheme might have an impact but even that
can be farmed out easily.

Actually requiring a Google account and OAUTH login would actually
have an impact because Google cares about spammers with Google
accounts and goes after them and shuts them down. On the one hand
Google is going to do a better job of anti-spam, opsec, and dos
mitigation than we every will. But on the other hand I suspect Google
is only concerned by numbers that are significantly larger than our
threshold of pain and it would mean giving away a lot of control over
the process.



-- 
greg



В списке pgsql-www по дате отправления:

Предыдущее
От: "Joshua D. Drake"
Дата:
Сообщение: Re: Wiki 2FA
Следующее
От: "Greg Sabino Mullane"
Дата:
Сообщение: Re: Wiki 2FA