this post was submitted on 20 Dec 2024
94 points (100.0% liked)
Cybersecurity
23 readers
21 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Rules
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
A cynical thought: what if it's actually less risky to make 2FA someone else's fault when it fails, rather than worry about ever having to be held accountable for an insecure implementation they created.
Thats a good point.
I expect the courts would uphold that flavor of argument too (at least in the U.S.; I expect the same in other countries, but don't feel comfortable speaking for systems I'm not at all familiar with).