Home
1 comment
ggmover 1 year ago
I looked at 'up to 8 devices/methods' in the AWS MFA page and wondered: is 8 2 or 4 or even 6 over the edge for how many discrete points of failure I have just introduced into my security regime?<p>It's a tension. One: I can lose that second factor and I'm screwed (ok backup codes people). Two: That feels good because it's where I am. Three: Can I even count up to three? What does failing to enter it correctly on 3 things mean? would i lock myself out? Is three meaning I leave one at home and have one with me so I can lose it?<p>I just think 8 is like "well we wanted 7, but we decided to go to "eleven" on this one" -unless its "there are 8 bits in an unsigned byte" and its a bitmap which one you use in their in-house API back end.