- Joined
- Jun 29, 2022
- Messages
- 5
- Reaction score
- 1
We found, that users who reset their passwords are also prompted to set up two factor like it was never used before. Having access to a mail account then allows to reset the passwords, by this reset two factor, log in using the password the attacker decided, and then the attacker can even set up his own two factor device, essentially turning off two factor for a user. Why is this happening? How can we prevent this? Two factor should never be reset automatically ever.