<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[No, you did not send a numeric code to my email to help me sign in &quot;for my security.&quot;]]></title><description><![CDATA[<p>No, you did not send a numeric code to my email to help me sign in "for my security." You did it because you couldn't be arsed to implement proper app-based authentication. </p><p>Control of any email address collapses down to a single factor for authentication. Do better.</p><p><a href="https://infosec.exchange/tags/TuesdayCyberGrouse" rel="tag">#<span>TuesdayCyberGrouse</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/0332ed77-faa3-4455-aa9e-f23456858e45/no-you-did-not-send-a-numeric-code-to-my-email-to-help-me-sign-in-for-my-security.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 05:09:32 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/0332ed77-faa3-4455-aa9e-f23456858e45.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 21 Apr 2026 06:07:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to No, you did not send a numeric code to my email to help me sign in &quot;for my security.&quot; on Tue, 21 Apr 2026 10:33:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/trantion%40masto.ai">@<span>trantion</span></a></span> <span><a href="/user/tarah%40infosec.exchange">@<span>Tarah</span></a></span> correct me if I'm wrong, but if they require a code they email you, password is redundant as you could otherwise reset it using the same email. Truth is, you email inbox is the single point of failure, but abstracting from it, I see nothing wrong with ditching passwords in such case</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116030382453444466/statuses/116442242521975253</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116030382453444466/statuses/116442242521975253</guid><dc:creator><![CDATA[iungomadre@infosec.exchange]]></dc:creator><pubDate>Tue, 21 Apr 2026 10:33:36 GMT</pubDate></item><item><title><![CDATA[Reply to No, you did not send a numeric code to my email to help me sign in &quot;for my security.&quot; on Tue, 21 Apr 2026 09:00:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/tarah%40infosec.exchange">@<span>Tarah</span></a></span> My favourite is a website I recently stayed using that says it's sending a "2FA code" to your email. They don't let you set a password.</p>]]></description><link>https://board.circlewithadot.net/post/https://masto.ai/users/trantion/statuses/116441876947746618</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://masto.ai/users/trantion/statuses/116441876947746618</guid><dc:creator><![CDATA[trantion@masto.ai]]></dc:creator><pubDate>Tue, 21 Apr 2026 09:00:38 GMT</pubDate></item><item><title><![CDATA[Reply to No, you did not send a numeric code to my email to help me sign in &quot;for my security.&quot; on Tue, 21 Apr 2026 06:49:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/tarah%40infosec.exchange">@<span>Tarah</span></a></span> Yes! You speak my mind. Every single one of these companies messing up login with stupid ideas need to be kicked in their CEO.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/ar1/statuses/116441361761798546</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/ar1/statuses/116441361761798546</guid><dc:creator><![CDATA[ar1@mastodon.social]]></dc:creator><pubDate>Tue, 21 Apr 2026 06:49:37 GMT</pubDate></item></channel></rss>