<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2FA recovery in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/2FA-recovery/m-p/52247#M3611</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Topic for discussion:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the secure and safe method for users &lt;FONT color="#993366"&gt;&lt;STRONG&gt;to recover&lt;/STRONG&gt;&lt;/FONT&gt; their account if they lost access to their 2nd factor Authentication device/method and do not have backup codes either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we lose the device we use for two-factor authentication (2FA), or are unable to access your 2FA method, we can easily request help from an account administrator to reset your 2FA. Once your 2FA is reset, we can log in with only with username and password. In this case user has to take the support of admin..it's not a big deal&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;but what I'm&amp;nbsp;highlighting here is self-service MFA recovery&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know few ways like &lt;SPAN&gt;TOTP&amp;nbsp;&lt;/SPAN&gt;, Email OTP, however these methods having risks&lt;/P&gt;&lt;P&gt;for email OTP, if the email has been compromised then that will be the risk since they can reset password on the account and verify OTP sent to the same email&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any guideline in this regard from NIST like&amp;nbsp;Digital Identity Guidelines NIST-SP-800-63A&lt;/P&gt;&lt;P&gt;any ideas please?!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2022 17:27:12 GMT</pubDate>
    <dc:creator>iluom</dc:creator>
    <dc:date>2022-08-01T17:27:12Z</dc:date>
    <item>
      <title>2FA recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/2FA-recovery/m-p/52247#M3611</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Topic for discussion:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the secure and safe method for users &lt;FONT color="#993366"&gt;&lt;STRONG&gt;to recover&lt;/STRONG&gt;&lt;/FONT&gt; their account if they lost access to their 2nd factor Authentication device/method and do not have backup codes either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we lose the device we use for two-factor authentication (2FA), or are unable to access your 2FA method, we can easily request help from an account administrator to reset your 2FA. Once your 2FA is reset, we can log in with only with username and password. In this case user has to take the support of admin..it's not a big deal&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;but what I'm&amp;nbsp;highlighting here is self-service MFA recovery&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know few ways like &lt;SPAN&gt;TOTP&amp;nbsp;&lt;/SPAN&gt;, Email OTP, however these methods having risks&lt;/P&gt;&lt;P&gt;for email OTP, if the email has been compromised then that will be the risk since they can reset password on the account and verify OTP sent to the same email&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there any guideline in this regard from NIST like&amp;nbsp;Digital Identity Guidelines NIST-SP-800-63A&lt;/P&gt;&lt;P&gt;any ideas please?!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 17:27:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/2FA-recovery/m-p/52247#M3611</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2022-08-01T17:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA recovery</title>
      <link>https://community.isc2.org/t5/Tech-Talk/2FA-recovery/m-p/52251#M3612</link>
      <description>&lt;P&gt;We recently updated our corporate environment to require that MFA registrations/updates be done from a managed (domain-joined, MDM, or onsite) device.&amp;nbsp; We fully anticipate this will cause some issues but it does substantially raise the bar for bad actors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I personally reduce my odds of getting locked out by registering multiple forms of MFA but at the same time, I realize I am not "normal" in this regard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 03:10:11 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/2FA-recovery/m-p/52251#M3612</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2022-08-03T03:10:11Z</dc:date>
    </item>
  </channel>
</rss>

