Why would you do such things? Just let me log in using some trusted authenticator please. If you can’t do that, you may as well replace everything with a confirmation mail every time I log in, cause you bet I’m going to click “forgot my password” Every Single Time and get in via the reset-email anyway.
You forcing me to change my password all the time just adds extra overhead to the inevitability that you’ll let me in after mailing me a confirmation code.
Keep them on their toes. After hunting down the last of them it’s time to introduce multi-factor.
That’s the plan. Can’t wait for their faces…
Why would you do such things? Just let me log in using some trusted authenticator please. If you can’t do that, you may as well replace everything with a confirmation mail every time I log in, cause you bet I’m going to click “forgot my password” Every Single Time and get in via the reset-email anyway.
You forcing me to change my password all the time just adds extra overhead to the inevitability that you’ll let me in after mailing me a confirmation code.