As part of a specific access to govt records, we submitted an application, that required us to receive a 2FA code by email.
When I saw it, my jaw dropped, mainly because of the specific access and the nature of the records.
But then also because of the stupidity of the many people involved with the software and the department.
I hope no one here uses a password or code like this .....
And yes I tested it's expiry, the same code, 3x in fact ! AND I am sure for the next day, and the next, etc.
Just mind blowing .
When I saw it, my jaw dropped, mainly because of the specific access and the nature of the records.
But then also because of the stupidity of the many people involved with the software and the department.
I hope no one here uses a password or code like this .....
And yes I tested it's expiry, the same code, 3x in fact ! AND I am sure for the next day, and the next, etc.
Just mind blowing .