Currently when disabling the 2FA on client side there is no step asking for the code a last time -> it directly disables. So for disabling 2FA only a valid session required. I think that this is not enough. Disabling the 2FA should be the same security as like the normal login.
Should disabling the 2FA need the a valid Code for confirmation? Discussion open :)
Currently when disabling the 2FA on client side there is no step asking for the code a last time -> it directly disables. So for disabling 2FA only a valid session required. I think that this is not enough. Disabling the 2FA should be the same security as like the normal login.
Should disabling the 2FA need the a valid Code for confirmation? Discussion open :)