FAQ SOP: Which 2FA method should I enforce for editors?
Not all second factors are equal. Pick in this order.
— Step 1: Default to a TOTP authenticator app (Aegis, 1Password, Authy). Phishing-resistant enough, zero cost.
— Step 2: For admins and developers, require a hardware key (WebAuthn / FIDO2). It cannot be phished or replayed.
— Step 3: Ban SMS 2FA. SIM-swap defeats it in minutes.
— Step 4: Store one set of recovery codes in the team password manager, not in email.
— Step 5: Verify: log in from an incognito window and confirm the second factor is mandatory, not skippable.
Method order matters more than the plugin you pick.
Run this on every privileged account.
Lockdown Ledger
@LockdownLedger
FAQ SOP: Which 2FA method should I enforce for editors?
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.