| ▲ | jimbocyou 6 hours ago | |||||||||||||
The problem is the rapid succession of changes to recovery phone number, country, cellular provider. There is no way to differentiate, at scale, between an account takeover currently in progress that needs to be stopped immediately to minimize damage, and a legit user deciding to change all his personal info at once. 30 day cool down period is a reasonable response, at scale. | ||||||||||||||
| ▲ | Hackbraten 6 hours ago | parent [-] | |||||||||||||
> The problem is the rapid succession of changes to recovery phone number, country, cellular provider. Aren't cellular providers inherently tied to the country they're in? How do you move to another country without changing cellular providers at the same time? | ||||||||||||||
| ||||||||||||||