Security Control Framework
This is what happens if you lose access to your 2FA GitLab.com account

This is what happens if you lose access to your 2FA GitLab.com account

10/8/2018 · Lyle Kozloff

What this post added

This post details a new, more secure process for verifying user identity when users lose access to their 2FA-enabled GitLab.com accounts. The previous method relied on government-issued IDs, which had drawbacks related to real names and independent verification. The new process involves classifying the risk factor of the data the user would access if 2FA were reset, and then posing a series of authentication challenges that require knowledge of the user's account. A minimum score must be attained based on the account's risk classification to reset 2FA. This process is peer-reviewed and the challenges are not made public.

Read the original post ↗