Isn't it safest to use a single password manager to rule them all, and a separate MFA application?
I mean, sure it would prevent this specific scenario. But I mean, in general, when is it safer to use github or another social login?
31–32 of 32 posts
I mean, sure it would prevent this specific scenario. But I mean, in general, when is it safer to use github or another social login?
At least you've learned a good lesson here. If you want ownership of an account, you need ownership of the email you use. And do a hard separation between personal and work services. Also, it sucks the hoops you're going through, but it's good they resist common social engineering tactics like they are. Good on them. Maybe suck up to a sys admin to re-instate the email for a day if support goes nowhere.
Also, if they're not keeping old domain (thus being able to create any (new or old) email account), they're doing a really bad job at sysadmining.