Sharax wrote:Maybe if we log in with a new IP (because most of us have dynamic IP), it will ask us what our old IP is...we enter it in and we're good to go. That would be a good enough process for me.
This could work but also a major flaw if someone figures out your password they would also know your ip in most cases. they log in on the website and get an unlock prompt, all it would take was that address and unlocked. I think a link such as the password reset link would do fine. And if you use dual authentication for your email your account should never get compromised.