Account Lockdown Ineffective - Idea for solution
A
Austin Metcalf
Hey Techlockdown team,
This website has been a Godsend for me, and I am very thankful this exists. I am a long time porn addict, and I am trying to use this website as a tool to truly lock down my phone, but I am very adept at undoing all my hard work. I always find a way around, and I have been on this journey for a long time to find a truly unbreakable method to lockdown my phone.
I say that to say that I found out that the account lockdown is ineffective, as there is a rather simple way to unlock your account without the passcode. I am the superuser for this account, and I am considering if not being the superuser will prevent me from doing this, and if so, then I will try to have someone else set up an account on here and be do all of this again through that account.
Here is how I did it: I set up the lockdown with a passcode, and I found a way around it by adding my own email to the secondary email, and then hitting forgot passcode, and having a recovery code sent to my email. Now, you might think that adding an email that isn't yours would be the solution, but I found out that I am able to simply remove the secondary email without any need for a passcode or anything, and then go back and change it to one of my own email. And that is where the issue is, and I am wondering if someone who isn't a superuser would have the ability to do that.
I propose a simple solution: just like having to send a code to the email for recovering the passcode, you should also be required to have a pin sent to the email address you are trying to remove. That way I would be unable to remove and then add my own if I didn't have access to the email. Then I would be able to put someone else's email in there and be certain that I would not be able to unlock my profile without that person.
So, I hope this finds you, and you are still developing this. If someone knows if not being a superuser prevents this from happening, then leave a comment.
Ben
Hi Austin,
Thanks for the detailed feedback. We could revert to a model where a pin must be entered from the secondary email, but I'm hesitent to do this since we get some customers who completely lock themselves out of their profile on purpose.
If the secondary email address is an accountability partner, you should enable email notifications. When you do this, changing your secondary email address will send your accountability partner a notification that you've changed the email. We don't have notifications enabled by default so that people can decide the level of strictness and transparency. It varies from person to person.
Instead of making profile unlocking impossible, we are opting for more techniques that slow people down and cause them to think. For example, adding a time delay or schedule.