loftar wrote:shubla wrote:2FA via email or via time based token/code whatever those are called. At least as an opt in thing.
I have considered that too, but that seems like a completely separate question from the one I posed, no?
If this information was behind strict 2FA without any cookie etc. memorization, then maybe.
It would suffice to list last access times by network operator/region/city. Not the exact ip addresses.