I still don't undestand where you get 46000 odd from but I give up!
It's based chance, where the chance of success increases based on the amount of guesses made. After 10000 guesses you would have a 63.2% chance to succeed.
Mark Twain was right
@ZakMcKracken Have you actually now abandoned BT email as your main provider?
I'm currently still moving a lot of my accounts, but yeah, I'm now using proton mail plus.
@ZakMcKracken Well I can certainly give the thumbs up for Protonmail, I’ve subscribed to it for almost 6 years. I’ve never had a single issue. Good luck 👍
I'm also moving my email after this hack, it's a pretty involved process.
Despite some butchering of statistics in the thread - I don't think ones only protection should be down whether a hacker is guessing a number that BT OTP doesn't use. This is zero protection.
This is just a little follow up, as there seems to be some interest in how I got to the percentages mentioned in my posts. When a hacker guesses a number of 4 digits there is a 1 in 10000 chance they guess it right. When doing another guess, they get another 1 in 10000 chance and so on, increasing the overall chance they get into the account. When doing 10000 guesses they have 63.2% chance, while this further increases to 99% chance after 46050 guesses. The actual formula used to determine this is: 1−(9999/10000)𝑛, where n is the number of guesses. This gives a value between 0 and 1, which is multiplied by 100 to get the percentage. Hope that clarifies things and shows BT should be asking for more than 4 numbers for the lost password check.
The system that’s in place on most mobile phones is a time delay. A ten or twenty second delay on each 2fa would make even a four digit number way more secure.
A time delay would certainly help, but if they have access to many accounts to hack they could simply check each account once and cycle through them all. Then after ten/twenty seconds start over again. I'm assuming there are lots of BT accounts, so should still be relatively easy.