Guardian approval for new device logins (single trusted contact)
Problem: Account takeovers via phishing/social engineering remain common. Beginners and elderly users are disproportionately affected and can be tricked into sharing login codes/QR or using cloned pages. Many don’t enable or properly use existing security settings.
Proposal: Add an optional “Trusted Contact (1 guardian)” feature. The user assigns one trusted person. Any login from a new device triggers an Approve/Deny request to the guardian (with timeout). Without approval, the login cannot complete.
Security & UX:
Fully optional (off by default), positioned as “Family / Elder Protection”.
Show the guardian minimal metadata only: device type, country/approx region, time.
Changing/removing the guardian should notify the guardian and apply a cooldown, preventing attackers from disabling protection immediately after compromise.
Works as an additional layer on top of existing security (2FA/sessions), not a replacement.
Expected impact: Meaningfully reduces successful takeovers for vulnerable users via a human approval barrier.