I activated 2-factor authentication using a security key, and when I logged in on my desktop device, the authentication login was simply "bypassed". Through Windows Security.
The Windows security tab automatically opens, I enter my computer's PIN (which email has nothing to do with the Trello account) and I can simply access my Trello account without authentication.
This assumes that anyone who has my password could very well access my Trello account from another device since the authentication is flawed. And a person with any other computer and PIN can access it.
In this sense, it makes more sense to just have a super strong password...
Is there something I'm being ignorant about and can't verify in another way? Please help me, because I can't find any reason why access was granted, since there is nothing on my desktop device linked to the same Trello email account that could have granted access to the account. In my opinion, nothing could grant access without the security key or without it being linked/saved somewhere on the computer.
I'm shocked. Because there has already been a leak of Trello data, hasn't there?