A year ago, our team introduced measures in our Rails app to prevent account sharing: MFA via email and session limits. The results are below. The app is healthy now - new user signups are stable, and sharing login reports are dropped.
This is my story in detail how we've done that - https://www.youtube.com/watch?v=ie3i2tsDjS8 and the related article - https://blog.widefix.com/prevent-account-sharing-with-mfa/


