-
-
Notifications
You must be signed in to change notification settings - Fork 10
Description
- I have searched open issues and pull requests. The issue I'm creating is not a duplicate of an existing open issue or pull request.
Information about the feature to be added:
It has been discovered in recent years, SMS and Email are not as secure as they used to be and while 2FA using these two methods are more secure than NOT having 2FA, it is much more seucre to implement Hardware or Software tokens. For service providers that offer either of the two (SMS and/or Email), there is no longer an option to 'poke' the provider into providing a more secure 2FA method (H/W and S/W tokens). On such sites, there should still exists the poke option, "Tell them to support 2FA" but details to implement more secure H/W and S/W 2FA instead of less secure 2FA.
Additionally, sites which offer H/W or S/W which falls back to SMS or Email should STILL have a poke option. Additionally, instead of a ! triangle next to the service provider, the ! triangle should be in the column (where the checkmark currently is located).
With regards to "Phone 2FA". Not sure how secure or in-secure Phone 2FA is. Additionally, some sites now offer Voice Verification (ie: Vanguard and Fidelity), although, it might only be "call in". Unsure how to indicate voice verification feature on https://twofactorauth.org.
SOURCE: NIST Special Publication 800-63B (summary: don't use SMS or Email for 2FA or out of band verification)
Metadata
Metadata
Assignees
Labels
Type
Projects
Status