Skip to content

Sites without Hardware or Software Token need a Poke option #17

@kilimar

Description

@kilimar

Information about the feature to be added:

It has been discovered in recent years, SMS and Email are not as secure as they used to be and while 2FA using these two methods are more secure than NOT having 2FA, it is much more seucre to implement Hardware or Software tokens. For service providers that offer either of the two (SMS and/or Email), there is no longer an option to 'poke' the provider into providing a more secure 2FA method (H/W and S/W tokens). On such sites, there should still exists the poke option, "Tell them to support 2FA" but details to implement more secure H/W and S/W 2FA instead of less secure 2FA.

Additionally, sites which offer H/W or S/W which falls back to SMS or Email should STILL have a poke option. Additionally, instead of a ! triangle next to the service provider, the ! triangle should be in the column (where the checkmark currently is located).

With regards to "Phone 2FA". Not sure how secure or in-secure Phone 2FA is. Additionally, some sites now offer Voice Verification (ie: Vanguard and Fidelity), although, it might only be "call in". Unsure how to indicate voice verification feature on https://twofactorauth.org.

SOURCE: NIST Special Publication 800-63B (summary: don't use SMS or Email for 2FA or out of band verification)

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions