Skip to content

Consider: Marking SMS only 2FA as insufficient #20

@vidia

Description

@vidia

It would be nice to see sites that only have SMS based two factor marked as "good, but insufficient" and potentially having the same tewwt and email links that other entries have to request a TOTP based code be added.

There has been a lot of talk lately about how insecure a SMS based two factor auth system can be. It would be nice to see that communicated here to raise that awareness. While SMS is better than nothing it is not an entirely secure option.

I'd like to see those fields marked with, possibly, yellow to denote that they are good, but not good enough.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    Status

    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions