Description
2-factor-authentication
Amendments
The curated list of authenticators should also include the Microsoft Authenticator.
It is required for use with Microsoft accounts and Azure (Entra) AD anyway, can be secured, and serves very well for TOTP for other accounts. It also provides backup in case of a lost or stolen primary device.
It would be fair to argue that including MS Authenticator, Google Authenticator should also be on the list. It can servere the same purpose (though only a requirement for google accounts).
It suffers several limitations. No security, if your device is unlocked, the TOTP codes within are plainly visible. It doesn't actually get backed up, and there are no options for this. If device is lost or stolen, it may not be possible to recover it. This is very dangerous, given that 2FA/MFA should be enabled anywhere it is offered, even if that is only SMS (better than nothing).
Association Disclosure
I use MS Authenticator to have everything except google in a single secure app
Would you like to submit a PR?
Maybe?
Please tick the boxes
- You have filled out this form accurately, and to the best of your knowledge
- You have indicated whether or not you are associated with the project the amendment refers to
- A similar submission has not already been opened for this software / service
- You agree to the code of conduct
Activity