Skip to content

Timestamp for QR and Backup Code keygen #593

@richardkentgates

Description

@richardkentgates

Is your enhancement related to a problem? Please describe.

I know phishing is not a bug, but email is an option, and it is a popular option. I just recently dealt with a phishing attack where email was set up and I had no way to know if the attacker reset the backup codes, giving them secondary access. I imagine it would also be possible to setup the time based token and as long as it isn't set to primary, the behavior would not seem unusual and may be missed.

Proposed Solution

Rather than being combative with users over the policy, which is why I assume the email option is available, maybe we could get a time and date that can be matched with the backup code metadata time and date where it is stored, allowing users to cross-reference the file time date with the time date in their user profile. A time and date to reference would give us something to at least compare.

Another suggestion would be an email notification when any two-factor settings are changed for that user. Both of these being implemented would be helpful for admins and users.

Thank you all for your hard work on this plugin.

Designs

N/A

Describe alternatives you've considered

We currently advise clients of the risk of using the email option in the plugin

Please confirm that you have searched existing issues in this repository.

Yes

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions