2
Additional configuration for hardening 2FA
Source: dani-garcia/vaultwarden#4222 · opened by @zacknewman
Currently one can require 2FA, disable 2FA remember, and disable certain forms of 2FA; however it would be nice to also be able to disable API log in, device log in, TOTP, and the recovery code in addition to adding WebAuthn attestation capabilities. By disabling the recovery code, one can enforce the specific forms of 2FA which in cases like WebAuthn are stronger; however with it enabled, the recovery code may be the "weakest" link and thus is more likely to be targeted than the stronger forms of 2FA. The diff to enforce this would be quite simple. Ditto for TOTP, device log in, and API log in. Note one can already disable e-mail, Yubico OTP, and Duo; so this is consistent with those options. For environments that want to enforce the strongest form of 2FA, WebAuthn, it would be nice if attestation support were added as well. With attestation support, one can not only enforce WebAuthn but also enforce specific WebAuthn providers (e.g., a provider that stores a non-tran…
No pledges yet. Be the first to back this.
Comments
Similar requests
Disable 2FA email setup button if email 2FA is disabled in admin settings
1 vote · 0 comments
2FA for web extension
2 votes · 0 comments
Default 2FA email for new users invited to organizations with 2FA-policy enabled
11 votes · 0 comments
Show notification and force if 2FA is required when first login
1 vote · 0 comments
option to force periodic reauth and 2FA
4 votes · 0 comments
No comments yet.