FeatureFuel
2

Additional configuration for hardening 2FA

Source: dani-garcia/vaultwarden#4222 · opened by @zacknewman
Currently one can require 2FA, disable 2FA remember, and disable certain forms of 2FA; however it would be nice to also be able to disable API log in, device log in, TOTP, and the recovery code in addition to adding WebAuthn attestation capabilities. By disabling the recovery code, one can enforce the specific forms of 2FA which in cases like WebAuthn are stronger; however with it enabled, the recovery code may be the "weakest" link and thus is more likely to be targeted than the stronger forms of 2FA. The diff to enforce this would be quite simple. Ditto for TOTP, device log in, and API log in. Note one can already disable e-mail, Yubico OTP, and Duo; so this is consistent with those options. For environments that want to enforce the strongest form of 2FA, WebAuthn, it would be nice if attestation support were added as well. With attestation support, one can not only enforce WebAuthn but also enforce specific WebAuthn providers (e.g., a provider that stores a non-tran…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests