twofactorauth icon indicating copy to clipboard operation
twofactorauth copied to clipboard

Websites with multiple 2FA policies

Open phallobst opened this issue 6 years ago • 0 comments

Some websites have various 2FA policies, for example depending on the user type (commercial vs. private, domestic vs. foreign, left-handed vs. right-handed). I'm sure we all agree that this is basically a terrible idea. However, the question is how to address these websites. There are several ways to handle them:

  1. Document as not supporting 2FA at all
  2. Document as not supporting 2FA, but with an exception text: "2FA is only available for right-handed people."
  3. Document as supporting 2FA, but with an exception text: "2FA is not available for left-handed people."
  4. Do not include the site until their policy is sorted out
  5. Add two entries with different info: "Initech.com (left-handed people)", "Initech.com (right-handed people)"

Currently. once the 2FA information has been added, the contact channels (twitter, facebook, email) are removed, which means there is no information how to pester them to roll out 2FA for everybody.

phallobst avatar Nov 13 '19 20:11 phallobst