Passky-Server icon indicating copy to clipboard operation
Passky-Server copied to clipboard

[Feature Request] Mitigate Personal Identifiable Information (PII) Threat

Open vzool opened this issue 2 years ago • 1 comments

The LastPass security incident caused a data breach for encrypted user passwords vault and Personal Identifiable Information (PII) like Usernames & Email addresses and many others, which lead to staging a Phishing-Attack.

The Passky-Server currently has the same issue with PII with the following fields:

  • [ ] Username.
  • [ ] Email.

Those fields need to be eliminated that threat and maintain the system usability for the following functions like:

1- Resetting 2FA thru Email. 2- Send an email if someone else has signed to your account.

REF: Screenshot of LastPass security incident in case it got deleted somehow ^_^

screencapture-blog-lastpass-2022-12-notice-of-recent-security-incident-2023-01-23-15_29_50

vzool avatar Jan 23 '23 13:01 vzool

Proposed Solution No. 1

Passky-Server Personally Identifiable Information (PII) Threat Mitigation

vzool avatar Jan 26 '23 08:01 vzool