Let an administrator waive the second factor for a passkey or an SSO sign-in #48
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
#47 Passkeys, so signing in needs no password at all
Postulo/postulo
#62 Write down what single sign-on's e-mail matching trusts
Postulo/postulo
Reference
Postulo/postulo#48
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Observation
Why
A passkey is already two factors: something the person has, unlocked by something they are
or know. Asking for a TOTP code afterwards is a second lock on a door that already has one,
and that is the friction that makes people switch two-factor off altogether.
Single sign-on is the same argument at one remove. The identity provider has already done
the checking the instance is about to repeat, and on a company or university provider it
very often did it with something stronger than TOTP.
It has to be the operator's decision rather than each person's, because the operator is
the one who knows what their provider actually enforces.
Shape
asked for TOTP.
provider is not asked either, under a plain sentence saying this trusts that provider's
own checking.
page.
password sign-in. Somebody who has TOTP and signs in with a password is asked for it,
always.
work out why they were asked once and not the next time.
it, and an operator should be able to see when that changed.
Classification
Enhancement, and one that deliberately weakens a control — so it is off unless somebody
chooses it, and the page says what it costs. Not breaking.
Depends on
#47, for the passkey half. The SSO half works against what is already there.
Open questions
account at a large provider are not the same promise. Proposal: one switch now, per
provider when a second one exists.
MFA_TRUST_ENABLEDstay as it is? Yes. A trusted device is a different bargain andis already each person's own choice.