Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Strypey
@strypey@mastodon.nzoss.nz  ·  activity timestamp 3 months ago

The UX of 2FA could be improved considerably, and security along with it, by using a circles of trust model.

Take the example of a code forge, hosting the canonical version of some crucial piece of kit like the Linux kernel, OpenSSL, or GnuPG. You would want a maintainer to be 100% authenticated before they can commit changes to these repositories. Basic security culture.

But ...

(1/2)

#2FA #authentication

  • Copy link
  • Flag this post
  • Block
Strypey
@strypey@mastodon.nzoss.nz replied  ·  activity timestamp 3 months ago

Would it still be important to authenticate them before performing a community mod action? Yes, but the stakes of making mistakes here are much lower, and usually reversible. For posting an issue, the only reason to authenticate is to prevent spam and other low-effort nuisance.

The UX implications are, it's perfectly secure to let anyone with a known email address post an issue, and ask them for further proof of identity before they do anything that requires higher levels of trust.

(2/2)

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.13 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login