Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enhancement: automatically generate (and activate) backup codes #292

Open
axelsimon opened this issue May 7, 2019 · 4 comments
Open

Enhancement: automatically generate (and activate) backup codes #292

axelsimon opened this issue May 7, 2019 · 4 comments

Comments

@axelsimon
Copy link
Contributor

It's been pointed out to me that it would be a nice default for regular users to have backup codes be automatically generated and showed when activating any other method of 2FA.

It can be dangerous to only activate one 2FA method (decent risk of locking yourselsf out), so we should automatically create the backup codes and show them to the user and prompt them to copy them and keep them safe.

It is possible that not having backup codes or having only one 2FA method is what you really want, (hence my mention of regular users), but in this case you can either remove the backup codes method after or simply not make note of the backup codes.

@axelsimon
Copy link
Contributor Author

Hi there, any news on this? It could really benefit regular users and help establish good security workflows for organisations wanting to use 2FA on Wordpress.
Thanks!

@kasparsd
Copy link
Collaborator

This is a great suggestion @axelsimon!

Unfortunately, I personally don't have time to work on this feature right now.

@r-a-y
Copy link
Contributor

r-a-y commented Oct 29, 2020

I think having the Backup Verification Codes option as a selectable 2FA method is wrong. It should be moved out of the 2FA table and displayed similar to the Security Keys section outside the table.

If a 2FA option is selected, but the Backup Verification Codes have not been generated yet, a warning should be displayed.

@iandunn
Copy link
Member

iandunn commented Jan 25, 2023

Related #485 , #507

@jeffpaul jeffpaul added this to the 0.12.0 milestone Sep 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

5 participants