hackmdio / hackmdio/hackmd-io-issues

Native sign-in with multi-factor authentication (MFA)

Open
#319 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
40
Forks
9
PR merge metrics
No merged PRs in 30d

Description

# About

Native sign-in with MFA allows for the user to own their account and data with maximum security. This aligns with the open-source values of HackMD.

# User flow

1. Create a HackMD account with a native username, password, and email. (Not using a third-party sign in like Twitter or GitHub).
2. Under *Settings*, set up multi-factor authentication (MFA) or two-factor authentication (TFA)
a. Choose type of MFA: FIDO2 with a hardware device like a Yubikey or OATH-TOTP with an app like Yubico Authenticator, email, or phone number.

# Alternative

**Migrate an account's native sign-in from username and password to third-party sign-in for MFA**
- By switching from native sign-in to a third-party sign that has MFA setup adds an extra layer of security in case the password is leaked or hacked.
- However, the user then must rely on the third-party service for their entire account data.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.