top | item 5518839

(no title)

menny | 13 years ago

Persona should add two-factor authentication.

For that matter, any open-ID or similar technology should add that.

discuss

order

AndrewDucker|13 years ago

Persona is only handling authentication temporarily.

Once email providers start providing their own Identity Providers then the security falls entirely on them.

For instance, once GMail starts being its own authenticator, my two-factor authentication there will kick in.

callahad|13 years ago

Identity Bridging will eventually get 60-80% of users functionally off of our fallback and onto their provider's native authentication paths, but I do wonder if the Persona fallback support two-factor auth natively for the remaining 20-40% of users.

Thoughts?

TheCoelacanth|13 years ago

Persona leaves authentication entirely up to the identity provider. In the case of the fallback identify provider that you're probably seeing, they choose passwords. Other identify providers can choose any method of authentication that they want to use.