Skip to content

websites that allow hardware token bypass. (SMS backup) #4308

@zee0

Description

@zee0

i'm looking specifically at the entry for vanguard, which has the hardware token column checked. it has an exception icon stating the following, but i'm not sure it is enough:

Hardware based 2FA requires SMS / Phone call 2FA as a backup. Hardware 2FA is only supported on Chrome browsers and works with the following hardware keys: Yubikey 4 Series, YubiKey 5 Series, Yubikey Security Key Series.

this is misleading as vanguard's policy requiring SMS as a 2FA backup means that the hardware token is always able to be bypassed. as such, i don't think they should be getting credit for having hardware tokens.

if it were up to me there would be a big red x in that column stating that their implementation was misconfigured and potentially dangerous.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionIssue contains a question.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions