Skip to content

Multifactor authentification (MFA) #2561

Description

@Didayolo

We need MFA for improving the safety of the platform.

Instead of phone number we could have an "auth app" endpoint.

Also to avoid:

To incentive / force MFA

Thoughts about incentives for the double authentification (phone / auth app verification):

Option 1: storage quota

Instead of forcing it, we could give incentives by increasing the storage quota. For instance:

  • Base user (email verified): 200 MB storage
  • After phone verification: 15 GB storage
  • Filling up info (github account, etc.): Up to 30 GB

Option 2: organizers option

An organizer option "Allow only verified users".

Option 3: organizers need to be verified

You can upload / manage competitions only if you are verified. That would improve security.

To be discuss

What would be the procedure if an user lose its authentification?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

DiscussionNeeds to be discussed before we can come up with specifications and begin the issueEnhancementFeature suggestions and improvements

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions