Would like higher security authentication to SSO

Bug #453131 reported by Joe "Rotund" Tennies
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Canonical SSO provider
Fix Released
Wishlist
Unassigned

Bug Description

I use Launchpad as my main OpenID provider. I would like increased security in the form of one-time use keys. An example of this is eBay/PayPal (https://www.paypal.com/cgi-bin/webscr?cmd=xpt/Marketing_CommandDriven/securitycenter/PayPalSecurityKey-outside) and World of Warcraft.

The SMS version eBay uses sounds good, but I'm concerned about needing a backdoor for the situation that you lose you cellphone/change phone numbers or providers. There's also the issue of the fact SMS is not a guaranteed service, so the key could be dropped if you are out of coverage (like in a basement at a conference). I wonder how eBay gets around these issues.

affects: launchpad → launchpad-foundations
Gary Poster (gary)
Changed in launchpad-foundations:
status: New → Triaged
importance: Undecided → Low
papukaija (papukaija)
tags: added: wishlist
Stuart Bishop (stub)
affects: launchpad-foundations → canonical-identity-provider
Revision history for this message
Stuart Metcalfe (stuartmetcalfe) wrote :

We're looking into a number of options to provide additional security for some cases, whether defined by a specific site or enabled by the user. This is not on our short-term roadmap but we are looking into it.

Changed in canonical-identity-provider:
importance: Low → Wishlist
summary: - Would like higher security authentication to launchpad
+ Would like higher security authentication to SSO
Revision history for this message
Daniel Manrique (roadmr) wrote :

login.ubuntu.com now supports 2-factor authentication. On the main personal details page, select "authentication devices" (on the left), configure one of the available devices, and you can then decide whether to be prompted for a 2FA code only for certain sites that request it, or all the time. To answer the "backup device" concerns, more than one device can be added to an account. There's even a "paper" device which is just a list of one-time codes, that's as low-tech as it gets and it will get you past any failures with e.g. a yubikey, a smartphone, etc.

Changed in canonical-identity-provider:
status: Triaged → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.