Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Providers #986

Closed
Carlgo11 opened this issue Feb 27, 2015 · 2 comments
Closed

Providers #986

Carlgo11 opened this issue Feb 27, 2015 · 2 comments
Labels
question Issue contains a question.

Comments

@Carlgo11
Copy link
Member

Hi everybody!

I think the provider category is rather inefficient.
Some of the providers only support a one/a few site(s), like SAT Mobile ID & Totp.Me, while some support almost every site listed on 2fa.org, like Google Authenticator & Authy.
It's not user friendly since they can't know if the provider will work for the site they want to add two factor authentication on.

Any ideas on what we could do to improve this?

@Carlgo11 Carlgo11 added the question Issue contains a question. label Feb 27, 2015
@smholloway
Copy link
Contributor

When I created the provider page I thought of it as a page for developers. Where twofactorauth.org is for end-users looking for sites offering 2FA, twofactorauth.org/providers is for developers looking for a 2FA solution to implement. It was also a good way to move past discussions about which providers should be represented on the main page.

...while some support almost every site listed on 2fa.org...

Many of the providers implement the HOTP and TOTP standards, so they would also support almost every site listed. I think it's a sad state of affairs when the majority of sites don't offer 2FA and those that do use a system that is decades old.

Deciding which providers should be listed is no fun*. I say list the providers who want to be listed and let developers choose the best solution for themselves. A couple exceptions: if a provider is not secure or is not truly a secondary factor, it should not be listed.

*As a Toopher employee it would serve my interest if only the novel, modern providers were listed--skip the amateur me-too OATH OTP generators. But that's not fair, and deciding who makes the cut would lead to more contentious debate.

@jamcat22
Copy link
Member

The providers page is being removed. You can read more about it on #1177.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Issue contains a question.
Projects
None yet
Development

No branches or pull requests

3 participants