Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Help folks choose which provider is right for them #483

Open
iandunn opened this issue Oct 19, 2022 · 4 comments
Open

Help folks choose which provider is right for them #483

iandunn opened this issue Oct 19, 2022 · 4 comments

Comments

@iandunn
Copy link
Member

iandunn commented Oct 19, 2022

Many folks aren't familiar w/ 2FA and it's not intuitive to them, so they might struggle to pick a provider that fits their threat model. it could help to add some kind of messaging to the Providers table that tells people how secure & convenient each method is, so they can make an informed decision about tradeoffs.

Rough idea:
Screen Shot 2022-10-19 at 9 31 32 AM

Alternatively, that could be displayed as list, like:

Strength of security: 5/5
Ease of setup: 2/5
Ease of use: 4/5

... or even as a "help me choose" type of wizard. Or maybe just linking off to an article or video that describes each provider and explains the pros/cons in depth.

@jeffpaul
Copy link
Member

That settings portion is due for some UX improvements, which I've been trying to steal time from colleagues but have not been successful on usable output, but otherwise even some light guidance like this seems helpful (ensuring those strings are translatable).

@iandunn
Copy link
Member Author

iandunn commented Oct 19, 2022

Another way to display it might be a matrix:

Provider Security Setup Convenience
Email Weak Easy Moderate
TOTP Strong Moderate Moderate
WebAuthn Very Strong Moderate Easy - Moderate

@jeffpaul
Copy link
Member

jeffpaul commented Nov 29, 2022

Some related approach on this that GitHub is taking that we might use to inform how the plugin evolves here for WP: https://github.blog/changelog/2022-11-21-updates-to-the-two-factor-authentication-setup-flow/

image

@jeffpaul
Copy link
Member

jeffpaul commented Mar 3, 2023

Some updated UX approach from GitHub on how they describe & note preference of 2FA methods: https://github.blog/changelog/2023-03-02-sms-and-totp-can-now-both-be-registered-2fa-methods/

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants