Two-Factor Watchtower -- ignore SMS-based Two-Factor

philkim
philkim
Community Member

In my opinion, SMS-based two-factor is bad.

Watchtower's data comes from twofactorauth.org which seems to offer this information. I would love an option to ignore SMS-based two factor recommendation.


1Password Version: 7.0.1
Extension Version: 4.7.1
OS Version: 10.13.4
Sync Type: iCloud

Comments

  • Hey @philkim,

    We are already filtering out SMS, only alerting you if the site supports TOTP. If you're seeing a website listed that only supports SMS, that's unintentional, let us know which site and we'll get it removed.

  • philkim
    philkim
    Community Member

    These don't support 1Password OTP (RFC 6238):

    • E*TRADE
    • Kickstarter
    • LogMe.in
    • SumoLogic
  • Jasper
    edited May 2018

    Thanks for the letting us know about those!

    I will get HSBC and E*TRADE removed, however as far as I can tell Kickstarter, LogMeIn, and SumoLogic all support TOTP.

    In the case of forum.qnap.com, it's inheriting the notice from the main qnap.com domain which is listed to support 2FA. I'm not sure if there's anything we can do about that one, but I'll make a note to take a look.

  • JadC
    JadC
    1Password Alumni

    @philkim not sure about the other services, but KickStarter sure does work with 1Password :). Let us know if you need help setting it up as I did it for KickStarter last week.

    @JamesHenderson like Jasper said, the forum account is most likely linked to a parent QNAP account, which supports 2FA according to their help page. Any website that supports authenticator apps like Google Authenticator should work with 1Password's TOTP.

  • Hi @JamesHenderson,

    Oh, are the instructions here for enabling TOTP on your NAS system locally? In other words, it's not associated with qnap.com but rather an IP address or your own domain?

    If that's the case, I would agree it does not belong on our list as we have no way to detect those correctly.

  • philkim
    philkim
    Community Member

    Thanks @jadchaar . I figured out Kickstarter. I had to enable SMS/phone two factor first, which I really prefer not to do, then I can add TOTP (RFC 6283). Given all the hacks around SMS, I am not sure this can be considered safe, however.

  • JadC
    JadC
    1Password Alumni

    @philkim Yeah it seems that Kickstarter uses that as a recovery method rather than backup codes. Sadly, we can't do anything about that since it is their design choice :(.

    If you have any other questions, please do not hesitate to reach out.

  • Understood, we'll get it removed from our list. Thanks!

  • :+1: :)

This discussion has been closed.