Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No two factor authentication (2FA) option available to customers to secure their account login #325

Open
n2diving-dgx opened this issue Apr 3, 2021 · 1 comment

Comments

@n2diving-dgx
Copy link

n2diving-dgx commented Apr 3, 2021

M2.3 includes an optional 2FA extension to further secure back-end user logins and with M2.4 a fully integrated 2FA was made required for back-end login. However, front-end customer logins still do not natively offer a similar 2FA option. There appear to be no third party extension solutions available from trusted Adobe certified partners, although there are a couple of "freeware" extensions published by individuals.

The Magento customer account typically contains a significant amount of Personally Identifiable Information (PII) such as names, billing and shipping addresses, phone numbers, order history and possibly contains gender, birth date, tax ID, etc. that is visible and editable by the customer upon successful authentication solely by a single password. Customers can also optionally store payment card information associated with their Magento account via the Vault for Card Payments feature of the included Braintree Payments extension.

Securing logins with MFA/2FA has become a best practice widely recommended to consumers and is becoming a requirement across a variety of industries. Complete absence of an integrated multi-factor or two-factor authentication option for customers who wish to further secure their PII is a significant security oversight for the Magento 2 platform.

@m2-assistant
Copy link

m2-assistant bot commented Apr 3, 2021

Hi @n2diving-dgx. Thank you for your report.
To help us process this issue please make sure that you provided sufficient information.

Please, add a comment to assign the issue: @magento I am working on this


Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant