Why does 2-factor / Two Step Authentication require phone number?
-
Documentation suggests, users need to provide a phone number in order to enable two-factor authentication.
After providing the phone number, it is possible to use the QR-Code and authenticator app. A phone number is by no means a requirement for authenticator app. Actually it’s the other way around: authenticator app allows 2-factor auth without a phone number.
Why does WordPress make the phone number a requirement? That raises the burdon for 2-factor auth and by that lowers usage numbers and by that security for users. Please reconsider the way this is currently handled and remove the phone number requirement, so more people can switch to 2-factor auth.
Thanks for considering & stay safe.
- This topic was modified 4 years, 11 months ago by . Reason: Moved to Fixing WordPress, this is not a Requests and Feedback topic
The page I need help with: [log in to see the link]
- The topic ‘Why does 2-factor / Two Step Authentication require phone number?’ is closed to new replies.