Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Link to vendor-agnostic page for buying a security key #463

Closed
iandunn opened this issue Oct 4, 2022 · 4 comments
Closed

Link to vendor-agnostic page for buying a security key #463

iandunn opened this issue Oct 4, 2022 · 4 comments

Comments

@iandunn
Copy link
Member

iandunn commented Oct 4, 2022

The settings screen currently links to a Google article for information on buying a key:

<p><a href="https://support.google.com/accounts/answer/6103523"><?php esc_html_e( 'You can find FIDO U2F Security Key devices for sale from here.', 'two-factor' ); ?></a></p>

IMO, it'd be more appropriate to link to an independent page that describes multiple vendors. I don't have a good one off the top of my head, though; does anyone know of one?

U2F might go away per #423, but I'm assuming we'd want keep the language for FIDO2 keys (#232)

@iandunn
Copy link
Member Author

iandunn commented Oct 4, 2022

https://fidoalliance.org/fido-certified-showcase/ might be a good one, but the number of options could be overwhelming for most folks. If we link there, we could add something like, "The most popular options from Yubikey, Titan, and Thetis" (or whatever vendors folks think are best).

https://www.nytimes.com/wirecutter/reviews/best-security-keys/ has lots of good info, but currently only recommends one vendor, which might be a little too skewed. It's at least an independent assessment, though.

@Clorith
Copy link
Member

Clorith commented Oct 4, 2022

I agree that a provider-agnostic source should be used. I'm not sure if fidoalliance is the right one though (getting newsletter popups as soon as you open a page isn't a great user experience, and feels like shelling over user information to 3rd parties).

Is there any reason we couldn't have a HelpHub page about enhancing your account security, since this is a core plugin then linking to it from there, and to the teams 3 most preferred vendors would be acceptable I think, maybe wit ha footnote linking to fidoalliance with a disclaimer that, disclaimers don't fit so well within plugins in the same way they do in a dedicated document to a thing after all.

I'm thinking something like the following wireframe:

| content block |
| content block |
| key | key | key |
| fidoalliance |

Where the fidoalliance has texts such as

There are many alternatives when it comes to keys, and these are only a few of the well known and often used ones. The fidoalliance, an unaffiliated third-party, that sources information about security key vendors, may have options that fit better into your daily activities.

I don't think it's possible to avoid some personal bias when providing options (it could be as simple as "that one was listed first" even though they had the same information about them), but at least this way the X most common are shown on as equal footing as possible, they are what those working on the feature use them selves, and the resource for a third party with a larger selection is provided 🤔

@iandunn
Copy link
Member Author

iandunn commented Oct 4, 2022

Yeah, I think that's a good idea 👍🏻

@kasparsd
Copy link
Collaborator

The FIDO U2F section will be removed in the next major release of the plugin #423 so I'm marking this as won't do.

@kasparsd kasparsd closed this as not planned Won't fix, can't repro, duplicate, stale Sep 19, 2024
@github-project-automation github-project-automation bot moved this from To Do to Done in Open Source Practice Sep 19, 2024
@jeffpaul jeffpaul removed this from the Future Release milestone Oct 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants