Connecting to Proton services with 3FA
Have the ability to log in through three separate forms of identification before accessing the Proton account.
For example :
1 - the Proton password
2 - Google Authentication code (or any other tool)
3 - Proton authenticator (to be created)
The user initially logs in with their username and password. Then Proton asks for the 6-digit code that Google Authenticator (or other) gives. Then the user enters the 6-digit code from Google Authenticator into Proton Authentication which validates the 6-digit code and gives a code (e.g. numbers or a word) to the user. The user enters the numbers (or word) given by Proton Authentication and finally logs in if everything is ok.
It takes longer to log in but (I think) it would increase security even more.
-
Anonymous
commented
Security keys or passkeys would be a better solution here instead of multiple TOTP codes. The security key needs to be on your person and so is the most secure form of two factor authentication
-
Shaun
commented
Would second password (already available) not be useful?
E.g: password 1, 2FA code, password 2?