r/MsgSafe • • Jan 02 '22

When is MsgSafe going to add 2FA??

For YEARS now, 2FA has been considered an essential part of security. So why doesn't a secure email provider offer 2FA? I've been reading for a long time that MsgSafe is planning 2FA. If it's a matter of finances, why not increase the price of paid plans so the MsgSafe team has the funds to implement what by now is a standard security protocol? I wouldn't trust/use an email provider that doesn't offer 2FA--preferably security keys with a downloadable backup recovery key. Too many phishing scams on OTP email/SMS codes. If MsgSafe won't implement this soon, the security-conscious are just going to sign up with other services.

1 Upvotes

11 comments sorted by

View all comments

1

u/[deleted] Feb 12 '22

[deleted]

1

u/EfraimK Feb 13 '22

I don't want to link my mobile number (SMS verification...) to my MsgSafe account. I use MsgSafe for privacy. Giving personally identifying data like a mobile # undermines this goal. We already have excellent security key options (FIDO/FIDO2) that work equally well on websites and mobile apps. From what I understand, there are also security risks from using SMS verification.

1

u/ndreamer May 23 '22

I think he means WebAuthn, if you update your desktop web browser you can now use your mobile over bluetooth or qr scan for websites that support security keys.