Recommend a more privacy friendly app than Google Authenticator for MFA
Mattermost suggests that the users use Google Authenticator which is no longer is available under a free license.
I would propose making a different recommendation.
- the MFA setting mentions "When true, users with AD/LDAP or email login can add multi-factor authentication to their account using Google Authenticator." But it should mention that any TOTP application will do.
- the MFA setup page only mentions Google Authenticator instead of giving a shortlist of possible apps, such as Aegis, a free and open source application.
As FOSS software, we should promote the use of FOSS software to users and not lead them to believe that only Google Authenticator can work.
3
votes
Nicolas
shared this idea