Skip to main content
Open

2FA - 2 factor authentication

  • Niels Rossipaul
  • Klaudia
  • henrikh
  • CMyers

Was it helpful?
Show first post

Forum|alt.badge.img
  • Contributor
  • November 18, 2024

It’s back now...must have been a “bug” ;) 

 


Forum|alt.badge.img
  • Contributor
  • November 18, 2024

@ElvaMiro 

Thank you for your reply. However, I need to respectfully push back on the suggestion to gather more votes and use cases for 2FA implementation:

  1. We already have concrete evidence of security breaches affecting non-enterprise customers (as demonstrated by the recent 150+ unauthorized members incident).
  2. The technical implementation is largely complete - 2FA is already working for enterprise customers, the infrastructure exists, and the documentation is written.
  3. The use case for 2FA is universal and well-established: protecting user accounts from unauthorized access. This is security fundamentals, not a feature request.
  4. Multiple paying customers have been requesting this for years, providing feedback and use cases throughout that time.

This isn't a matter of gathering more feedback or proving demand - it's about providing a basic security feature that's industry standard. Every day without universal 2FA puts more customer workspaces at risk of compromise.

As someone who has worked in digital product development, I can confidently say that extending existing 2FA infrastructure to all paying customers requires minimal technical effort compared to the initial implementation. The barrier here isn't technical or about understanding use cases - it appears to be purely a business decision to keep it as a premium feature.

I genuinely appreciate you engaging with the community on this, but we need action on this security issue, not more voting and use cases. Meanwhile, real security breaches continue to occur, putting customer data and intellectual property at risk. How many more workspaces need to be compromised before this basic security feature is made accessible to all paying customers?


I am (was) a new customer, and just discovered that 2FA is only available on the Enterprise package. I thought perhaps it was enabled on a paid a plan, but this is incorrect.

So I’ve cancelled my subscription and am moving to a competitor.

Interestingly, I’ve yet to find a competitor who doesn’t offer 2FA even on the free plans (or any SaaS in fact), so was very surprised to discover this.

What I do see is SSO being an Enterprise feature; I can understand that. But 2FA missing entirely? I’m surprised, and disappointed.

@foundsoul and others in the community, you’re doing great to work to continue momentum here, and I hope that this is finally resolved for you all soon.