Rabbit-Company / Passky-Server

Server for Passky (password manager)
https://passky.org
GNU General Public License v3.0
184 stars 23 forks source link

[Feature Request] Mitigate Personal Identifiable Information (PII) Threat #34

Open vzool opened 1 year ago

vzool commented 1 year ago

The LastPass security incident caused a data breach for encrypted user passwords vault and Personal Identifiable Information (PII) like Usernames & Email addresses and many others, which lead to staging a Phishing-Attack.

The Passky-Server currently has the same issue with PII with the following fields:

Those fields need to be eliminated that threat and maintain the system usability for the following functions like:

1- Resetting 2FA thru Email. 2- Send an email if someone else has signed to your account.

REF: Screenshot of LastPass security incident in case it got deleted somehow ^_^

screencapture-blog-lastpass-2022-12-notice-of-recent-security-incident-2023-01-23-15_29_50

vzool commented 1 year ago

Proposed Solution No. 1

Passky-Server Personally Identifiable Information (PII) Threat Mitigation