You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As a user, who lost access to all devices as well as the Setup Code, I want to reset my user account to gain access again.
Resetting will re-roll the user's key pair. I.e. while the user can remain a vault member, keys need to be re-shared ("Update Permissions" button).
Furthermore, we need to decide, whether the user needs to re-validate his devices, as in the meantime a malicious admin could have sneaked in fake devices which we must not allow to receive a copy of the user's new key.
The content you are editing has changed. Please copy your edits and refresh the page.
I would argue that re-adding devices isn't much pain and is certainly not unexpected, if a user knowingly resets her account. Thus we should remove them as well, mitigating attacks that are based on sneaking in unauthentic devices.
As a user, who lost access to all devices as well as the Setup Code, I want to reset my user account to gain access again.
Resetting will re-roll the user's key pair. I.e. while the user can remain a vault member, keys need to be re-shared ("Update Permissions" button).
Furthermore, we need to decide, whether the user needs to re-validate his devices, as in the meantime a malicious admin could have sneaked in fake devices which we must not allow to receive a copy of the user's new key.
Tasks
The text was updated successfully, but these errors were encountered: