Skip to content

Commit

Permalink
Resolve #2577 by clarifying 2.8.6 wording (#2603)
Browse files Browse the repository at this point in the history
  • Loading branch information
tghosth authored Feb 11, 2025
1 parent 9bc2d08 commit 8d33693
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion 5.0/en/0x11-V2-Authentication.md
Original file line number Diff line number Diff line change
Expand Up @@ -182,7 +182,7 @@ Multi-factor TOTPs are similar to single-factor TOTPs, but require a valid PIN c
| **2.8.3** | [DELETED, MERGED TO 2.6.3] | | |
| **2.8.4** | [DELETED, MERGED TO 2.6.1] | | |
| **2.8.5** | [DELETED, INSUFFICIENT IMPACT] | | |
| **2.8.6** | [MODIFIED, LEVEL L2 > L3] Verify that physical single-factor OTP generators can be revoked in case of theft or other loss. Ensure that revocation is immediately effective across logged in sessions, regardless of location. | 3 | 613 |
| **2.8.6** | [MODIFIED, LEVEL L2 > L3] Verify that any authentication factor (including physical devices) can be revoked in case of theft or other loss. | 3 | 613 |
| **2.8.7** | [MODIFIED, LEVEL L2 > L3] Verify that biometric authentication mechanisms are only used as secondary factors together with either something you have or something you know. | 3 | 308 |
| **2.8.8** | [ADDED] Verify that time-based OTPs are checked based on a time source from a trusted service and not from an untrusted or client provided time. | 3 | 367 |

Expand Down

0 comments on commit 8d33693

Please sign in to comment.