Internet Identity Lack Of Security

Hi, I wanted to start a topic Enhance security on identity.ic0.app but found this one and as it would be duplicated will just comment here.

Motivation: Users are supposed to properly secure their auth devices but at the same time are supposed to use them several times per day to access dApps, which are mutually exclusive requirements.

  1. I agree with
  • This will allow owner of the Anchor to secure the passphrase and eventually use it as last resort recovery


  1. I shared idea for had/dp type of device (hidden authorisation device/decreasing priority), but similar functionality seems covered by below proposal
  • https://twitter.com/plsak/status/1470840499779031044?s=20
  • Planned propsal:
  • Note: this might seem to provide similar protection as hardening of seed-phrase change, but it’s actually more secure:
    • passphrase can be copied or memorised during the securing process and then misused
    • had/dp device(s) could be secured on different places (different banks safes) making it’s unauthorised access nearly impossible


  1. Another convenient functionality would be to implement in Internet Identity option for 2FA setup
3 Likes