kartoteq
Create account
Roadmap

Two-factor sign-in

A code from an authenticator app on top of the password, with recovery codes for the day the phone is lost.

Olena manages the shared notebooks for a design studio of twelve people. One morning she gets an email that looks like it came from a client, with a link to a “shared document”. She almost types her password. Then she remembers that this password also opens the studio’s whole archive, and that nothing else stands between that link and three years of work.

A password is a single secret, and people reuse secrets. A second factor is there so that a stolen password opens nothing on its own. The part people forget is the opposite case: the day the phone with the codes falls into a river.

A second lock, and a spare key

Olena will turn on two-factor sign-in in her account settings, scan a QR code with any standard authenticator app and get a set of recovery codes to print and put in the studio’s safe. From then on a new device needs the one-time code, and changing the email address asks for confirmation. If the phone is lost, a recovery code gets her back in without writing to support.

This is ahead, after collaboration and the AI notebook. Before release we have to walk through the lost-phone case from start to finish and check what happens to her other signed-in devices and to the notebooks she shares.

Planned · Security

What is in scope

This is ahead, after collaboration and the AI notebook, because the hardest part is not the code itself but what happens to shared notebooks and open sessions when someone loses access. The scope is a one-time code (TOTP) that any standard authenticator app can generate, a set of recovery codes to print or save, and a confirmation step before sensitive changes such as a new email address. Before release we have to walk through recovery with a lost phone from start to finish and check that the other signed-in devices behave the way a person would expect.

Where it stands

This direction is in the plan but not in development yet. We will write here when work starts and when there is something to try. Until then there is no date, and we would rather say so than guess.

If this direction matters to you, tell us about the task behind it. A concrete situation changes what we build more than a vote for a feature does.

Tell us about your task