OTP activity record

Currently it appears that when a user reveals or copies a One-Time Passcode this activity is not logged as recent activity on the pasword entry. This is a security flaw as it permits a user to see the password once, not it elsewhere, then continue to use it without any insight into who/when since the OTP click is not registered in the same way revealing or copying the password itself would be.

Please log user activation of the OTP fields in passwords in the same way as actifity on the password itself is currently logged.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board

Core Web App

Subscribe to request

Get notified by email when there are changes.