# More Two-Factor Authentication Methods

**URL:** https://forums.plex.tv/t/more-two-factor-authentication-methods/807167
**Category:** Feature Suggestions
**Tags:** account
**Created:** [August 26, 2022, 3:22am UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167 "2022-08-26T03:22:35Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ippikiwoof](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ippikiwoof/32/286308_2.png) [@ippikiwoof](https://forums.plex.tv/u/ippikiwoof)
#### Post date: [August 26, 2022, 3:22am UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/1 "2022-08-26T03:22:35Z")

</div>

Recently got the email about a beach, and reset my password as was suggested.

I looked into setting up two-factor again, however as I remembered, the only available method is device-specific app authentication with recovery codes as the only backup option, which I am reluctant to use for various, personal reasons.

If Plex offered email or SMS options (even just for premium accounts), I’d be more inclined to use the feature. And contrary to what many would say about the security of such methods, my account would be more secure than it currently is.

---

<div class="post-metadata">

### Author: ![CptChaos](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/cptchaos/32/97483_2.png) [@CptChaos](https://forums.plex.tv/u/CptChaos)
#### Post date: [August 26, 2022, 8:42am UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/2 "2022-08-26T08:42:58Z")

</div>

Keep in mind that email and SMS are both not secure by default. Also, password managers like Enpass, Bitwarden and LastPass (although the latter is debatable to use as well to my opinion) have options to share the database with passwords and keys across multiple devices. So there are options that mitigate the “single point of truth” for your TOTP-tokens and apps like Google Authenticator.

---

<div class="post-metadata">

### Author: ![OttoKerner](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ottokerner/32/10079_2.png) [@OttoKerner](https://forums.plex.tv/u/OttoKerner)
#### Post date: [August 26, 2022, 11:06am UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/3 "2022-08-26T11:06:09Z")

</div>

> [@ippikiwoof](#):
>
> And contrary to what many would say about the security of such methods, my account would be more secure than it currently is.

I strongly suggest you check the validity of this claim.

> [@ippikiwoof](#):
>
> the only available method is device-specific app authentication

The 2FA method which Plex uses is not device-specific. It is a standardized method, which allows you to use all apps and software on all platforms which conform to the `OATH-TOTP` method to generate the verification codes.

This is a widely supported industry standard, which is much much more secure than SMS or Email  
And that is not my claim, but proven by commonly acknowledged security experts.

---

<div class="post-metadata">

### Author: ![SkylerWolfe](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/skylerwolfe/32/10375_2.png) [@SkylerWolfe](https://forums.plex.tv/u/SkylerWolfe)
#### Post date: [August 26, 2022, 5:48pm UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/5 "2022-08-26T17:48:14Z")

</div>

I’m guessing he meant SMS/email would be more secure than doing absolutely no 2FA (which he implied he is not currently doing).

---

<div class="post-metadata">

### Author: ![ippikiwoof](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ippikiwoof/32/286308_2.png) [@ippikiwoof](https://forums.plex.tv/u/ippikiwoof)
#### Post date: [August 27, 2022, 12:37am UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/6 "2022-08-27T00:37:59Z")

</div>

> [@CptChaos](#):
>
> Keep in mind that email and SMS are both not secure by default.

I understand this. But we’re not talking about bank account information. I just don’t think it’s that much of a concern for one time use codes which expire after ten minutes. If people are reading my SMS or emails, having my plex login breached is among the least of my concerns.

> [@CptChaos](#):
>
> password managers like Enpass, Bitwarden and LastPass (although the latter is debatable to use as well to my opinion) have options to share the database with passwords and keys across multiple devices

Cheers, I’ll have a look into these. Might I ask why not lastpass?

> [@OttoKerner](#):
>
> The 2FA method which Plex uses is not device-specific. It is a standardized method, which allows you to use all apps and software on all platforms which conform to the `OATH-TOTP` method to generate the verification codes.

Appreciate the explanation. Which software would you recommend?

> [@SkylerWolfe](#):
>
> I’m guessing he meant SMS/email would be more secure than doing absolutely no 2FA (which he implied he is not currently doing).

Yes, precisely, thank you. I like to access my emails and SMS from multiple devices, including ones that do not have a GUI.

---

<div class="post-metadata">

### Author: ![CptChaos](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/cptchaos/32/97483_2.png) [@CptChaos](https://forums.plex.tv/u/CptChaos)
#### Post date: [September 10, 2022, 8:00pm UTC](https://forums.plex.tv/t/more-two-factor-authentication-methods/807167/7 "2022-09-10T20:00:20Z")

</div>

> [@ippikiwoof](#):
>
> I understand this. But we’re not talking about bank account information. I just don’t think it’s that much of a concern for one time use codes which expire after ten minutes. If people are reading my SMS or emails, having my plex login breached is among the least of my concerns.

People might use the same credentials for multiple sites and services. So it might be possible people use the same credentials for their online banking and their Plex account. Assuming that people have different for all websites and services they use is a bad assumption.

> [@ippikiwoof](#):
>
> Cheers, I’ll have a look into these. Might I ask why not lastpass?

For me, it’s mostly because LastPass had serveral leaks and issues in the past, which shouldn’t be happening at all for a password management tool.

> [@ippikiwoof](#):
>
> Appreciate the explanation. Which software would you recommend?

There are a lot of options, actually. I have a Premium Lifetime subscription for Enpass, so that’s why I stay at Enpass, but nowadays, Bitwarden is a great alternative for a password manager. If you are looking for a TOTP manager only, you can look into [Authy](https://authy.com/).

> [@ippikiwoof](#):
>
> Yes, precisely, thank you. I like to access my emails and SMS from multiple devices, including ones that do not have a GUI.

It’s only a bit more secure, as SMS and e-mail can always be intercepted for instance. It you can avoid this that’s preferable for security reasons too.
