Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Roundcube
  3. 2FA for RC?

2FA for RC?

Scheduled Pinned Locked Moved Roundcube
12 Posts 3 Posters 3.8k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • humptyH Offline
    humptyH Offline
    humpty
    wrote on last edited by
    #1

    Anyone using 2FA TOTP with RC? The plugins I've found are couple of years old.

    marcusquinnM necrevistonnezrN 2 Replies Last reply
    0
    • humptyH humpty

      Anyone using 2FA TOTP with RC? The plugins I've found are couple of years old.

      marcusquinnM Offline
      marcusquinnM Offline
      marcusquinn
      wrote on last edited by
      #2

      @humptydumpty I'd just make a very long password and trust in fail2ban 🙂

      Web Design & Development: https://www.evergreen.je
      Technology & Apps: https://www.marcusquinn.com

      humptyH 1 Reply Last reply
      0
      • marcusquinnM marcusquinn

        @humptydumpty I'd just make a very long password and trust in fail2ban 🙂

        humptyH Offline
        humptyH Offline
        humpty
        wrote on last edited by
        #3

        @marcusquinn I didn't do/config anything with fail2ban. Is it good enough using the default settings? My pass is over 50 characters long with a mix of symbols. 🙄 It's still nice to have 2FA though.

        marcusquinnM 1 Reply Last reply
        0
        • humptyH humpty

          @marcusquinn I didn't do/config anything with fail2ban. Is it good enough using the default settings? My pass is over 50 characters long with a mix of symbols. 🙄 It's still nice to have 2FA though.

          marcusquinnM Offline
          marcusquinnM Offline
          marcusquinn
          wrote on last edited by marcusquinn
          #4

          @humptydumpty yeah, Cloudron already thought of that all for us 🙂

          I know what you're saying, and I like 2FA because it mostly protects people that reuse passwords, but it's really no more secure than good long password if you use unique passwords and a solid password manager.

          Web Design & Development: https://www.evergreen.je
          Technology & Apps: https://www.marcusquinn.com

          humptyH 1 Reply Last reply
          1
          • marcusquinnM marcusquinn

            @humptydumpty yeah, Cloudron already thought of that all for us 🙂

            I know what you're saying, and I like 2FA because it mostly protects people that reuse passwords, but it's really no more secure than good long password if you use unique passwords and a solid password manager.

            humptyH Offline
            humptyH Offline
            humpty
            wrote on last edited by
            #5

            @marcusquinn In that case, between Cloudron and Bitwarden's pass generator, we're all set.

            marcusquinnM 1 Reply Last reply
            2
            • humptyH humpty

              @marcusquinn In that case, between Cloudron and Bitwarden's pass generator, we're all set.

              marcusquinnM Offline
              marcusquinnM Offline
              marcusquinn
              wrote on last edited by
              #6

              @humptydumpty yuuuup!!

              Web Design & Development: https://www.evergreen.je
              Technology & Apps: https://www.marcusquinn.com

              1 Reply Last reply
              0
              • marcusquinnM Offline
                marcusquinnM Offline
                marcusquinn
                wrote on last edited by
                #7

                I haven't checked Roundcube - but best advice is for force a minimum 12-char password on any app that has that ability for user's security. It's difficult to enforce uniqueness but easier to encourage it if people are using Bitwarden or similar since it's so easy.

                Web Design & Development: https://www.evergreen.je
                Technology & Apps: https://www.marcusquinn.com

                1 Reply Last reply
                0
                • marcusquinnM Offline
                  marcusquinnM Offline
                  marcusquinn
                  wrote on last edited by
                  #8

                  More password geeking here: https://brandlight.org/h/policies/password-security-policy/

                  Web Design & Development: https://www.evergreen.je
                  Technology & Apps: https://www.marcusquinn.com

                  humptyH 1 Reply Last reply
                  1
                  • marcusquinnM marcusquinn

                    More password geeking here: https://brandlight.org/h/policies/password-security-policy/

                    humptyH Offline
                    humptyH Offline
                    humpty
                    wrote on last edited by
                    #9

                    @marcusquinn Nice article. I'd like to share this security tip I picked up about Authy. Make sure to disable Multi-device after setting it up. IIRC, it's disabled by default but some people might leave it on after setting up multiple devices.

                    marcusquinnM 1 Reply Last reply
                    0
                    • humptyH humpty

                      @marcusquinn Nice article. I'd like to share this security tip I picked up about Authy. Make sure to disable Multi-device after setting it up. IIRC, it's disabled by default but some people might leave it on after setting up multiple devices.

                      marcusquinnM Offline
                      marcusquinnM Offline
                      marcusquinn
                      wrote on last edited by
                      #10

                      @humptydumpty Yeah, I only use Authy if there's no TOTP code available to save into Enpass/Bitwarden. I do have multi-device but pretty well locked-down through various layers on each.

                      Web Design & Development: https://www.evergreen.je
                      Technology & Apps: https://www.marcusquinn.com

                      1 Reply Last reply
                      1
                      • humptyH humpty

                        Anyone using 2FA TOTP with RC? The plugins I've found are couple of years old.

                        necrevistonnezrN Offline
                        necrevistonnezrN Offline
                        necrevistonnezr
                        wrote on last edited by
                        #11

                        @humptydumpty said in 2FA for RC?:

                        Anyone using 2FA TOTP with RC? The plugins I've found are couple of years old.

                        This plugin was updated as recently as 4 months ago and works just fine: https://github.com/alexandregz/twofactor_gauthenticator

                        humptyH 1 Reply Last reply
                        3
                        • necrevistonnezrN necrevistonnezr

                          @humptydumpty said in 2FA for RC?:

                          Anyone using 2FA TOTP with RC? The plugins I've found are couple of years old.

                          This plugin was updated as recently as 4 months ago and works just fine: https://github.com/alexandregz/twofactor_gauthenticator

                          humptyH Offline
                          humptyH Offline
                          humpty
                          wrote on last edited by
                          #12

                          @necrevistonnezr It's working great. Thank you!

                          I know I'm going to need this when it's time to update the plugin. Make sure to remove the -master from the folder name so it's just "twofactor_gauthenticator" and use the code mentioned in the Cloudron doc page, and not the one on the plugin's github page.

                          array_push($config['plugins'], 'twofactor_gauthenticator');
                          
                          1 Reply Last reply
                          2

                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                          With your input, this post could be even better 💗

                          Register Login
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • Bookmarks
                          • Search