<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[2FA for all LDAP apps]]></title><description><![CDATA[<p dir="auto">The absence of 2FA on the LDAP login Apps makes me nervous for GDPR and typical security needs nowadays.</p>
<p dir="auto">I don't know that anyone's ever had a break-in yet, and fail2ban is a good start but expectations for 2FA are increasing.</p>
<p dir="auto">I wonder if a global solution would be for all Cloudron packaged apps to use a Cloudron login screen with 2FA instead of the app's native logins?</p>
<p dir="auto">Realising this is development overhead in packaging, open to discussion and alternative suggestions. Hoping this idea is more evolution than revolution.</p>
<p dir="auto">The more we use any data-silo, the potentially more valuable or attractive it becomes for unscrupulous targeting.</p>
<p dir="auto">Thoughts?</p>
]]></description><link>https://forum.cloudron.io/topic/3285/2fa-for-all-ldap-apps</link><generator>RSS for Node</generator><lastBuildDate>Sun, 17 May 2026 06:25:16 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/3285.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Oct 2020 10:33:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 2FA for all LDAP apps on Sat, 17 Feb 2024 18:50:55 GMT]]></title><description><![CDATA[<p dir="auto">I will mark this as solved. LDAP standard hasn't moved to support 2FA and neither have apps settled on a pseudo standard. There is not much we can do.</p>
]]></description><link>https://forum.cloudron.io/post/83455</link><guid isPermaLink="true">https://forum.cloudron.io/post/83455</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Sat, 17 Feb 2024 18:50:55 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 13 Feb 2024 09:42:34 GMT]]></title><description><![CDATA[<p dir="auto">We are moving one app after the other over to OpenID connect where we can use Cloudron 2FA which exists for a long time now. LDAP has no proper standard to do this as such.</p>
]]></description><link>https://forum.cloudron.io/post/83220</link><guid isPermaLink="true">https://forum.cloudron.io/post/83220</guid><dc:creator><![CDATA[nebulon]]></dc:creator><pubDate>Tue, 13 Feb 2024 09:42:34 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 13 Feb 2024 09:16:01 GMT]]></title><description><![CDATA[<p dir="auto">3 years later any plans to have 2FA feature ?</p>
]]></description><link>https://forum.cloudron.io/post/83214</link><guid isPermaLink="true">https://forum.cloudron.io/post/83214</guid><dc:creator><![CDATA[gog122]]></dc:creator><pubDate>Tue, 13 Feb 2024 09:16:01 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Jul 2021 21:39:51 GMT]]></title><description><![CDATA[<p dir="auto">@humptydumpty that's correct, this feature didn't get implemented. The 2FA is only implemented on the Cloudron side and not for the apps. There was a parallel discussion going on about how to show what kind of auth is being used in an app in the dashboard. I think we need to show some indication to the user about how to log in before implementing this feature.</p>
]]></description><link>https://forum.cloudron.io/post/33486</link><guid isPermaLink="true">https://forum.cloudron.io/post/33486</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Tue, 06 Jul 2021 21:39:51 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Sat, 19 Jun 2021 14:55:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> I just logged into Wordpress (dev) with my CR user that has 2FA enabled and it didn't ask me for the code. Is there an option I need to enable somewhere or is this feature still on the to-do list?</p>
]]></description><link>https://forum.cloudron.io/post/32901</link><guid isPermaLink="true">https://forum.cloudron.io/post/32901</guid><dc:creator><![CDATA[humpty]]></dc:creator><pubDate>Sat, 19 Jun 2021 14:55:31 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 03 Feb 2021 17:54:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hendrikvl" aria-label="Profile: hendrikvl">@<bdi>hendrikvl</bdi></a> Yes, we will try to add this in the next release. This current release (6.1) we pushed out has 2FA for the proxy auth apps now.</p>
]]></description><link>https://forum.cloudron.io/post/24800</link><guid isPermaLink="true">https://forum.cloudron.io/post/24800</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Wed, 03 Feb 2021 17:54:45 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 03 Feb 2021 13:39:59 GMT]]></title><description><![CDATA[<p dir="auto">Just searched the forum for any news on 2FA and am happy that the discussion came up again. I would also endorse the proposal of PASSWORD;TOTP. Having no 2FA for some of the apps makes me somewhat nervous nowadays.<br />
I totally understand that this is less than ideal from an UX perspective, but I don't see how it would hurt if admins can optionally enable it.</p>
]]></description><link>https://forum.cloudron.io/post/24771</link><guid isPermaLink="true">https://forum.cloudron.io/post/24771</guid><dc:creator><![CDATA[hendrikvl]]></dc:creator><pubDate>Wed, 03 Feb 2021 13:39:59 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Mon, 14 Dec 2020 20:13:17 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nj" aria-label="Profile: nj">@<bdi>nj</bdi></a> Apart from what you mentioned, I think for 1) there is also the issue that we somehow need to update the 2FA inside the app's database when the cloudron 2fa changes. Recently, I saw that some apps like rocket.chat can pull 2FA from LDAP. I haven't looked into it closely but maybe some sort of standardization is happening in this space.</p>
<p dir="auto">Can consider this for next release nevertheless. It's actually very easy to implement, the hard part is to not confuse end users. But really, all the hard work has to be done the Cloudron admin to communicate to their users.</p>
]]></description><link>https://forum.cloudron.io/post/21630</link><guid isPermaLink="true">https://forum.cloudron.io/post/21630</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 14 Dec 2020 20:13:17 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Mon, 14 Dec 2020 19:43:07 GMT]]></title><description><![CDATA[<p dir="auto">The comment thread on this post seems to have diverted from the original topic. I would like to comment on <a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a>'s request for 2FA for LDAP apps. As <a class="plugin-mentions-user plugin-mentions-a" href="/user/girish" aria-label="Profile: girish">@<bdi>girish</bdi></a> has said, we have had a long discussion about it, and the team couldn't come up with a one-size-fits-all solution. I was expecting the PASSWORD;TOTP feature in version 6 too. Here's my understanding and proposed solution:</p>
<hr />
<p dir="auto"><strong>1. Apps that have their own 2FA system, like Gogs, Gitlab, Wiki.JS, etc.</strong><br />
NOTE: I have used this trick in quite a few apps to save myself from having <em>dozens</em> of 2FA secrets. I simply replace the app's <code>mfa_secret</code> value with the secret from Cloudron (<em>Hint: while setting up 2FA on your Cloudron account, select to enter code manually, and write the displayed secret in a piece of paper so you can copy it elsewhere</em>).</p>
<p dir="auto">Cloudron has access to the database so Cloudron could automate this process:</p>
<ul>
<li>enabling 2FA for that user in the app by authenticating as that user.</li>
<li>replacing the TOTP secret in the app with the TOTP secret from the Cloudron user account.</li>
</ul>
<p dir="auto">The 2FA code from Cloudron will also work on the app, so no need to have per-app 2FA codes. But this approach has downsides:</p>
<ol>
<li>The maintainer of this feature needs to keep things updated when the app's database schema changes!</li>
<li>The apps usually create a new account when the user logs in using LDAP. For the above approach to work, Cloudron should make those changes before the user's account is created on the app.</li>
</ol>
<p dir="auto">I have only done this with my own account because it's quite time consuming to replace the TOTP Secret for all users of my Cloudron instance; a script would certainly help.</p>
<hr />
<p dir="auto"><strong>2. Apps that do note have native support for 2FA</strong><br />
Proposed solutions:</p>
<ul>
<li>Cloudron adds a feature to support <em>PASSWORD;TOTP</em> as password, and validate <em>TOTP</em> by extracting it from the input. For this to work, all users must be informed. I wish password managers and authenticator apps had a feature to make it easier to auto-fill 2FA codes as well...  <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f644.png?v=11345d81604" class="not-responsive emoji emoji-android emoji--face_with_rolling_eyes" style="height:23px;width:auto;vertical-align:middle" title=":face_with_rolling_eyes:" alt="🙄" /></li>
<li><em>can't think of another way, will add if I can come up with something</em></li>
</ul>
<hr />
<p dir="auto">Enabling 2FA for all apps is an important feature for some users like me, because of compliance reasons &amp; a bit of paranoia. I can't trust everyone to not fall for phishing attacks, so I really wish Cloudron team kept this feature in priority. For the time being, I'm enabling 2FA in per-app basis, and avoiding apps that don't have 2FA built in. <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/270c.png?v=11345d81604" class="not-responsive emoji emoji-android emoji--v" style="height:23px;width:auto;vertical-align:middle" title=":v:" alt="✌" /></p>
]]></description><link>https://forum.cloudron.io/post/21598</link><guid isPermaLink="true">https://forum.cloudron.io/post/21598</guid><dc:creator><![CDATA[nj]]></dc:creator><pubDate>Mon, 14 Dec 2020 19:43:07 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 09 Dec 2020 15:14:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Big fan of Vivaldi browser on macOS but there's no iOS version, there is an Android though, so worth a play, being a Chromium iteration as I understand.</p>
]]></description><link>https://forum.cloudron.io/post/21136</link><guid isPermaLink="true">https://forum.cloudron.io/post/21136</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 09 Dec 2020 15:14:13 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 09 Dec 2020 14:46:07 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> nice, I might give that a spin.  I've actually got uBlock Origin and Privacy Badger addons installed on my Firefox Android... but now I'm wondering if they get used/ included in app instances... hope/ guess so!</p>
<p dir="auto">I've recently tried out Bromite (a privacy focused fork of Chromium) after someone mentioned when I tweeted about an annoyance with using Mastodon using Firefox on Andriod (with long toots it's impossible to reply because you can't get down to the Toot button)... I quite like it but even though it's using uBlock and other filters it doesn't seem to actually block as much as Firefox + uBlock (possible because Bromite doesn't support CSS filter, I think).</p>
<p dir="auto">Have you looked into good open source source Chromium forks before? Ideally ones that block ads. I find Twitter works better in Chromium based browsers on Android than on Firefox, but I can't stand seeing ads and I don't see them on Firefox with uBlock...</p>
]]></description><link>https://forum.cloudron.io/post/21135</link><guid isPermaLink="true">https://forum.cloudron.io/post/21135</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Wed, 09 Dec 2020 14:46:07 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 09 Dec 2020 14:39:02 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Ditto! If you install Firefox Focus, that adds a bit more privacy capability to all other browsers too. (iOS at least)</p>
]]></description><link>https://forum.cloudron.io/post/21134</link><guid isPermaLink="true">https://forum.cloudron.io/post/21134</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Wed, 09 Dec 2020 14:39:02 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Wed, 09 Dec 2020 14:37:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/14765">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Interesting, I deleted the Facebook app a long time ago. Makes me think I should do the same for other social spyware too. Will give it a try.</p>
</blockquote>
<p dir="auto">One thing I've started doing is using the browser "install app/ add to homepage" whatever they call it feature for various things like Twitter/ Mastodon/ this and other Forums I use so they kinda sorta work like apps but really I'm just using the browser (but I stay logged in and don't have to install the actual app)</p>
]]></description><link>https://forum.cloudron.io/post/21133</link><guid isPermaLink="true">https://forum.cloudron.io/post/21133</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Wed, 09 Dec 2020 14:37:18 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 16:58:29 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/14811">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto">I hear a lot of the claims that you'd be able to see the bandwidth if audio was going to central servers</p>
</blockquote>
<p dir="auto">You need a ridiculously low amount of bandwidth to transmit proper audio: <a href="https://www.wowza.com/blog/opus-codec-the-audio-format-explained" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.wowza.com/blog/opus-codec-the-audio-format-explained</a></p>
<p dir="auto">But the discussion has already went off topic enough.</p>
<p dir="auto">Let's just hope applications will be faster I'm adopting webauthn, than they are at implementing oidc.</p>
]]></description><link>https://forum.cloudron.io/post/14848</link><guid isPermaLink="true">https://forum.cloudron.io/post/14848</guid><dc:creator><![CDATA[fbartels]]></dc:creator><pubDate>Tue, 06 Oct 2020 16:58:29 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 11:07:25 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mehdi" aria-label="Profile: mehdi">@<bdi>mehdi</bdi></a> I think more likely the person I was talking to had been searching for coffee machine related recently.</p>
<p dir="auto">I hear a lot of the claims that you'd be able to see the bandwidth if audio was going to central servers but with the computing power in phones I'm pretty sure they can do the local transcription and just send the data encoded for minimal footprint.</p>
<p dir="auto">It mostly appears to be contact cross-referencing interests but given that any big ad network could acquire data by proxy from a chain of apps to keep their distance from the actual spyware themselves, I'm just increasingly aware of <em>coincidences</em>.</p>
]]></description><link>https://forum.cloudron.io/post/14811</link><guid isPermaLink="true">https://forum.cloudron.io/post/14811</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 06 Oct 2020 11:07:25 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 06:53:51 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/14763">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto">I mentioned "coffee machine" on a phone call to a friend, hadn't typed it in anywhere or searched anything. Next time I look at Twitter the first ad is for a Nespresso machine.</p>
</blockquote>
<p dir="auto">I think it's just a coincidence ^^ There is no reason to think ad companies are literally listening to you 24/7 :  it's too costly from a computing power standpoint, so not worth it.</p>
<p dir="auto">What they're doing is "just" knowing everything else about you : who you're talking to, what your looking at online, what are your interests, your age, where you live ... And based on that, they can just guess that you may be interested in coffee machines.</p>
<p dir="auto">(Which, if you ask me, is even scarier that being listened to ^^)</p>
]]></description><link>https://forum.cloudron.io/post/14790</link><guid isPermaLink="true">https://forum.cloudron.io/post/14790</guid><dc:creator><![CDATA[mehdi]]></dc:creator><pubDate>Tue, 06 Oct 2020 06:53:51 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 06:51:23 GMT]]></title><description><![CDATA[<p dir="auto">@Lonk said in <a href="/post/14710">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto">amazing how ridiculously insecure things were even 15 years ago.</p>
</blockquote>
<p dir="auto">I think people are going to think the same 15 years from now ^^</p>
]]></description><link>https://forum.cloudron.io/post/14789</link><guid isPermaLink="true">https://forum.cloudron.io/post/14789</guid><dc:creator><![CDATA[mehdi]]></dc:creator><pubDate>Tue, 06 Oct 2020 06:51:23 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 01:00:54 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Nice. will try. Been looking at <a href="https://jarvee.com/" target="_blank" rel="noopener noreferrer nofollow ugc">https://jarvee.com/</a> - maybe of interest in a similar API access approach but more for data-mining and marketing.</p>
]]></description><link>https://forum.cloudron.io/post/14771</link><guid isPermaLink="true">https://forum.cloudron.io/post/14771</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 06 Oct 2020 01:00:54 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:59:27 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/14765">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto">I deleted the Facebook app a long time ago</p>
</blockquote>
<p dir="auto">I never even installed it as it asked for such a ridiculous number of permissions.</p>
]]></description><link>https://forum.cloudron.io/post/14769</link><guid isPermaLink="true">https://forum.cloudron.io/post/14769</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:59:27 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:58:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> see also <a href="https://nitter.net/about" target="_blank" rel="noopener noreferrer nofollow ugc">Nitter</a> and similar apps for accessing other platforms.</p>
]]></description><link>https://forum.cloudron.io/post/14768</link><guid isPermaLink="true">https://forum.cloudron.io/post/14768</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:58:45 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:26:18 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/jdaviescoates" aria-label="Profile: jdaviescoates">@<bdi>jdaviescoates</bdi></a> Interesting, I deleted the Facebook app a long time ago. Makes me think I should do the same for other social spyware too. Will give it a try.</p>
]]></description><link>https://forum.cloudron.io/post/14765</link><guid isPermaLink="true">https://forum.cloudron.io/post/14765</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:26:18 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:23:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/marcusquinn" aria-label="Profile: marcusquinn">@<bdi>marcusquinn</bdi></a> said in <a href="/post/14763">2FA for all LDAP apps</a>:</p>
<blockquote>
<p dir="auto">Next time I look at Twitter the first ad is for a Nespresso machine.</p>
</blockquote>
<p dir="auto">I only ever look at Twitter through Firefox with ublock origin installed, so don't see ads on there.</p>
<p dir="auto">The UX is a bit shit in the mobile browser (especially since recent Firefox update, ironically), but that helps me to use it less on my mobile! <img src="https://forum.cloudron.io/assets/plugins/nodebb-plugin-emoji/emoji/android/1f61b.png?v=11345d81604" class="not-responsive emoji emoji-android emoji--stuck_out_tongue" style="height:23px;width:auto;vertical-align:middle" title=":P" alt="😛" /></p>
]]></description><link>https://forum.cloudron.io/post/14764</link><guid isPermaLink="true">https://forum.cloudron.io/post/14764</guid><dc:creator><![CDATA[jdaviescoates]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:23:30 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:20:34 GMT]]></title><description><![CDATA[<p dir="auto">What most people don't realise is that all the add-ons, extensions and social-logins would once have been considered trojans for the snooping capabilities they have.</p>
<p dir="auto">I mentioned "coffee machine" on a phone call to a friend, hadn't typed it in anywhere or searched anything. Next time I look at Twitter the first ad is for a Nespresso machine.</p>
<p dir="auto">So, it doesn't matter how good my security is, we all rely on the security of everyone we are connected to.</p>
]]></description><link>https://forum.cloudron.io/post/14763</link><guid isPermaLink="true">https://forum.cloudron.io/post/14763</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:20:34 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA for all LDAP apps on Tue, 06 Oct 2020 00:18:00 GMT]]></title><description><![CDATA[<p dir="auto">@Lonk agreed, and misinformation and information-overload cause a lot of vulnerabilities for people that don't know what we do, and even we find difficult to truly solve. Steps in the right direction though.</p>
]]></description><link>https://forum.cloudron.io/post/14712</link><guid isPermaLink="true">https://forum.cloudron.io/post/14712</guid><dc:creator><![CDATA[marcusquinn]]></dc:creator><pubDate>Tue, 06 Oct 2020 00:18:00 GMT</pubDate></item></channel></rss>