nextensio / tickets

0 stars 0 forks source link

2FA support on the Nextensio controller login #4

Open greg-next opened 2 years ago

greg-next commented 2 years ago

Considering that the Nextensio controller may have customer-sensitive information in it, please add support for a second factor at login.

Preferred second factors would be an authenticator app (e.g., Google Authenticator) and a security key such as Titan Security Key or YubiKey. A recovery process will also be needed.

SMS second factors are still compromised by sim-stealing attacks and known vulnerabilities in the SS7 network.

greg-next commented 2 years ago

Consider using OneLogin https://www.onelogin.com/