4 ms·
Yeah so about that 2FA. I have a local email client, which uses IMAP and hence cannot do 2FA. What now? I've always thought this is rather a gaping hole. Of
by toothbrush 10y ago
Yeah so about that 2FA. I have a local email client, which uses IMAP and hence cannot do 2FA. What now? I've always thought this is rather a gaping hole. Of course i use app-specific passwords which presumably won't allow access to webmail or changing the account password, but still, if someone got my app password for IMAP, they could still siphon out password reset emails for all my other services.
What do the rest of you do? Only use webmail with 2FA, disable all other access? That seems onerous.
- tobyjsullivan 10y agoDepends on your underlying email service provider. If it is gmail, for example, then they provide one-time use passwords for exactly his purpose. What this means is if you enable 2FA for your gmail account, you can generate a one-time password to authorize any client which does not support a 2FA auth flow. This password is then destroyed by both parties. If you run your own email server, I think you are at low risk of being attacked in a more general phishing net. An attacker targeting you personally still has many options but that is much less likely.
- sly010 10y ago> This password is then destroyed by both parties. I don't quite understand this. Won't the email client need the need the password every time to auth with IMAP?
- zeroxfe 10y agoSome IMAP providers like Gmail use a more sophisticated auth mechanism where a secret token is shared over the encrypted link after the first password auth. This token typically has a long lifetime and is used for future sessions.
- BrandoElFollito 10y agoI have never heard of that, do you have any sources?
- tedunangst 10y agoIf you simply don't use webmail, you're about 99% less likely to accidentally type your password into a website that happens to look like your webmail login page (which doesn't exist).
- toothbrush 10y agoSure. FWIW i avoid using webmail as much as i can, but that's just because i love my mu4e. Still though, i wonder about what would happen in the (admittedly very unlikely) event that someone compromised my secrets file. (example off the top of my head: seized backup disk at border control)
- tedunangst 10y agoYeah, depends on what your threat model is. You'll go crazy treating every possible threat as "guaranteed to happen; must defend" though. If you're worried about border control, at least you'll know if they search your stuff and can revoke access after the fact, which puts it in a slightly different category than day to day surreptitious password theft.