<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[[Implemented] Two Factor Authentication (2FA)]]></title><description><![CDATA[<p dir="auto">I actually wanted to answer this topic: <a href="https://vulndetect.org/topic/344/data-processing-policy">https://vulndetect.org/topic/344/data-processing-policy</a>, but wasn't able to. Probably because this thread is somehow in Announcements!?</p>
<p dir="auto">Anyway, my answer: I really don't like this architecture. From a security point of view, it is extremely valuable data to have a list of security vulnerabilities of a (or better said: of MANY) concrete targets. It would be way more secure to have all the data stay on the clients.</p>
<p dir="auto">Anyway, since I don't know a good alternative, I'll stay with VulnDetect for now. In order to protect my account as good as possible, I would like to see two factor authentication being implemented to the website. Shouldn't be a big issue since libraries for HOTP/TOTP are publicly available.</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://vulndetect.org/topic/501/implemented-two-factor-authentication-2fa</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 23:44:28 GMT</lastBuildDate><atom:link href="https://vulndetect.org/topic/501.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 12 Dec 2018 19:48:47 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Mon, 14 Sep 2020 16:13:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> Yes, this is implemented</p>
]]></description><link>https://vulndetect.org/post/3841</link><guid isPermaLink="true">https://vulndetect.org/post/3841</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Mon, 14 Sep 2020 16:13:38 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 13 Sep 2020 16:24:09 GMT]]></title><description><![CDATA[<p dir="auto">In the <strong>business UI</strong> 2FA (Two Factor Authentication) is working:</p>
<p dir="auto"><img src="/assets/uploads/files/1600014178169-abdf087d-f5bb-4956-ab2a-cc4d153829ac-image.png" alt="abdf087d-f5bb-4956-ab2a-cc4d153829ac-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">The icon in the 2FA field is from <strong>KeePassXC</strong>.</p>
<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong> Should I mark the issue as <strong>Implemented</strong>?</p>
]]></description><link>https://vulndetect.org/post/3840</link><guid isPermaLink="true">https://vulndetect.org/post/3840</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 13 Sep 2020 16:24:09 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 12 Jul 2020 17:32:45 GMT]]></title><description><![CDATA[<p dir="auto">It is a very small change:<br />
One programmer of KeePassCX suggests:</p>
<blockquote>
<p dir="auto">Yes, adding <code>name="2fa"</code> would be enough. However, I'd suggest using <code>autocomplete="one-time-code"</code></p>
</blockquote>
]]></description><link>https://vulndetect.org/post/3719</link><guid isPermaLink="true">https://vulndetect.org/post/3719</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 12 Jul 2020 17:32:45 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 12 Jul 2020 17:20:45 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/olli_s" aria-label="Profile: OLLI_S">@<bdi>OLLI_S</bdi></a> I'm not much into the details of the two factor authentication. But I will push for a review of it.</p>
<p dir="auto">However, during the rest of July and the first half of August we have a development freeze, which means that we will only fix critical bugs, due to vacations. The earliest this will be handled is in late August.</p>
]]></description><link>https://vulndetect.org/post/3716</link><guid isPermaLink="true">https://vulndetect.org/post/3716</guid><dc:creator><![CDATA[Tom]]></dc:creator><pubDate>Sun, 12 Jul 2020 17:20:45 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 12 Jul 2020 17:16:49 GMT]]></title><description><![CDATA[<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong> When will this little issue be fixed?<br />
It is very annoying, because I delete the browser cache very often and then I have to manually search the entry in KeePassXC and manually copy and paste the 2FA code.<br />
And I reported this issue <strong>4 months ago</strong>!</p>
]]></description><link>https://vulndetect.org/post/3715</link><guid isPermaLink="true">https://vulndetect.org/post/3715</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 12 Jul 2020 17:16:49 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Thu, 26 Mar 2020 11:07:26 GMT]]></title><description><![CDATA[<p dir="auto">I found a <strong>small issue</strong> in the 2FA login:<br />
The field where I enter the 2FA code is not named properly, so password managers can not fill this fields.</p>
<p dir="auto">I am using <strong><a href="https://keepassxc.org/" rel="nofollow ugc">KeePassXC</a></strong> and this password manager does not only fill the username and password into login fields (if the URL matches), it also fills the 2FA code in the login form.<br />
KeePassXC can generate the 2FA codes.</p>
<p dir="auto">Normally I see in the field where I have to enter the 2FA code a green icon on the right:</p>
<p dir="auto"><img src="/assets/uploads/files/1585220632673-add613f8-f643-4560-a16a-a69546666fc1-image.png" alt="add613f8-f643-4560-a16a-a69546666fc1-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I just click this icon and KeePassXC fills the 2FA code.</p>
<p dir="auto">At VulnDetect this icon is missing:</p>
<p dir="auto"><img src="/assets/uploads/files/1585220656537-fdd59d57-0314-4f0e-92c4-36522592e596-image.png" alt="fdd59d57-0314-4f0e-92c4-36522592e596-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">So here I have to switch to KeePassXC, search for the entry "VulnDetect", select the entry in the search results, manually copy the 2FA code and paste it in the field.</p>
<p dir="auto">The fix is very easy and described here:<br />
<strong><a href="https://github.com/keepassxreboot/keepassxc-browser/issues/826" rel="nofollow ugc">https://github.com/keepassxreboot/keepassxc-browser/issues/826</a></strong></p>
<p dir="auto">So please fix this, all users using password managers will benefit from it.</p>
]]></description><link>https://vulndetect.org/post/3242</link><guid isPermaLink="true">https://vulndetect.org/post/3242</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Thu, 26 Mar 2020 11:07:26 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Tue, 24 Mar 2020 22:03:22 GMT]]></title><description><![CDATA[<h3>One very important annotation to this feature:</h3>
<p dir="auto"><strong>Besides to the QR-Code</strong> many services offer the <strong>Two-Factor-Token also as plain text</strong> (the part behind <strong>secret=</strong>) that can be copied to the clipboard and then inserted in any Two Factor App on the Desktop.</p>
<p dir="auto">I am using <strong><a href="https://keepassxc.org/" rel="nofollow ugc">KeePassXC</a></strong> and this client can also generate 2FA keys for the two-factor-authentication.<br />
I am lucky that many services like GitHub, Google and Paypal (just some examples) offer the Two-Factor-Token as plain text.</p>
<p dir="auto">Otherwise I have to use a QR-Code scanner on my phone, scan this code, send me the code from my phone to myself, open the mail app, copy the code (the part behind <strong>secret=</strong>) and paste it in KeePassXC.<br />
Showing the Two-Factor-Token makes it much easier for me (and also other users).</p>
]]></description><link>https://vulndetect.org/post/3240</link><guid isPermaLink="true">https://vulndetect.org/post/3240</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Tue, 24 Mar 2020 22:03:22 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 11 Aug 2019 19:53:06 GMT]]></title><description><![CDATA[<p dir="auto"><strong><a class="plugin-mentions-user plugin-mentions-a" href="/user/tom" aria-label="Profile: Tom">@<bdi>Tom</bdi></a></strong><br />
You store very sensitive data (the complete list of application that a user has installed).<br />
Families will have the option to store multiple computers in one account.<br />
And business users also have multiple computers and here a leak of information could be critical.</p>
<p dir="auto">So please implement Two Factor Authentication (2FA) by allowing users to log on with a Temporal One Time Password (TOTP).</p>
<p dir="auto">And please don't forget to add 2FA Recovery Codes (codes that users get when they set up 2FA and that can be used instead of 2FA).</p>
]]></description><link>https://vulndetect.org/post/3144</link><guid isPermaLink="true">https://vulndetect.org/post/3144</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 11 Aug 2019 19:53:06 GMT</pubDate></item><item><title><![CDATA[Reply to [Implemented] Two Factor Authentication (2FA) on Sun, 11 Aug 2019 19:49:28 GMT]]></title><description><![CDATA[<p dir="auto">A Two Factor Authentication is really a cool idea, thank you for suggesting this!<br />
I linked it in the <strong><a href="https://vulndetect.org/topic/15/overview-of-feature-and-functionality-requests">Overview of Feature and Functionality Requests</a></strong>.</p>
]]></description><link>https://vulndetect.org/post/1974</link><guid isPermaLink="true">https://vulndetect.org/post/1974</guid><dc:creator><![CDATA[OLLI_S]]></dc:creator><pubDate>Sun, 11 Aug 2019 19:49:28 GMT</pubDate></item></channel></rss>