Re: [CGP-Update] [*] CommuniGate Pro 6.2c1 is released

Nicolas Hatier <[email protected]> Wed, 15 Feb 2017 10:20:56 -0500
Newsgroups gmane.mail.cgatepro.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------5EC633B3541750DD76A90201
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable


Hello

To the developers: I know this is a preliminary version. But the current =

implementation of the two-factor authentication for webmail has a=20
blatant flaw, since it relies on a field being sent by the client=20
browser. If all I have to do is to press F12 on my browser and remove=20
the x2auth value to bypass 2fa, well, that's not very secure. I=20
understand Mr Average Joe probably won't be able to do that, but that's=20
not the point here.

If CGP can get something directly from strings.data without relying on=20
the client browser to send it, that's where I would put the x2auth=3D1=20
value. If CGP can't get something from strings.data, you may want to put =

an intermediate wssp step that contains a conditional server-side=20
redirect or something like that.

*Nicolas Hatier, ing.* <[email protected]=20
<mailto:[email protected]>>
Niversoft id=C3=A9es logicielles - http://www.niversoft.com



On 2017-02-14 15:38, Technical Support wrote:
> Major Release
>
> * SESSION: two-factor authentication framework has been implemented.
> * XIMSS: the protocol has been extended to support two-factor authentic=
ation and forced password change.
> * WebUser: the interface has been extended to support two-factor authen=
tication and forced password change.
>


--------------5EC633B3541750DD76A90201
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html>
  <head>
    <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Ty=
pe">
  </head>
  <body bgcolor=3D"#FFFFFF" text=3D"#000000">
    <br>
    Hello<br>
    <br>
    To the developers: I know this is a preliminary version. But the
    current implementation of the two-factor authentication for webmail
    has a blatant flaw, since it relies on a field being sent by the
    client browser. If all I have to do is to press F12 on my browser
    and remove the x2auth value to bypass 2fa, well, that's not very
    secure. I understand Mr Average Joe probably won't be able to do
    that, but that's not the point here.<br>
    <br>
    If CGP can get something directly from strings.data without relying
    on the client browser to send it, that's where I would put the
    x2auth=3D1 value. If CGP can't get something from strings.data, you
    may want to put an intermediate wssp step that contains a
    conditional server-side redirect or something like that.<br>
    <div class=3D"moz-signature"><br>
      <p><b>Nicolas Hatier, ing.</b> &lt;<a style=3D"text-decoration:none=
;
          color:inherit" href=3D"mailto:[email protected]">nic=
[email protected]</a>&gt;<br>
        Niversoft id=C3=A9es logicielles - <a style=3D"text-decoration:no=
ne;
          color:inherit" href=3D"http://www.niversoft.com">http://www.niv=
ersoft.com</a></p>
      <br>
      <br>
    </div>
    <div class=3D"moz-cite-prefix">On 2017-02-14 15:38, Technical Support=

      wrote:<br>
    </div>
    <blockquote cite=3D"mid:[email protected]" type=3D"cite"=
>
      <pre wrap=3D"">
Major Release

* SESSION: two-factor authentication framework has been implemented.
* XIMSS: the protocol has been extended to support two-factor authenticat=
ion and forced password change.
* WebUser: the interface has been extended to support two-factor authenti=
cation and forced password change.

</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------5EC633B3541750DD76A90201--