Re: [CGP-Update] [*] CommuniGate Pro 6.2c1 is released
Nicolas Hatier <[email protected]> Wed, 15 Feb 2017 10:20:56 -0500
| Newsgroups | gmane.mail.cgatepro.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------5EC633B3541750DD76A90201 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: quoted-printable Hello To the developers: I know this is a preliminary version. But the current = implementation of the two-factor authentication for webmail has a=20 blatant flaw, since it relies on a field being sent by the client=20 browser. If all I have to do is to press F12 on my browser and remove=20 the x2auth value to bypass 2fa, well, that's not very secure. I=20 understand Mr Average Joe probably won't be able to do that, but that's=20 not the point here. If CGP can get something directly from strings.data without relying on=20 the client browser to send it, that's where I would put the x2auth=3D1=20 value. If CGP can't get something from strings.data, you may want to put = an intermediate wssp step that contains a conditional server-side=20 redirect or something like that. *Nicolas Hatier, ing.* <[email protected]=20 <mailto:[email protected]>> Niversoft id=C3=A9es logicielles - http://www.niversoft.com On 2017-02-14 15:38, Technical Support wrote: > Major Release > > * SESSION: two-factor authentication framework has been implemented. > * XIMSS: the protocol has been extended to support two-factor authentic= ation and forced password change. > * WebUser: the interface has been extended to support two-factor authen= tication and forced password change. > --------------5EC633B3541750DD76A90201 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Ty= pe"> </head> <body bgcolor=3D"#FFFFFF" text=3D"#000000"> <br> Hello<br> <br> To the developers: I know this is a preliminary version. But the current implementation of the two-factor authentication for webmail has a blatant flaw, since it relies on a field being sent by the client browser. If all I have to do is to press F12 on my browser and remove the x2auth value to bypass 2fa, well, that's not very secure. I understand Mr Average Joe probably won't be able to do that, but that's not the point here.<br> <br> If CGP can get something directly from strings.data without relying on the client browser to send it, that's where I would put the x2auth=3D1 value. If CGP can't get something from strings.data, you may want to put an intermediate wssp step that contains a conditional server-side redirect or something like that.<br> <div class=3D"moz-signature"><br> <p><b>Nicolas Hatier, ing.</b> <<a style=3D"text-decoration:none= ; color:inherit" href=3D"mailto:[email protected]">nic= [email protected]</a>><br> Niversoft id=C3=A9es logicielles - <a style=3D"text-decoration:no= ne; color:inherit" href=3D"http://www.niversoft.com">http://www.niv= ersoft.com</a></p> <br> <br> </div> <div class=3D"moz-cite-prefix">On 2017-02-14 15:38, Technical Support= wrote:<br> </div> <blockquote cite=3D"mid:[email protected]" type=3D"cite"= > <pre wrap=3D""> Major Release * SESSION: two-factor authentication framework has been implemented. * XIMSS: the protocol has been extended to support two-factor authenticat= ion and forced password change. * WebUser: the interface has been extended to support two-factor authenti= cation and forced password change. </pre> </blockquote> <br> </body> </html> --------------5EC633B3541750DD76A90201--