Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

What if I lose my phone? #63

Closed
UDZGuru opened this issue Oct 7, 2016 · 2 comments
Closed

What if I lose my phone? #63

UDZGuru opened this issue Oct 7, 2016 · 2 comments

Comments

@UDZGuru
Copy link

UDZGuru commented Oct 7, 2016

Hi, I just activated 2FA for my owncloud instance and it works just as expected (using Google Authenticator app).

I set up several app-specific passwords which also work fine. So I guess I have to thank you for the great work.

But I do have one little worry: What happens if I lose / destroy my phone so I cannot access the registered TOTP app anymore?

One thing is for sure: I cannot log in regularly via web interface to owncloud anymore. And probably I cannot change the login-system to "regular" from the owncloud app.

Is there a security fallback for such a case? Google provides a list of "backup-codes" which would work in such a case. So you have to know the username/password combination PLUS have such a backup code (which invalidates itself after one-time usage).

I would love to see such a fallback for emergency cases.

@ChristophWurst
Copy link
Member

Good point. We've thought about that too, so we added backup codes to Nextcloud. See nextcloud/server#1171 for implementation details. This will be available soon as part of Nextcloud 11 🚀

@ChristophWurst
Copy link
Member

FYI: since Nextcloud will soon have its own app store, I will no longer maintain this app for ownCloud.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants