Linode Forum Index Linode Forum
Linode Community Forums
 


Two Factor Authentication

Click here to go to the original topic
Goto page 1, 2, 3  Next
 
       Linode Forum Index -> Feature Request/Bug Report
Author Message
k33l0r



Joined: 24 Oct 2008
Posts: 27

Posted: Sat Aug 27, 2011 4:25 am    Post subject: Two Factor Authentication  

Could we get two-factor authentication for the Linode Manager?

Speaking as a developer, it should be fairly simple to add using either the Google Authenticator (for example see this tutorial for Rails) or something like MailChimp's AlterEgo (though I of course have no knowledge of your existing systems or code, for all I know it might actually be hard).
Back to top  
obs



Joined: 07 Mar 2010
Posts: 1403
Location: Earth

Posted: Sat Aug 27, 2011 4:35 am    Post subject:  

Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist
Back to top  
reaktor



Joined: 12 Jun 2010
Posts: 52

Posted: Sat Aug 27, 2011 5:34 pm    Post subject:  

This would be great.

yubikey would be awesome,
Back to top  
dugsong



Joined: 28 Aug 2011
Posts: 1

Posted: Sun Aug 28, 2011 8:52 am    Post subject: Duo Security  

Sorry to suggest our company's product here. I figured mention of other open-source / free solutions meant an honest suggestion of our own (which is also open-source, and free for most Unix admin deployments) might be acceptable. I'm a fan of our own product, what can I say.

Hope you guys find something reasonable to implement. It's an important feature.
Back to top  
glg



Joined: 09 Jan 2009
Posts: 505

Posted: Sun Aug 28, 2011 9:11 am    Post subject: Re: Duo Security  

dugsong wrote: SPAM
Woo spammer!
Back to top  
pclissold



Joined: 24 Oct 2003
Posts: 877
Location: Netherlands

Posted: Sun Aug 28, 2011 11:09 am    Post subject:  

Cool new TLD. Who fixed his company name and link?
Back to top  
glg



Joined: 09 Jan 2009
Posts: 505

Posted: Sun Aug 28, 2011 2:03 pm    Post subject:  

pclissold wrote: Cool new TLD. Who fixed his company name and link?

Sounds like a good sign that the weather isn't all that bad in NJ :)
Back to top  
waldo



Joined: 21 May 2009
Posts: 336

Posted: Sun Aug 28, 2011 2:48 pm    Post subject:  

obs wrote: Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist

Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.
Back to top  
obs



Joined: 07 Mar 2010
Posts: 1403
Location: Earth

Posted: Sun Aug 28, 2011 6:11 pm    Post subject:  

waldo wrote: obs wrote: Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist

Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.

Never had one take more than a minute myself (I think) try poking support.
Back to top  
sweh



Joined: 13 Apr 2004
Posts: 565

Posted: Sun Aug 28, 2011 7:03 pm    Post subject:  

waldo wrote: obs wrote: Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist

Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.

Do you have grey-listing or other anti-spam features in place that might slow down incoming mail? I've always received this message in a timely manner.
Back to top  
db3l



Joined: 13 May 2009
Posts: 556

Posted: Sun Aug 28, 2011 8:17 pm    Post subject:  

I don't think it's just waldo... I tried one myself and it took a while (4-5 minutes). In looking at the headers, the first Date: and first Received: line (internally at Linode) were delayed from the timestamp in the bottom of the message by about 4 minutes. So definitely held up within Linode. At least in my case, after that first transmission, it made it the rest of the way to me in just a few seconds.

Can't say if it's a transient problem or actually a periodic processing of the white lists, though the former seems more likely as although I haven't used this notice a lot, I would have sworn the last time was faster.

-- David
Back to top  
ldilley



Joined: 07 Oct 2011
Posts: 2

Posted: Fri Oct 07, 2011 3:15 pm    Post subject:  

I also think it would be nice for Linode to offer an optional RSA token or something similar (like the mobile Battle.net authenticator) for an added layer of security.

Regards,
Lloyd D.
Back to top  
Obsidian



Joined: 20 Apr 2011
Posts: 39

Posted: Fri Oct 07, 2011 3:33 pm    Post subject:  

reaktor wrote: This would be great.

yubikey would be awesome,

I'd second this. A yubikey OTP as an optional second authentication factor would be quite welcome.
Back to top  
Piki



Joined: 16 Jun 2011
Posts: 276
Location: Cyberspace

Posted: Fri Oct 07, 2011 8:17 pm    Post subject:  

Perhaps a randomly selected secret question, similar to online banking. The user presets several questions, one displays at random. To make associating the answers to the questions, the question being asked could be scrambled slightly in CAPTCHA style to confuse spambots. To make it harder to guess by humanoids, some similar looking questions could be suggested.
Back to top  
hybinet



Joined: 02 May 2008
Posts: 1058

Posted: Fri Oct 07, 2011 9:17 pm    Post subject:  

Piki wrote: Perhaps a randomly selected secret question, similar to online banking.
The problem with this approach is that anyone who knows a bit about the user's life history can easily guess the answers. Especially if the questions are about your hometown, favorite band, mom's maiden name, etc. These days, even strangers can figure out many of these things by looking at your Facebook. So although it's better than nothing, it's nowhere near as secure as a physical token like yubikey.
Back to top  
 
       Linode Forum Index -> Feature Request/Bug Report Goto page 1, 2, 3  Next
Page 1 of 3