Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sat Aug 27, 2011 5:25 am 
Offline
Junior Member

Joined: Fri Oct 24, 2008 4:56 pm
Posts: 28
Website: http://matiaskorhonen.fi
Could we get two-factor authentication for the Linode Manager?

Speaking as a developer, it should be fairly simple to add using either the Google Authenticator (for example see this tutorial for Rails) or something like MailChimp's AlterEgo (though I of course have no knowledge of your existing systems or code, for all I know it might actually be hard).


Top
   
 Post subject:
PostPosted: Sat Aug 27, 2011 5:35 am 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
 Post subject:
PostPosted: Sat Aug 27, 2011 6:34 pm 
Offline
Senior Member

Joined: Sat Jun 12, 2010 4:53 pm
Posts: 77
This would be great.

yubikey would be awesome,


Top
   
 Post subject: Duo Security
PostPosted: Sun Aug 28, 2011 9:52 am 
Offline

Joined: Sun Aug 28, 2011 9:46 am
Posts: 1
Sorry to suggest our company's product here. I figured mention of other open-source / free solutions meant an honest suggestion of our own (which is also open-source, and free for most Unix admin deployments) might be acceptable. I'm a fan of our own product, what can I say.

Hope you guys find something reasonable to implement. It's an important feature.


Last edited by dugsong on Sun Aug 28, 2011 10:06 pm, edited 1 time in total.

Top
   
 Post subject: Re: Duo Security
PostPosted: Sun Aug 28, 2011 10:11 am 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
dugsong wrote:
SPAM

Woo spammer!


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 12:09 pm 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
Cool new TLD. Who fixed his company name and link?

_________________
/ Peter


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 3:03 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
pclissold wrote:
Cool new TLD. Who fixed his company name and link?


Sounds like a good sign that the weather isn't all that bad in NJ :)


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 3:48 pm 
Offline
Senior Member

Joined: Thu May 21, 2009 3:19 am
Posts: 336
obs wrote:
Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist


Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 7:11 pm 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
waldo wrote:
obs wrote:
Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist


Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.


Never had one take more than a minute myself (I think) try poking support.

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 8:03 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
waldo wrote:
obs wrote:
Not sure if you know about it but there is a white list by ip address you can set under the profile section of the linode manager, it will email you if you try and log in from a non-white listed address with a link to add the new ip to your whitelist


Which works great when the emails get sent out in a timely manner. I just waited nearly 10 minutes for an email to be sent. Those types of emails should be sent instantly instead of being done on a schedule of some sort.

Just did another test and that took 15 minutes to get the email.


Do you have grey-listing or other anti-spam features in place that might slow down incoming mail? I've always received this message in a timely manner.

_________________
Rgds
Stephen
(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Sun Aug 28, 2011 9:17 pm 
Offline
Senior Member

Joined: Wed May 13, 2009 1:18 am
Posts: 681
I don't think it's just waldo... I tried one myself and it took a while (4-5 minutes). In looking at the headers, the first Date: and first Received: line (internally at Linode) were delayed from the timestamp in the bottom of the message by about 4 minutes. So definitely held up within Linode. At least in my case, after that first transmission, it made it the rest of the way to me in just a few seconds.

Can't say if it's a transient problem or actually a periodic processing of the white lists, though the former seems more likely as although I haven't used this notice a lot, I would have sworn the last time was faster.

-- David


Top
   
 Post subject:
PostPosted: Fri Oct 07, 2011 4:15 pm 
Offline
Newbie

Joined: Fri Oct 07, 2011 3:07 pm
Posts: 2
Website: http://www.dilley.me/
I also think it would be nice for Linode to offer an optional RSA token or something similar (like the mobile Battle.net authenticator) for an added layer of security.

Regards,
Lloyd D.


Top
   
 Post subject:
PostPosted: Fri Oct 07, 2011 4:33 pm 
Offline
Senior Member
User avatar

Joined: Wed Apr 20, 2011 1:09 pm
Posts: 63
reaktor wrote:
This would be great.

yubikey would be awesome,


I'd second this. A yubikey OTP as an optional second authentication factor would be quite welcome.

_________________
うるさいうるさいうるさい!


Last edited by Obsidian on Sun Jan 01, 2012 12:56 pm, edited 1 time in total.

Top
   
 Post subject:
PostPosted: Fri Oct 07, 2011 9:17 pm 
Offline
Senior Member
User avatar

Joined: Thu Jun 16, 2011 8:24 am
Posts: 412
Location: Cyberspace
Perhaps a randomly selected secret question, similar to online banking. The user presets several questions, one displays at random. To make associating the answers to the questions, the question being asked could be scrambled slightly in CAPTCHA style to confuse spambots. To make it harder to guess by humanoids, some similar looking questions could be suggested.

_________________
Kris the Piki Geeker


Top
   
 Post subject:
PostPosted: Fri Oct 07, 2011 10:17 pm 
Offline
Senior Member

Joined: Fri May 02, 2008 8:44 pm
Posts: 1121
Piki wrote:
Perhaps a randomly selected secret question, similar to online banking.

The problem with this approach is that anyone who knows a bit about the user's life history can easily guess the answers. Especially if the questions are about your hometown, favorite band, mom's maiden name, etc. These days, even strangers can figure out many of these things by looking at your Facebook. So although it's better than nothing, it's nowhere near as secure as a physical token like yubikey.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group