Welcome to the mailbox user forum
 

Add Yubikey/FIDO2 WebAuth as another 2FA option to Login 2.0

NovaViper shared this idea 10 months ago
Planned

Hey, my account was recently migrated over to Login 2.0 and to my dismay, I saw it no longer had Yubikey support built into it (thankfully I wasn't locked out since I had OTPs as a fallback option when I first enabled 2FA on the old setup). I'm wondering if there are any plans to add back Yubikey support into the new login interface.

As a bonus option, add FIDO2 webauth as another 2FA option to expand the support for various hardware based keys, not just Yubikeys! This bonus feature would allow for mobile phones to be used as a method of 2FA login.

Replies (6)

photo
1

I would also be happy to get Yubikey support.

This comment is in trash! Restore
photo
2

They are working on it (Yubikeys)... but this can mean weeks, months or even years. :) I hope Nitrokeys and others will be supported.

This comment is in trash! Restore
photo
1

You can use your yubikeys to generate TOTP and add them in as 2FA devices. I just tried this and it works fine. But yes, would be cool to have native support and possibly FIDO2.

This comment is in trash! Restore
photo
1

How did you do that? Do you have private or business accounts? When I go to "Security -> 2FA Authentication" it allows only TOTP with an App, i.e. Google Authenticator. Did I miss something?

This comment is in trash! Restore
photo
1

I followed this: https://support.yubico.com/hc/en-us/articles/360013789259-Using-your-YubiKey-with-authenticator-codes

I have standard account. This is a cool feature that you can use. HTH.

This comment is in trash! Restore
photo
photo
1

I support this, adding Yubikey as 2FA is very important for me

This comment is in trash! Restore
photo
9

Hi,

just to chime in here: we are actively working on Yubikey support within Login 2.0.


Best,

Hendrik

This comment is in trash! Restore
photo
1

Nitrokey?

This comment is in trash! Restore
photo
2

I’ll take a look, but as they mostly support FIDO2/U2F this should be possible as well.

This comment is in trash! Restore
photo
3

Thats good to hear, thanks! Could you please consider publishing an overview of things you are working on or some sort of roadmap (doesn‘t even need any date estimations) but just to get some transparency and know what you have planned/in progress.

This comment is in trash! Restore
photo
2

Hi Mailbox Team, it has been a few months - do you have an update for us on when we might anticipate Yubikey/FIDO2/U2F support? Thanks!

This comment is in trash! Restore
photo
photo
1

Hello. This is so immportant to get done. I just got phished through whatsapp sending me hotel booking information that the hacker can only know through either reading my booking mails or if booking.com was hacked. I have never tried such sophosticated attack before. I have to order a new credit card now.


I also get mails like this:

6debcd003aae5f6fa50e97f9978caa79

Can you please improve your security. I have used yubikeys (FIDO2) for several years. I do not want TOTP codes.

This comment is in trash! Restore
photo
1

I am sorry this happened to you, but I would not call a phishing attempt sent by "jshull380@outlook.com" sophisticated.

That said, FIDO2 would have helped here.

This comment is in trash! Restore
photo
1

That was not the phishing attempt I was referring to. These are two separate phishing attempts. The above imaged phishing attempt I have received twice over a couple of weeks.

This comment is in trash! Restore
photo
1

Hello asbjoedt,

We sincerely apologise for the inconvenience caused by the recent wave of phishing attacks.

We analysed the situation and cleared all affected inboxes of the phishing messages. We have also reviewed and further strengthened our security measures to protect your data as effectively as possible.

Your security and trust are very important to us. Should you have any further questions or require assistance, our Support team is always happy to help.

Yubikey support is still planned, and we will let you know once it is implemented.


Kind regards

Your mailbox Team

---

Useful links:

d9e15a7fee470fb66af17115c3a43886

This comment is in trash! Restore
photo
Leave a Comment
 
Attach a file
You can't vote. Please authorize!