Welcome to the mailbox.org user forum!
 

2FA Pointless Currently

8875100 shared this idea 15 days ago
Proposed

Does setting up 2FA serve any real purpose?


If someone got in to my email thru IMAP, can they just then reset my email password eliminating 2FA?

Replies (1)

photo
1

no, the web portal with your control panel is protected by a 4-digit pin + your password.

photo
1

* i mean 4-digit pin + one-time-password or yubikey

photo
1

That what I thought. But I was able to use the “forgot password” to change a password and retrieve thru my IMAP access. At that point it turned off 2FA and I was able to login via the web portal.

photo
Leave a Comment
 
Attach a file