Skip to main content

MFA Email Factor for Users with Registered Accounts

Comments

2 comments

  • Connor Woolfolk
    Community Manager

    Hello,

    Thank you for submitting this enhancement request! We have raised this type of enhancement to our product and engineering teams in the past, and it was determined that email based OTP for MFA is considered insecure, and they had decided to not go down the path of implementation due to the security risk. However, I do believe DUO carries some of this functionality, and DUO Is already supported within Cerberus. That is what we tend to suggest to folks looking for email based OTP for MFA.

    0
  • Systems

    Hi Connor,

    I understand the concern however Duo requires 3$/month/user and requires additional overhead to provision ad hoc third-party vendors which use our system a few times a year. Email OTP would be a preferred usage as we use CerberusFTP for B2B. It would be a nice feature and allow us to assess risk for our use case, if you allowed the administrator to select acceptable MFA assigned by Group that would be great.

    Our issue is within regulated spaces cellphones and new software are not permitted or requires extensive review. The usage of Duo would require SMS, Duo Push or us shipping hardware tokens to vendors, while every business has email. CerberusFTP excels in it's ability to work in regulated spaces while being able to selfhost and having a limitation. We assess vendor email risk outside Cerberus and allowing this flexibility would be great. May I ask this option to be reconsidered?

    Feel free to reach out via email if you'd like to understand our use case and reasoning behind this request.

    0

Please sign in to leave a comment.