View Issue Details

IDProjectCategoryView StatusLast Update
0007097Anastasisanastasis-webuipublic2021-11-16 14:34
ReporterChristian Grothoff Assigned Tosebasjm  
PrioritynormalSeverityminorReproducibilityN/A
Status assignedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Summary0007097: Google TOTP can only do 6 digits
DescriptionWe had one user that used Google TOTP, which can only generate 6 digits. We need to provide guidance that an app that implements TOTP completely (like the ones in F-Droid) must be used because 8 digits is really needed for baseline security here.
Right now, the user basically was stumped as to why we did not accept their 6 digit code.
TagsNo tags attached.

Activities

Christian Grothoff

2021-11-16 14:34

manager   ~0018484

anastasis.gtk 696a49a..f2fbc38 modifies anastasis-gtk to point out that the code must be 8-digits, that Google's TOTP is not working, and suggests the use of FreeOTP+. The WebUI should be modified in the same way.

Issue History

Date Modified Username Field Change
2021-11-10 21:57 Christian Grothoff New Issue
2021-11-16 14:34 Christian Grothoff Note Added: 0018484
2021-11-16 14:34 Christian Grothoff Category authentication methods => anastasis-webui
2021-11-16 14:34 Christian Grothoff Assigned To => sebasjm
2021-11-16 14:34 Christian Grothoff Status new => assigned