2FA Reset Protocol Needs a Correction

IMI

SOHO User
Joined
Jun 21, 2021
Messages
30
Reaction score
12
INFO: 3CX Version 20.0 Update 5 (Build 551 Release)


Hello 3cx team,

I have been working with 2FA and password resets to understand what is going in v20. I would like to suggest a better way to handle this...

Currently, in v20 when a User has 2FA selected and their password is reset it requires the User to reset the 2FA. That is a bad policy. Further, it allows a user to reset their password (from login page) without entering a 2FA another bad policy - especially when compounded.

Here is how it should be:
1) When a User wants to reset their password it must require the 2FA to complete. Meaning not at the request but when actually updating the new password. Currently, there is no ask of previous password (which is fine I guess with 2FA request in the least). Thereby, they can only reset the password only and NOT the 2FA.

2) When the admin (eg: System Owner) resets a User's password, it should ask to include resetting the 2FA (by default it is NOT selected). Typically, you do not want to reset the 2FA unless that is lost by the User, and the admin wants to reset both (but a choice known at the admin level).

While we are on this topic, I would like to recommend a related correction. Since now an extension is used to admin 3CX there should be an auto-log out setting (especially for admins). Either by a time-period or by the closing browser tab (or browser).

Lastly, on another related topic... I have read other posts regarding admins now forced to be an extension - while I agree that admin access should not be coupled with an extension User - it can be left this way, but I do not agree with the credential's format protocol. Basically, a User-extension + password is one secret key (a combination of 2 parts) and with an email being able to be short in some cases (eg: [email protected]) and the password minimum set to 10 characters - it does not make for a strong key (especially for an admin User). Therefore, to keep this User extension-based access maybe think about requiring 3 parts: User extension, email and PW - this would also allow for duplicate email addresses. I say duplicate emails since every business operates in its own fashion and some businesses may choose to have extensions share an email, or certain people may have multiple extensions with a single email. I know this may seem odd at first but for added security (especially for admin) it might be thought through further. You could even have a separate option at login for "advance logins" (such as a gear icon on the login page) – which requires the 3 parts (which is an option for all Users) but required for admin logins.

Thank you in advance for hearing this out. I truly hope updates are considered and made - specifically the 2FA.

P.S. I used a strong title to get some attention. I primarily work in security.
 
Last edited:

Latest Posts

Forum statistics

Threads
111,948
Messages
589,880
Members
164,841
Latest member
erre