To use the webclient, you need to enter a unique email address for the extension. This will be a requirement going forward so you need to update any installs. In future versions, if you dont specify an email, then the webclient will be disabled. So lets say for a hotel room, of course dont specify an email and web client will be disabled but hotel room phone will work.
It makes a lot of sense. I don't know if I'm the only one to have noticed but .. it's more and more common for people to get hacked via the WebClient (weak password).
I've seen SIP and VoiceMail hacks for a long time.
But it's only been a few years since I've seen WebClient login hacks (and more and more frequent)
What I'm getting at is that I find it makes a lot of sense that without email addresses, WebClient will be disabled. It It limits the risk of piracy due to user negligence.
Thank you for this logic!
On the same line, to offer additional protection,
Is there any plan to be able to offer admin to force user to use google-oauth2 or SSO ?
or
Do you have other projects related to WebClient security ?
Previously, passwords were not hashed, although many were saying it was a security flaw
For us, this allowed us to do audits passwords ;
and notify the administrator that users A B C D had to change their passwords, it is not safe to put their first name followed by their extension number as a password
The choice (to the administrator) to force the users to use SSO/Google-Oauth2, allows easy connection (one less password to remember) and 2-factor authentication imposed via Microsoft or Google.
Or maybe you have other strategies planned for WebClient security ?
I know it is possible to limit access to an IP address range but it is not very practical for people who work from home, residential internet connections have no static IP, except in rare cases.
Thx