Hacker News new | ask | show | jobs
by DavideNL 857 days ago
One thing i hate about mailbox.org is the way they implemented 2fa login [1]

They prepend a 4 digit PIN-code before the actual 2fa code - which of course is not compatible with password managers. It all feels so... clumsy.

Other than that, it seems like a great service (i'm testing the trial version.)

[1] https://kb.mailbox.org/en/private/account-article/how-to-use...

1 comments

Some time ago they changed web login to have the username/account to be the full mail adress. That was a little more to type and only a small decrease of comfort. They had a reason for that and it was communicated. Anyway, I shiftet to use mail clients because of that. I am lazy af. Later i added also TOTP as 2fa and noticed also the unusual approach for the web login. I think first part is your password, followed by the 2fa generated code. keepassDX does that fine btw., as you just have to paste the totp code after your password, wich is also selectable with the magikeyboard. But since i already do not use weblogin nowadays except to check on my payments, this is not a showstopper for me. Otherwise i would also discourage the penalty on comfort here. I also see the clear advantage, as that they care about security seriously even when this may scare away some customers. Maybe they adapt to FIDO passkey soon or speak openly against it when they see some downside to securety. My usecase is not affected by this anyway as the one-time setup of a mailclient is the lazy way to have this solved.