Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TOTP not mendetory if browser plugin uses app passcode #276

Open
dj4oC opened this issue Nov 3, 2022 · 0 comments
Open

TOTP not mendetory if browser plugin uses app passcode #276

dj4oC opened this issue Nov 3, 2022 · 0 comments

Comments

@dj4oC
Copy link

dj4oC commented Nov 3, 2022

-- transferd --
As a user I use TOTP on my local oC 10 installation.

I did follow https://owncloud.com/news/how-to-sync-passwords-with-buttercup/ to store my passwords in a buttercup database.

Additional I am using chrome browser extension of buttercup (https://chrome.google.com/webstore/detail/buttercup/heflipieckodmcppbnembejjmabajjjj?hl=en-GB)

To set up buttercup browser extension I need to create an app passcode to bypass by TOTP.

After restarting my computer, buttercup chrome extension opens with a tab asking for buttercup database master password to open buttercup database.

Next step: open a tab and go to oC web client. Unfortunately I will not been asked for my password and totp-token. Since this does not happen with deactivated browser extension I assume access is grated using buttercap app passcode. IMHO this is quite dangerous since TOTP is passed by.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant