It’s Cybersecurity Awareness Month! Join our interactive training session, or learn about security and AI from 1Password experts.
Forum Discussion
zcutlip
4 years agoDedicated Contributor
Accounts where TOTP code should be appended (or prepended) to the password
This may be a bit of a corner case request, but here goes...
There are some websites (looking at Etrade.com!) where the 2FA TOTP code needs to be silently appended to the password in the same fiel...
Former Member
3 years agoThe sketch by melorama above looks very usable to me... nice job. As a 1password gui user, I would have no problem with that if the need arose. I wish it was in the app :)
I'm not so sure this is a corner case. For example, to enable TOTP on some of the most commonly used firewall web GUIs (eg: OPNSense), you concatenate the TOTP and the password for any authentication attempt. If I want to authenticate with the OpenVPN VPN on one of our firewalls, it also takes this structure. Identity platforms like FreeIPA do the same thing. I think you see it even more as an admin user, though some consumer / regular-human sites are doing it too.
I basically evangelize 1password, btw. Getting people to adopt good security hygiene is really really hard if they don't have a way to manage longer, more complex authentication processes. I'm probably preaching to the choir here :) Anyway, I can tell you that the two companies in our corporate group are using concatenated [TOTP][Password] to authenticate on the firewall gui and VPN at least. An MSP we work with has the same setup internally because we set it up for them. Some of their client sites either have or will-have the same. And a corporate client of ours with ~5,000 employees may have the same thing for some users (admins and managers mostly) in the future.
So... I also think this would be a good feature. It's not impossible to log into the concatenated-password things without it (especially if you're technical enough to script something yourself), but it would be convenient if there was a way to handle it. Hope you all will consider it, and thanks for making a great product. :)