2FA/MFA for Adguard Home #5480
Replies: 16 comments 18 replies
-
|
If you're hosting it locally, this shouldn't be a security improvement. (maybe, but useless) Perhaps there are other alternatives to protect your home network... |
Beta Was this translation helpful? Give feedback.
-
|
It seems a bit overkill? I don't know.. Come to think of it, I am in favor of adding web authentication(fido2+ctap2) based login. With that, I can login much more quickly without having to enter any username/passwords but just adding a form of 2FA(totps or u2f/fido key based) feels overkill. |
Beta Was this translation helpful? Give feedback.
-
|
oauth or 2fa/mfa is necessary, can be optional of course it should exist, tons of information in the dns queries and just username/password is not enough. especially for cloud setups |
Beta Was this translation helpful? Give feedback.
-
|
I agree. I am concerned about session ID riding/hijacking even with a strong TLS encryption + strong B-Crypt password hash. I think AdGuard team would have to integrate some kind of key generation mechanism that can generate a key we can add to Authy. I am not entirely sure other cloud services do this... |
Beta Was this translation helpful? Give feedback.
-
|
Any news on this? |
Beta Was this translation helpful? Give feedback.
-
|
Any word on when MFA or Webauth will be enabled for Adguard Home? I do host it at home, but it's accessible to the web for DoH, so I would like to get extra protection to my login prompt. |
Beta Was this translation helpful? Give feedback.
-
|
Same here, AGH is running on a vServer to serve the mobile devices I have. I'd like to have some security for the login page ... |
Beta Was this translation helpful? Give feedback.
-
|
anything which helps in integrating it with authentik would be helpful. so +1 Thanks! |
Beta Was this translation helpful? Give feedback.
-
|
+1 |
Beta Was this translation helpful? Give feedback.
-
|
+1 |
Beta Was this translation helpful? Give feedback.
-
|
+1 |
Beta Was this translation helpful? Give feedback.
-
|
2 years and still no news? Really need it as I'm hosting my instance on a public IP. |
Beta Was this translation helpful? Give feedback.
-
|
My solution... Web-UI behind nginx, and only allow access from my home... |
Beta Was this translation helpful? Give feedback.
-
|
Another workaround would be separate DOH and Web UI port, so we can only just expose the DOH port on the internet. |
Beta Was this translation helpful? Give feedback.
-
|
Yes, I tried with nginx and DOH didn't work on 443. I meant the devs maybe should add the feature to separate both ports. So you can have nginx plus some 2FA like Authelia working with the WEB UI (or just not expose that port on internet) and DOH working at the same time with a different port. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi Everyone,
How does everyone think about adding 2FA/MFA to Adguard Home?
It will drastically improve security. Besides that it will be a feature that other DNS application don't have.
Beta Was this translation helpful? Give feedback.
All reactions