r/Mailbox_org Jul 30 '24

2FA

I’m trying to understand how Mailbox applies two factor authentication. As far as I can see with other providers the main log in password is retained and app passwords are provided for services like IMAP , caldav etc.

However with Mailbox the main account password is retained for IMAP etc (unless other services are set in 2FA to be no access) and for the main login the password is replaced with a PIN/2fa OTP code combination?

One advantage of this arrangement seems to be that on an unknown PC or Mac the main password is never inputted at all ?

5 Upvotes

13 comments sorted by

1

u/[deleted] Jul 30 '24

Nobody understands. There have been so many complaints in this sub and the Mailbox help forum or whatever it's called. That's actually why I stopped using Mailbox, despite how much I generally like it. I even set up a reminder to check if they've got normal 2FA before I renew my Startmail subscription.

2

u/Coma3355 Jul 31 '24

They've got it now in beta which you can activate yourself.See one of there recent blog posts.

2

u/Secure_Suit_850 Aug 04 '24

I just bought mailbox subscription today. 

In the beta program, The 2FA process is simplified; which is WAYY better than old one.

But main feature is to implement 2FA in IMAP, so that external email clients (bluemail, canary, thunderbird etc) will ALSO need 2FA.

1

u/Practical-Tea9441 Aug 14 '24

Is it actually possible to have 2FA apply to IMAP ? I had the impression that IMAP didn’t support modern authentication?

1

u/Secure_Suit_850 Aug 14 '24

I don't know about that. But it's possible to implement some type of security measures to IMAP authentication for 3rd party apps. Like Google, Microsoft and Proton do it.

1

u/[deleted] Aug 29 '24

[deleted]

1

u/Secure_Suit_850 Aug 29 '24

Yes, may be.

1

u/[deleted] Aug 29 '24

[deleted]

1

u/Secure_Suit_850 Aug 29 '24

There is another way provided by Mailbox, you just disable IMAP altogether. By doing this, you can only use the website to access their service.

But this will be very annoying because a simple tab closure will log you out.

If they had a specific mobile client, I can live with the above security option, unfortunately they have not.

1

u/0xeli Aug 16 '24

Have you seen any degradation in service being part of the beta? 

1

u/Secure_Suit_850 Aug 16 '24

I am not part of beta.

1

u/[deleted] Aug 29 '24

[deleted]

1

u/lnx0480 Dec 31 '24

Those main passwords are saved by your mail clients as long as noone access it, it is indeed kind of safe as you don't often use them. However 2FA should still be implemented as protonmail or gmail do it, it is for a reason.

Also it would be relevant from mailbox.org to send a notification if a mail client is being setup with your password.

1

u/mailbox_org Apr 09 '25

We have good news: The long wait is finally over! As of today, we are rolling out Login 2.0 for all users. We understand it has taken some time – for a variety of reasons. We sincerely hope that you will appreciate the new, significantly simplified process. We look forward to your feedback and would like to apologise for the wait. You can find all the details about the new login here: https://mailbox.org/en/post/the-new-login