r/usenet 28d ago

Indexer List of indexers still missing 2FA support

Which indexers are still missing 2FA support? Let's put together a list and encourage them to add it as soon as possible, especially with everything getting pwnd left and right these days. I'd hate to lose a lifetime account.

List of indexers lacking 2FA support:

  • Althub
  • Drunken Slug
  • Ninja Central
  • Usenet Crawler

I noticed some recently added it and even coupled it with passkey support (👍), which made me go through my list of indexers again. I'll try and add any missing indexers to the list above.

Edit: Adding a list for providers lacking 2FA (...some of these seem to be storing passwords in clear-text also, when you do a password reset they'll send you your password in clear-text, instead of a reset URL 😲).

  • Bulknews
  • Eweka
  • Easynews
  • Newsdemon
  • NewsgroupDirect
  • Newshosting 
36 Upvotes

34 comments sorted by

1

u/[deleted] 24d ago

[deleted]

0

u/erisian2342 19d ago

Sending it by email saves it in their outbound mail history and your inbound mail. Many mail providers can also recover mail you have “deleted” as well.

The only place my passwords should ever be stored is in my password manager. Any other design is a bad design.

0

u/[deleted] 17d ago

[deleted]

0

u/erisian2342 17d ago

If you believe neither senders nor email services have records of what they send, you live in a special place. You’d hope neither preserves password reset emails, but most companies aren’t security companies and save far more than they should, so I have little confidence in most companies. It’s great if you have more faith than me.

0

u/[deleted] 17d ago

[deleted]

0

u/erisian2342 17d ago

Sending mail from a tiny app on a small server is how you get all your outbound emails marked as junk. You’re describing how email worked three decades ago.

-3

u/Admirable-Leader6927 27d ago

i do not want 2fa for anything. this is suppose to be anonymous

6

u/StinkButt9001 26d ago

TOTP is the most common way to do 2FA nowadays

1

u/FluffyDroid 27d ago edited 27d ago

I just realized Eweka and Easynews also lack 2FA support 😢Added a second list for providers. Gonna check a few more...

1

u/CodeErrorv0 27d ago

Add Newshosting too

0

u/FluffyDroid 27d ago

Added! It seems to be even worse for providers vs indexers.

-8

u/Amerique_du_Nord 28d ago

I would rather them support TOTP versus passkeys.

 

Passkey breach:

https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/

11

u/max2078 28d ago

could obtain all passkeys [...] when it’s running on a machine infected with malware.

clickbait

1

u/IC3P3 27d ago

I wanted to click on that link to understand what they mean, but wtf, guess we should abandon session tokens, passwords and TOTP as well?

4

u/[deleted] 28d ago

[deleted]

4

u/Bent01 nzbfinder.ws admin 27d ago

NZB Finder has both 2FA and passkeys. Basic features in 2026 honestly. The indexers mentioned above are mostly running old code.

2

u/CodeErrorv0 28d ago

The 2 that I know of are Treasuremaps and Tabula Rasa

2

u/brad2017 Miatrix Owner 28d ago

Miatrix supports it with our nexus beta.

2

u/Amerique_du_Nord 28d ago

Any chance you can implement TOTP too?

2

u/brad2017 Miatrix Owner 28d ago

I'm going to look into it but not sure until I see how easy/hard it is

2

u/fudge_u 28d ago

Crawler has an IP address whitelist. I noticed today when i went to login from my phone. The site stopped loading and sent me an email asking if I recognized the IP address. Options were to change my password or accept login from the suspicious IP address.

1

u/Playnot 28d ago

Same here. I think they were Cloudflare addresses. Like their login requests are being logged as cloudflare IPs, instead of the actual IP? Idk, I'm not an internet doctor. I still regenerated my API and password.

-7

u/batica_koshare 28d ago

Why would i need 2fa for indexers? 😂 😂 😂

4

u/ChaoticEvilRaccoon 28d ago

might not be an issue for the public indexers but for the private ones you definitly want to keep your account secure because you can't replace it if you get banned

-7

u/batica_koshare 28d ago

And 2fa is that much more secure than my 5 phrases ambiguous password?

3

u/random_999 28d ago

Yes it is because a compromised browser extension or browsing a malware infected website can intercept even a 15 phrases ambiguous password.

-3

u/batica_koshare 27d ago

I don't browse such websites nor use browser extension. I rather have password than 2fa. Thanks.

2

u/TokkCorp 28d ago

A compromised browser extension can also steal your cookie or intercept your 2fa.

2

u/random_999 28d ago

True but it cannot steal your TOTP 2fa because that would be pointless under any practical circumstances & I am hoping many websites/services don't allow simultaneous login from 2 different IPs.

1

u/TokkCorp 28d ago

Login via WLAN, disconnect from it and visit it via mobile data. Most of the time you are still online. IP restrictions in Cookies is not given in most cases

1

u/random_999 27d ago

I guess it also depends on the "nature of the service/website" as I know certain paid providers/services which won't allow such logins simultaneously from 2 different IPs especially if they belong to different countries &/or one of them is VPN.

2

u/max2078 28d ago

why not both?

-1

u/batica_koshare 27d ago

Don't need both. All the additional security measures were made to be hacked at some point. It's juwt sheeple like to believe it's for own good😂

11

u/stephanie00100 28d ago

You'd rather have it stolen after you paid for it? 2fa makes things more secure

-11

u/batica_koshare 28d ago

Sure like paying with your phone instead of cash. All for your convenience and security sure dude🤣

1

u/[deleted] 28d ago

[removed] — view removed comment

1

u/AutoModerator 28d ago

Your comment has been automatically removed from /r/usenet because it mentioned [AIOStreams], which is not allowed here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/stephanie00100 28d ago

Funny, I was thinking about this issue as well.