this post was submitted on 09 Apr 2025
131 points (99.2% liked)

Privacy Guides

18804 readers
5 users here now

In the digital age, protecting your personal information might seem like an impossible task. We’re here to help.

This is a community for sharing news about privacy, posting information about cool privacy tools and services, and getting advice about your privacy journey.


You can subscribe to this community from any Kbin or Lemmy instance:

Learn more...


Check out our website at privacyguides.org before asking your questions here. We've tried answering the common questions and recommendations there!

Want to get involved? The website is open-source on GitHub, and your help would be appreciated!


This community is the "official" Privacy Guides community on Lemmy, which can be verified here. Other "Privacy Guides" communities on other Lemmy servers are not moderated by this team or associated with the website.


Moderation Rules:

  1. We prefer posting about open-source software whenever possible.
  2. This is not the place for self-promotion if you are not listed on privacyguides.org. If you want to be listed, make a suggestion on our forum first.
  3. No soliciting engagement: Don't ask for upvotes, follows, etc.
  4. Surveys, Fundraising, and Petitions must be pre-approved by the mod team.
  5. Be civil, no violence, hate speech. Assume people here are posting in good faith.
  6. Don't repost topics which have already been covered here.
  7. News posts must be related to privacy and security, and your post title must match the article headline exactly. Do not editorialize titles, you can post your opinions in the post body or a comment.
  8. Memes/images/video posts that could be summarized as text explanations should not be posted. Infographics and conference talks from reputable sources are acceptable.
  9. No help vampires: This is not a tech support subreddit, don't abuse our community's willingness to help. Questions related to privacy, security or privacy/security related software and their configurations are acceptable.
  10. No misinformation: Extraordinary claims must be matched with evidence.
  11. Do not post about VPNs or cryptocurrencies which are not listed on privacyguides.org. See Rule 2 for info on adding new recommendations to the website.
  12. General guides or software lists are not permitted. Original sources and research about specific topics are allowed as long as they are high quality and factual. We are not providing a platform for poorly-vetted, out-of-date or conflicting recommendations.

Additional Resources:

founded 2 years ago
MODERATORS
 

Before today, mailbox.org's 2FA mechanism was unorthodox. In the login screen, you typed in the TOTP in the password field and then added a 4 digit static pin at the end. This got people confused, as it's different than the usual login+password then TOTP. Now it's just like that.

There's also other goodies, like separate passwords for IMAP and SMTP, WebDAV, CardDAV/CalDAV (one password for both), Exchange Sync. Before today, you'd be using your main mailbox.org password for all of the above. Looks like IMAP access is not even possible without creating a separate password https://kb.mailbox.org/en/private/account-article/how-to-use-two-factor-authentication-2fa/

There doesn't seem to be support for the YubiKey TOTP anymore. No passkeys or hardware webauthn either for now.

mailbox.org is based on OpenXchange.

top 11 comments
sorted by: hot top controversial new old
[–] LWD@lemm.ee 14 points 6 days ago (1 children)

Okay, so for those of us using third party apps like Thunderbird, everything is done using app specific passwords, which is great

The new feature for Email App Passwords for external email programmes

But if this is a new feature, how did third party apps work before? Could people just not use them if they enabled 2FA?

[–] GreatBlue@infosec.pub 6 points 6 days ago (2 children)

Basically, yes, they couldn't use them. The old 2FA had a really weird implementation...

[–] 20nat@feddit.it 3 points 6 days ago

This is just wrong, you used the main account password instead of an app password

[–] Rogue1633@discuss.tchncs.de 2 points 6 days ago

You could use third party clients with 2FA enabled in the past (at least I could). I think I used my normal password for the clients, so no real 2FA on that side, but that's no different from the new app specific passwords. IMAP doesn't allow 2FA so every mail provider allowing third party clients essentially has a weak point with no 2FA there.

[–] Creat@discuss.tchncs.de 9 points 6 days ago (1 children)

Well fucking finally. I have no idea what took them so long.

[–] BenchpressMuyDebil@szmer.info 1 points 6 days ago (1 children)

I think they resell https://www.open-xchange.com/ so they were dependent on them accomodating Keycloak (identity solution used by mailbox)

[–] Creat@discuss.tchncs.de 2 points 6 days ago

I'm not sure I quite understand how this would make them unable to support normal 2fa until now.

Keycloak is one of the most configurable and flexible auth solutions, and there is no way it didn't support otp based 2fa until recently.

[–] Cadende@hexbear.net 8 points 6 days ago* (last edited 6 days ago)

Bit of trivia but I think I know why the 4 digit pin thing existed! It's an out-of-the-box feature on freeRADIUS, I ran across it in a pfsense environment in the past. I thought it was neat (esp. in the absence of passwords, this was primary auth with public keys and then 2fa on top) but ultimately too convoluted for most users

[–] RiQuY@lemm.ee 1 points 6 days ago (1 children)

How can I enable it? I received the mail but my login is still using pin+otp and in the settings there is no option to migrate to normal F2A, only the old pin+opt thing.

[–] BenchpressMuyDebil@szmer.info 1 points 5 days ago

Read the The rollout of Login 2.0 for our customers se tion in the linked post

[–] allthat@sh.itjust.works -1 points 4 days ago

Maybe most people using Mailbox know about this but I'll still mention that using Mailbox kinda requires having your own domain.

Reason is the same as Posteo (unless Posteo changed something lately) : mail adresses will get recycled after some time when you stop using the service and close your account.

Most other providers blacklist adresses so they can't get reused when an account gets deleted.