Retrieving the second factor when using the external password tool
0 vote
After the trial period of Remote Desktop Manager, our CIO is not completely convinced that the security of the connected password tools is guaranteed.
The current situation is that after Remote Desktop Manager is started, the second factor required for this (TOTP) is requested and entered when the external password tool is called up for the first time. This is followed by permanent authentication via the API. Access could potentially take place at any time without the user's action or knowledge.
Does Devolutions see a possibility to limit access to the API for the duration/validity of the TOTP, i.e. max. 30 seconds?
In other words, if a new request is made via the external password tool, the second factor is requested again and must be entered by the user.
Hello,
Could you tell us what password integration you're using in RDM? They're not all implemented in the same way and some of them already have configurations to act as you describe. It's possible we don't yet support this for certain integrations.
Regards,
Hubert Mireault
Hello Hubert,
Thank you for your quick response.
In our case, we use the password tools:
LastPass
Pleasant Password
Regards,
itd:
Hello,
For LastPass, you could check in File > Settings > Types > Credential management > LastPass, and try out the different settings there:
Let me know if one of the modes works for you or not. At the moment we don't have anything for Pleasant Password I believe, so if this works for you then we could add something similar for Pleasant Password.
Regards,
Hubert Mireault
eff200e6-33b8-471b-906e-a087c5fdb87b.png
Hello Hubert,
Some of our users have checked the settings for LastPass and the observed behavior goes in the direction we envision for Pleasant Password.
Would it be conceivable to define the duration of trust to the device, e.g. 30 seconds, 5 minutes or an hour after TOTP has to be re-entered?
Regards,
itd:
Hello,
Thank you for the feedback. Yes, that should be possible. I will open a ticket.
Regards,
Hubert Mireault
Also, would you need this just for Pleasant Password, or also LastPass?
Hubert Mireault
Hello,
For our current use case is desirable for Lastpass and Pleasant Password.
However, this could potentially be interesting for all password tools with TOTP, right?
Thank you very much for your efforts regarding an implementation.
Regards,
itd:
Hello,
Thank you for the confirmation, I will open a ticket with this information.
You're correct, it's something other password manager integrations could have, but as we have other priorities as well, it will be quicker for us to focus on these two specific password managers since they are the ones you and your team are using.
Regards,
Hubert Mireault