Retrieving the second factor when using the external password tool

Retrieving the second factor when using the external password tool

0 vote

avatar

After the trial period of Remote Desktop Manager, our CIO is not completely convinced that the security of the connected password tools is guaranteed. 

The current situation is that after Remote Desktop Manager is started, the second factor required for this (TOTP) is requested and entered when the external password tool is called up for the first time. This is followed by permanent authentication via the API. Access could potentially take place at any time without the user's action or knowledge. 

Does Devolutions see a possibility to limit access to the API for the duration/validity of the TOTP, i.e. max. 30 seconds?

In other words, if a new request is made via the external password tool, the second factor is requested again and must be entered by the user.

All Comments (8)

avatar

Hello,

Could you tell us what password integration you're using in RDM? They're not all implemented in the same way and some of them already have configurations to act as you describe. It's possible we don't yet support this for certain integrations.

Regards,

Hubert Mireault

avatar

Hello Hubert,

Thank you for your quick response.

In our case, we use the password tools:
LastPass
Pleasant Password

Regards,
itd:

avatar

Hello,

For LastPass, you could check in File > Settings > Types > Credential management > LastPass, and try out the different settings there:


Let me know if one of the modes works for you or not. At the moment we don't have anything for Pleasant Password I believe, so if this works for you then we could add something similar for Pleasant Password.

Regards,

Hubert Mireault

eff200e6-33b8-471b-906e-a087c5fdb87b.png

avatar

Hello Hubert,

Some of our users have checked the settings for LastPass and the observed behavior goes in the direction we envision for Pleasant Password.
Would it be conceivable to define the duration of trust to the device, e.g. 30 seconds, 5 minutes or an hour after TOTP has to be re-entered?

Regards,
itd:

avatar

Hello,

Thank you for the feedback. Yes, that should be possible. I will open a ticket.

Regards,

Hubert Mireault

avatar

Also, would you need this just for Pleasant Password, or also LastPass?

Hubert Mireault

avatar

Hello,

For our current use case is desirable for Lastpass and Pleasant Password.
However, this could potentially be interesting for all password tools with TOTP, right?

Thank you very much for your efforts regarding an implementation.

Regards,
itd:

avatar

Hello,

Thank you for the confirmation, I will open a ticket with this information.
You're correct, it's something other password manager integrations could have, but as we have other priorities as well, it will be quicker for us to focus on these two specific password managers since they are the ones you and your team are using.

Regards,

Hubert Mireault