Thunderbird 60.0 release
thunderbird.net
Thunderbird 60.0 release
1–10 of 57 posts
Re: Thunderbird 60.0 release
#2Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.
Re: Thunderbird 60.0 release
#3Re: Thunderbird 60.0 release
#4Re: Thunderbird 60.0 release
#5Re: Thunderbird 60.0 release
#6> FIDO U2F support Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.
Re: Thunderbird 60.0 release
#7> FIDO U2F support Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.
Re: Thunderbird 60.0 release
#8[1] = https://www.thunderbird.net/en-US/ [2] = https://support.mozilla.org/en-US/kb/profiles-where-thunderb...
Re: Thunderbird 60.0 release
#9> FIDO U2F support Sweet, although IIRC several of the email providers with 2FA (Gmail and Outlook come to mind) have the option of providing app-passwords instead, which bypass the need for a 2FA token.
Just so you know, an app password downgrades the security of your 2FA+Password pairing, and I never use app paswords because of that. If it was somehow possible to intercept the password used in the IMAP handshake, then that means access to your inbox without 2FA. This is why I am a huge fan of web-based clients and not things like Thunderbird.
For some reason I also thought there was some way of tying the app's identity to the password, such that if an app other than Thunderbird tried to use my Gmail Thunderbird-app password, Gmail would block it. But I'm probably wrong on that point.
Would be a great enhancement, if not.