F18: admin account has email-2FA only (no TOTP) #3
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: High
Status: Open
Admin account 2FA = email only. Email auth has weak link if SMTP provider compromised, mailbox compromised, or DNS hijacked. TOTP would give phishing-resistance.
Fix: Enroll TOTP on admin account in Authentik. Keep email-2FA as fallback (or recovery code).
Verification:
s8n-ruadmin login shows TOTP prompt before email.Source:
security/nullstone-server/2026-05-02.md§F18.