- Docs
- Security
- Two-Factor Authentication (2FA)
- Supported 2FA Methods
Supported 2FA Methods
Files.com offers several 2FA methods from which your users can select for their 2FA protection.
Users may add multiple 2FA method to their accounts and have multiple active simultaneously.
Yubikey WebAuthn (Preferred)
This is the 2FA method recommended by Files.com for the greatest security. This method does not support FTP/SFTP/DAV connections. Learn more about Yubikeys.
WebAuthn is compatible with the previous FIDO U2F standard.
Yubikey Native
This method uses the OTP (One-time Password) feature of your Yubikey. This method supports FTP/SFTP/DAV connections. Blue Yubikeys are not supported.
Authenticator Apps That Use TOTP (Time-Based One-Time Password)
These include apps such as Google Authenticator, Duo, and Authy. Authenticator apps are typically installed and used on mobile devices. This method supports FTP/SFTP/DAV connections.
SMS (Text Messages)
This method is considered less secure than the others but still offers greater security than password alone. This method supports FTP/SFTP/DAV connections.
Hardware Key (WebAuthn)
This includes non-Yubikey hardware keys that support WebAuthn. This method does not support FTP/SFTP/DAV connections.
Email Verification
With this method, the user enters a code that Files.com sends by email each time they attempt to log in.
Each code is valid for 5 minutes and can only be used once.
After a code is used or expires, it becomes invalid. At the next login attempt, Files.com automatically sends a new code by email.
A user can log in with an unused code within its 5 minute validity window. After five minutes, the code expires.
All login attempts that are made within the 5 minute duration of an unused code will expect that code. Once used, the code cannot be used again. After 5 minutes, the next login attempt will cause a new code to be emailed to the user.
Like SMS, email-based 2FA is less secure than other methods, but still safer than using a password alone.
This method does not support FTP/SFTP/DAV connections.
Use email verification only if you cannot use other 2FA methods.