Before today, mailbox.org’s 2FA mechanism was unorthodox. In the login screen, you typed in the TOTP in the password field and then added a 4 digit static pin at the end. This got people confused, as it’s different than the usual login+password then TOTP. Now it’s just like that.
There’s also other goodies, like separate passwords for IMAP and SMTP, WebDAV, CardDAV/CalDAV (one password for both), Exchange Sync. Before today, you’d be using your main mailbox.org password for all of the above. Looks like IMAP access is not even possible without creating a separate password https://kb.mailbox.org/en/private/account-article/how-to-use-two-factor-authentication-2fa/
There doesn’t seem to be support for the YubiKey TOTP anymore. No passkeys or hardware webauthn either for now.
mailbox.org is based on OpenXchange.
Well fucking finally. I have no idea what took them so long.
I think they resell https://www.open-xchange.com/ so they were dependent on them accomodating Keycloak (identity solution used by mailbox)
I’m not sure I quite understand how this would make them unable to support normal 2fa until now.
Keycloak is one of the most configurable and flexible auth solutions, and there is no way it didn’t support otp based 2fa until recently.