Two Factor Authentication for Hybrid and Private Cloud
blog.aerofs.com
blog.aerofs.com
For more info check it out here: https://www.tinfoilsecurity.com/blog/two-factor-authenticati...
Also, for a list of services that provide 2FA, check out http://twofactorauth.org. It's a pretty extensive list, and hopefully more companies start adding 2FA.
I'm looking to emulate them on this (ie shamelessly copy) whenever I have an auth system for a similarly complex multi user system to spec or implement.
I also think there are other forms of 2fa besides totp/hotp which are worth adding, and the general amazon strategy of "multiple levels of logged in stet per user" for various actions on their retail shopping site has much broader applicability too.
In general I think Amazon has done an exceptional job here across multiple products.
I suspect there's probably a career (for a while) in being an IAM/VPC/etc. configuration specialist.
On the other hand and with the latest Synology private cloud hacks, I am not sure if 2FA makes that much of a difference for private cloud servers. 2FA cannot be used for all logins and the solution therefore are usually additional passwords with limited user rights, however, if there is a security issue, such limited user rights are usually sufficient …
Your mileage might vary, of course, but I agree more and more that hosting your own data is probably not the right solution for most users (and maybe even for most HN folks).
Recommended reading: http://tante.cc/2013/05/20/host-your-own-is-cynical/