MFA for your production infrastructure running on ngrok
Blog post from Ngrok
The Security and Identity (SI) team at ngrok recently introduced Multi-Factor Authentication (MFA) to enhance the security of ngrok accounts, particularly for production environments. By exploring the technical and security challenges, the team implemented MFA as an optional feature to add an additional layer of security beyond passwords, using Time-based One-Time Passwords (TOTPs). This involved developing a service to manage TOTP devices and leveraging existing internal libraries for secure storage. The introduction of MFA also required addressing the complexities of a multi-tenant infrastructure, where accounts can represent organizations rather than individual users. To mitigate potential user friction, MFA was made opt-in, and a support-based recovery method was chosen over SMS-based alternatives due to its stronger security posture against risks like SIM hijacking. The project highlights ngrok's commitment to safeguarding production infrastructure while balancing security with user experience.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.