<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[#Immich does not have 2FA and the devs made clear, it&#x27;s not coming.]]></title><description><![CDATA[<p><a href="https://pandas.social/tags/Immich" rel="tag">#<span>Immich</span></a> does not have 2FA and the devs made clear, it's not coming.</p><p>The <a href="https://github.com/immich-app/immich/discussions/8175#discussioncomment-11498833" rel="nofollow noopener">reasoning against</a> <a href="https://pandas.social/tags/2FA" rel="tag">#<span>2FA</span></a> is pretty weak.</p><p>This thread is <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/2705.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--white_check_mark" style="height:23px;width:auto;vertical-align:middle" title="✅" alt="✅" />️  (for me). Points were made.</p><p><a href="https://pandas.social/tags/infosec" rel="tag">#<span>infosec</span></a> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/topic/6e9c3f88-e2a6-4712-9157-0e7d374a1639/immich-does-not-have-2fa-and-the-devs-made-clear-it-s-not-coming.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 11 Sep 2026 13:53:00 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/6e9c3f88-e2a6-4712-9157-0e7d374a1639.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 20:21:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 16:11:44 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@silmaril" rel="nofollow noopener">@<span>silmaril</span></a></span> <span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> Very nice - thanks a lot!</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117241957846740576</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117241957846740576</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 16:11:44 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 16:10:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span><br />I think the immich fork Noodle improves this.</p><p><a href="https://github.com/open-noodle/gallery" rel="nofollow noopener"><span>https://</span><span>github.com/open-noodle/gallery</span><span></span></a></p><p><span><a href="https://mastodon.social/@preya">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://chaos.social/users/silmaril/statuses/117241951488520840</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://chaos.social/users/silmaril/statuses/117241951488520840</guid><dc:creator><![CDATA[silmaril@chaos.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 16:10:07 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 09:34:22 GMT]]></title><description><![CDATA[<p><span><a href="https://polymaths.social/@thedoctor" rel="nofollow noopener">@<span>thedoctor</span></a></span> <span><a href="https://sueden.social/@vb" rel="nofollow noopener">@<span>vb</span></a></span> <span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> <span><a href="https://odd.blog/author/donncha/" rel="nofollow noopener">@<span>donncha</span></a></span> Tried it as well. Didn't like it either.</p><p>Immich is by far the most promising/nice looking software for this in my opinion. But (so far) it still lacks several features that unfortunately prevent me from switching to it completely.</p><p>We need user groups - otherwise sharing albums etc is a nightmare once you have more than a handful of people using it.</p><p>And shared albums should offer the same functionality as "normal" ones. I don't want to have duplicates or miss out images that show a particular person because Immich can't run duplicate/face detection in shared albums.</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117240395341982992</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117240395341982992</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 09:34:22 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 09:28:54 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de" rel="nofollow noreferrer noopener">@<span>abulling</span></a></span> <span><a href="https://sueden.social/@vb" rel="nofollow noreferrer noopener">@<span>vb</span></a></span> <span><a href="https://mastodon.social/@preya" rel="nofollow noreferrer noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noreferrer noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noreferrer noopener">@<span>homelab</span></a></span> <span><a href="https://odd.blog/author/donncha/" rel="nofollow noreferrer noopener">@<span>donncha</span></a></span> There is also Photoprism, but I have no experience with it. Perhaps it might be worth looking into.</p>]]></description><link>https://forum.fedi.dk/post/https://polymaths.social/users/thedoctor/statuses/01M22QZBDFJGV6RAVZ56Z9PTSG</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://polymaths.social/users/thedoctor/statuses/01M22QZBDFJGV6RAVZ56Z9PTSG</guid><dc:creator><![CDATA[thedoctor@polymaths.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 09:28:54 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 09:14:47 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span> <span><a href="https://sueden.social/@vb">@<span>vb</span></a></span> <span><a href="https://mastodon.social/@preya">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="https://odd.blog/author/donncha/">@<span>donncha</span></a></span> Just in case you want to track this, note that this seems to be the #1 item in the Immich roadmap (not that I think order is that important): <a href="https://immich.app/roadmap" rel="nofollow noopener"><span>https://</span><span>immich.app/roadmap</span><span></span></a><br />And is being tracked here: <a href="https://github.com/immich-app/immich/issues/12614" rel="nofollow noopener"><span>https://</span><span>github.com/immich-app/immich/i</span><span>ssues/12614</span></a></p><p>I haven't decided yet on Immich vs Ente Photos here.</p>]]></description><link>https://forum.fedi.dk/post/https://social.treehouse.systems/users/Aissen/statuses/117240318364854739</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.treehouse.systems/users/Aissen/statuses/117240318364854739</guid><dc:creator><![CDATA[aissen@social.treehouse.systems]]></dc:creator><pubDate>Wed, 09 Sep 2026 09:14:47 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 08:53:18 GMT]]></title><description><![CDATA[<p><span><a href="https://sueden.social/@vb" rel="nofollow noopener">@<span>vb</span></a></span> <span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> <span><a href="https://odd.blog/author/donncha/" rel="nofollow noopener">@<span>donncha</span></a></span> Same here. This (and the missing user groups) is the reason I don't use Immich as our image archive solution.</p><p>I briefly tried Ente but it felt/looked too limited in terms of functionality.</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117240233869559028</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117240233869559028</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 08:53:18 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 08:46:06 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span> <span><a href="/user/preya%40mastodon.social">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> <span><a href="https://odd.blog/author/donncha/">@<span>donncha</span></a></span> This is the reason I still use Apple Fotos with shared library. <a href="https://sueden.social/tags/immich" rel="tag">#<span>immich</span></a> is only the backup solution. I will check <a href="https://sueden.social/tags/Ente" rel="tag">#<span>Ente</span></a> and <a href="https://sueden.social/tags/zeitkapsl" rel="tag">#<span>zeitkapsl</span></a> whether they have a better solution. But I still like <a href="https://sueden.social/tags/immich" rel="tag">#<span>immich</span></a>.</p>]]></description><link>https://forum.fedi.dk/post/https://sueden.social/ap/users/116466000055299971/statuses/117240205526291277</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://sueden.social/ap/users/116466000055299971/statuses/117240205526291277</guid><dc:creator><![CDATA[vb@sueden.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 08:46:06 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 08:00:57 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> I know that a lot of sharing things are currently being worked on. So I'd hope that some of these things will be fixed in the upcoming releases.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117240028030432239</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117240028030432239</guid><dc:creator><![CDATA[preya@mastodon.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 08:00:57 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 07:03:17 GMT]]></title><description><![CDATA[<p><span><a href="https://social.kobelnet.be/@tandemblog">@<span>tandemblog</span></a></span> <span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> <br />Very true. Not everyone likes to have so many things. I have 40+ TOTPs myself.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239801300574722</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239801300574722</guid><dc:creator><![CDATA[fbinin@mastodon.fbin.in]]></dc:creator><pubDate>Wed, 09 Sep 2026 07:03:17 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 07:01:51 GMT]]></title><description><![CDATA[<p><span><a href="https://social.kobelnet.be/@tandemblog">@<span>tandemblog</span></a></span> <span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> <br />1 at a time tbvh.<br />I mean TOTP first, so that at least the basic need is implemented. Rest can come at a later stage if possible. The more ask gets chipped, the more the word NO gets chanted by the devs.</p><p>I do understand it all can be done. It also begs the question of a maintainer. Even smaller changes or updates at times may break something. One reason why I said, just implement the basis TOTP at least.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239795636337306</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239795636337306</guid><dc:creator><![CDATA[fbinin@mastodon.fbin.in]]></dc:creator><pubDate>Wed, 09 Sep 2026 07:01:51 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 07:01:02 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> Ah, right. Now I remember what the issue was (it's been a long time since I last looked into this but my browser history showed what I had been looking into):</p><p><a href="https://odd.blog/2026/01/16/creating-a-shared-photo-library-in-immich/" rel="nofollow noopener"><span>https://</span><span>odd.blog/2026/01/16/creating-a</span><span>-shared-photo-library-in-immich/</span></a></p><p>"While Immich has shared albums, they don’t quite solve this problem. The photos don’t appear in search and aren’t processed for face recognition or analysis."</p><p>The article proposes a solution based on an external library. That's why I still remembered this "solution"...</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239792402919466</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239792402919466</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 07:01:02 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:51:30 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> Hm, I wonder as well how I missed this. I had even asked in a forum and people referred to the "external library" function instead. <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f926.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--face_palm" style="height:23px;width:auto;vertical-align:middle" title="🤦" alt="🤦" />‍<img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️ </p><p>Thanks a million!</p><p>Do they also support user groups by now (did I miss that as well)?</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239754916569986</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239754916569986</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:51:30 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:49:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> This has been a feature for ages. Not sure why you think that's missing. It's even described here in the docs: <a href="https://docs.immich.app/features/sharing/" rel="nofollow noopener"><span>https://</span><span>docs.immich.app/features/shari</span><span>ng/</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239745269284033</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239745269284033</guid><dc:creator><![CDATA[preya@mastodon.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:49:02 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:46:39 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> I create an album, add some pictures, and can then share it with other users on the same instance. I can set whether they can only view or also edit the album. If so, they can also add pictures etc</p><p>I know that there is an "external library" but this is for a different purpose and doesn't provide the functionality of a shared album.</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239735846803224</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239735846803224</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:46:39 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:45:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/abulling%40fedifreu.de">@<span>abulling</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> What's your specific definition of a "shared folder" in Immich?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239732747719854</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239732747719854</guid><dc:creator><![CDATA[preya@mastodon.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:45:51 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:44:33 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@preya">@<span>preya</span></a></span> </p><p>Exactly! Either remove user+pass entirely and rely solely on oauth/oidc or add a means of 2FA for user+pass.</p><p>user+pass is incomplete without 2FA in it's current state.</p><p><span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://pandas.social/users/panda/statuses/117239727604583225</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://pandas.social/users/panda/statuses/117239727604583225</guid><dc:creator><![CDATA[panda@pandas.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:44:33 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:33:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="https://social.kobelnet.be/@tandemblog">@<span>tandemblog</span></a></span> <span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> Exactly, that‘s why i‘m rolling out pocket-id for all my personal services. <a href="https://pocket-id.org" rel="nofollow noopener"><span>https://</span><span>pocket-id.org</span><span></span></a> <a href="https://hachyderm.io/tags/pocketid" rel="tag">#<span>pocketid</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://hachyderm.io/users/goebelmeier/statuses/117239683443190714</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://hachyderm.io/users/goebelmeier/statuses/117239683443190714</guid><dc:creator><![CDATA[goebelmeier@hachyderm.io]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:33:19 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:26:43 GMT]]></title><description><![CDATA[<p><span><a href="https://social.kobelnet.be/@tandemblog" rel="nofollow noopener">@<span>tandemblog</span></a></span> </p><blockquote><p>I initially implemented multiple login methods in my applications by using existing libraries</p></blockquote><p>I'd really just need one TOTP slot. No WebAuthn, Passkeys or whatever. Just a single means of 2FA.</p><p>OAuth / OIDC is great. 100%. I just think it's not a good idea to provide a login with username + password, but then not provide TOTP.</p><p>Just remove user+pass auth entirely and rely solely on OAuth/OIDC, if user+pass cannot be secured with TOTP / what ever.</p><p><span><a href="/user/hrafnagud%40runespaces.com" rel="nofollow noopener">@<span>hrafnagud</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://pandas.social/users/panda/statuses/117239657494225400</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://pandas.social/users/panda/statuses/117239657494225400</guid><dc:creator><![CDATA[panda@pandas.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:26:43 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:18:09 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@preya" rel="nofollow noopener">@<span>preya</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noopener">@<span>homelab</span></a></span> The most severe major flaw in <a href="https://fedifreu.de/tags/immich" rel="tag">#<span>immich</span></a> IMO is that they don't support proper shared albums. For whatever reason.</p>]]></description><link>https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239623787277354</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://fedifreu.de/ap/users/115895439005760263/statuses/117239623787277354</guid><dc:creator><![CDATA[abulling@fedifreu.de]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:18:09 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 06:10:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> Yeah this is one of the only major flaws of Immich. It just makes no sense. Here’s a service that needs external access to work properly - yet you can’t secure it with MFA (only when using an external IdP).</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239593212017789</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/preya/statuses/117239593212017789</guid><dc:creator><![CDATA[preya@mastodon.social]]></dc:creator><pubDate>Wed, 09 Sep 2026 06:10:22 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 05:32:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/fbinin%40mastodon.fbin.in">@<span>fbinin</span></a></span> <span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> Furthermore I like to manage my credentials and MFA settings in one place instead of in multiple applications. My services a home grew to the point I already have 14 applications using Keycloak as OTP service. Additionally a Single Sign On requires less support for family members. (I'm aware not every one wants to operate so many applications)</p>]]></description><link>https://forum.fedi.dk/post/https://social.kobelnet.be/ap/users/116699600450459993/statuses/117239444863287561</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.kobelnet.be/ap/users/116699600450459993/statuses/117239444863287561</guid><dc:creator><![CDATA[tandemblog@social.kobelnet.be]]></dc:creator><pubDate>Wed, 09 Sep 2026 05:32:38 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 05:26:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/fbinin%40mastodon.fbin.in">@<span>fbinin</span></a></span> <span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> But a good TOTP implementation takes some effort too if you want to support multiple devices and recovery codes. The library updates are probably not because of TOTP itself, the might be required due to the libraries dependencies or framework integrations. Furthermore, if TOTP is implemented, why not add WebAuthn/Passkeys too?</p>]]></description><link>https://forum.fedi.dk/post/https://social.kobelnet.be/ap/users/116699600450459993/statuses/117239420157223233</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.kobelnet.be/ap/users/116699600450459993/statuses/117239420157223233</guid><dc:creator><![CDATA[tandemblog@social.kobelnet.be]]></dc:creator><pubDate>Wed, 09 Sep 2026 05:26:21 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 04:32:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/hrafnagud%40runespaces.com">@<span>hrafnagud</span></a></span> <span><a href="https://social.kobelnet.be/@tandemblog">@<span>tandemblog</span></a></span> <span><a href="/user/panda%40pandas.social">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social">@<span>homelab</span></a></span> <br />But but, TOTP is much simpler to implement and does not have several changes or does not need many updates. OAUTH can change implementation logic and unless kept updated by the user, it may not work or may lock one out (I guess). These are pics, which are sensitive and have several data which can be parsed. TOTP obviously is not hard to implement.<br />Also, TOTP can be implemented once, and not updated, it will still work.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239207044508778</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.fbin.in/ap/users/115968153178175357/statuses/117239207044508778</guid><dc:creator><![CDATA[fbinin@mastodon.fbin.in]]></dc:creator><pubDate>Wed, 09 Sep 2026 04:32:10 GMT</pubDate></item><item><title><![CDATA[Reply to #Immich does not have 2FA and the devs made clear, it&#x27;s not coming. on Wed, 09 Sep 2026 04:09:15 GMT]]></title><description><![CDATA[<p><span><a href="https://social.kobelnet.be/@tandemblog" rel="nofollow noreferrer noopener">@<span>tandemblog</span></a></span> <span><a href="/user/panda%40pandas.social" rel="nofollow noreferrer noopener">@<span>panda</span></a></span> <span><a href="/user/homelab%40fedigroups.social" rel="nofollow noreferrer noopener">@<span>homelab</span></a></span> Good point - thanks for sharing your thoughts on that one! <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title="👍" alt="👍" /><img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3fb.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--skin-tone-2" style="height:23px;width:auto;vertical-align:middle" title="🏻" alt="🏻" /></p>]]></description><link>https://forum.fedi.dk/post/https://runespaces.com/users/hrafnagud/statuses/01M225P3GMFNJ0THWJHPAN1JKZ</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://runespaces.com/users/hrafnagud/statuses/01M225P3GMFNJ0THWJHPAN1JKZ</guid><dc:creator><![CDATA[hrafnagud@runespaces.com]]></dc:creator><pubDate>Wed, 09 Sep 2026 04:09:15 GMT</pubDate></item></channel></rss>