Following the security enhancements proposed for CSWeb (Issue #2), it is critical to extend Two-Factor Authentication (2FA) support to CSPro and CSEntry. Since CSEntry and CSPro clients frequently connect to CSWeb to deploy applications and synchronize data, usernames and passwords alone represent a significant vulnerability if a device is compromised or intercepted.
When a user logs into a CSWeb server from CSPro or CSEntry to deploy or download data, the environment must prompt for the 2FA verification token immediately after validating the primary credentials. Also, before saving synchronization credentials or initiating a data transfer connection (SyncId / SyncPassword), both applications must support the secondary authentication challenge. To maintain operational efficiency in field data collection without adding infrastructure costs, we propose leveraging the same free, robust mechanisms implemented in CSWeb.
By requiring 2FA before storing or utilizing sync credentials, we ensure that even if a supervisor's or enumerator's password is leaked, unauthorized devices cannot spoof the server, download sensitive survey structures, or upload fraudulent data.
Following the security enhancements proposed for CSWeb (Issue #2), it is critical to extend Two-Factor Authentication (2FA) support to CSPro and CSEntry. Since CSEntry and CSPro clients frequently connect to CSWeb to deploy applications and synchronize data, usernames and passwords alone represent a significant vulnerability if a device is compromised or intercepted.
When a user logs into a CSWeb server from CSPro or CSEntry to deploy or download data, the environment must prompt for the 2FA verification token immediately after validating the primary credentials. Also, before saving synchronization credentials or initiating a data transfer connection (SyncId / SyncPassword), both applications must support the secondary authentication challenge. To maintain operational efficiency in field data collection without adding infrastructure costs, we propose leveraging the same free, robust mechanisms implemented in CSWeb.
By requiring 2FA before storing or utilizing sync credentials, we ensure that even if a supervisor's or enumerator's password is leaked, unauthorized devices cannot spoof the server, download sensitive survey structures, or upload fraudulent data.