finds.dev← search

// the find

morozen/pam_twauth

★ 3 · C · updated Sep 2015

twauth PAM module enables authentication over Twilio SMS API

A PAM module written in C that adds Twilio SMS as a second factor for Linux logins (SSH etc.), reading the target phone number out of the GECOS field in /etc/passwd. Useful only to someone who wants self-hosted SMS 2FA on an old-school Linux box and is comfortable auditing C auth code themselves.

Repurposing the GECOS telephone field to store per-user phone numbers is a neat way to avoid inventing a separate mapping file. The module does exactly one thing and the source is small enough to read end to end in an afternoon. Setup correctly calls out chmod 0600 root:root on the credentials file instead of leaving that as an afterthought.

The README's own TODO admits there's no syslog logging, no reviewed memory allocation/release, and 'improve error handling and sanity checks' — all serious gaps for something sitting in the auth path. Last commit is from 2015 and only verified against Debian 8; it hasn't been built or tested against any libcurl/PAM combination from the last decade. It links against libcurl's GnuTLS flavor specifically, which is an unusual and fragile build requirement on modern distros. There's no mention of rate limiting, OTP expiry, or replay protection on the SMS challenge, so as shipped it's a weak second factor even if it compiles.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →