We are happy to announce that we have just released a new version of our flagship software product, Syncplify Server!
What’s changed?
Identity verification during
HA-JOINis now mutual and bidirectionalIncreased password hashing rounds to the levels required for full FIPS 140-3 compliance (and all existing hashes are automatically upgraded at next login with zero administrative burden)
Fixed a bug that allowed a SuperAdmin to create a password-less SuperAdmin account (the password-less SA would be dead-on-arrival though, as password-less SuperAdmin logins are always forbidden by the API, so this does not constitute a widening of the software’s security posture)
Strengthened TOTP replay prevention in all 2FA/MFA paths, now even cross-node when the software runs in high-availability (HA) deployments
Improved the TOTP general user experience (UX), now featuring recovery codes (shown only once during enrollment)
Added the ability for each individual user to revoke “trusted devices” (specifically for the TOTP authentication path)
WebClient! now properly honors the “force change password” and “force enroll in MFA” settings when an Admin sets them for a specific user account
As usual, you can download the most recent release from our website.
Thank you all for trusting our software with your secure file transfers!

