SenGuy Posted November 7, 2015 Posted November 7, 2015 It would be nice if two factor authentication ( a text message to a phone) were to be implemented in the next version. Thanks
Bluto Posted November 7, 2015 Posted November 7, 2015 That sounds like something for a developer to create. I believe there is one for the admin area, maybe that developer could create one for the general site?
Koby Posted November 7, 2015 Posted November 7, 2015 24 minutes ago, Bluto said: That sounds like something for a developer to create. I believe there is one for the admin area, maybe that developer could create one for the general site? The admin cp is just that an admin can set a global 2nd password which all admins would have to have to be able to login to admin cp. What the OP is referring to is a feature that FaceBook has, in which to login you must have a code that is sent to your mobile. The issue I see with this in IPS; is most users aren't going to want to share their mobile number to access a forum.
Bluto Posted November 7, 2015 Posted November 7, 2015 10 minutes ago, Koby said: The admin cp is just that an admin can set a global 2nd password which all admins would have to have to be able to login to admin cp. What the OP is referring to is a feature that FaceBook has, in which to login you must have a code that is sent to your mobile. The issue I see with this in IPS; is most users aren't going to want to share their mobile number to access a forum. I didn't really look at the mod for the admin control panel. But I knew something was in there related to it. I don't think this is something that IP is going to put into the script just because it's so niche. Not a lot of communities are going to use it. As far as the people putting in their numbers, you're probably right about their personal numbers. Though when you create a twitter bot (twitter app) you need to have a mobile number attached to the profile, you do this via Google Voice - Twitter only allows a mobile number to be used once on the site (assuming that is used for the persons personal Twitter account). So, people can get around having to use their personal number. I would probably use this on my forum. But my forum is a bunch of "high security tech" type people who would love something like this.
Spirits of Arianwyn Posted November 7, 2015 Posted November 7, 2015 My community would love this. You don't need to give your mobile number, you can use the 2-step auth with codes and just use an app like Google Authenticator...
Hexsplosions Posted November 7, 2015 Posted November 7, 2015 2 hours ago, Spirits of Arianwyn said: you can use the 2-step auth with codes and just use an app like Google Authenticator... +1 I'd support that. I already use authenticator for several sites.
Management Lindy Posted November 8, 2015 Management Posted November 8, 2015 We are planning on 2FA - likely the first half of next year (but don't quote me.)
Bluto Posted November 8, 2015 Posted November 8, 2015 39 minutes ago, Lindy said: We are planning on 2FA - likely the first half of next year (there is a 110% chance we're adding it!) Quoted!
Joel R Posted November 8, 2015 Posted November 8, 2015 15 hours ago, Lindy said: We are planning on 2FA - likely the first half of next year (but don't quote me.) Is this part of a broader push into mobility and mobile enhancements? Or is this an isolated feature?
aaabe4d31bb Posted May 8, 2016 Posted May 8, 2016 On 11/7/2015 at 5:13 AM, Lindy said: We are planning on 2FA - likely the first half of next year (but don't quote me.) Any progress?
MadMaxMangos Posted May 28, 2016 Posted May 28, 2016 @Lindy Is there any update on 2 factor auth? Something my community is interested in
Management Lindy Posted May 31, 2016 Management Posted May 31, 2016 We're using 2FA on our managed/enterprise platform. It will be implemented in the retail product in coming months.
The Dark Wizard Posted May 31, 2016 Posted May 31, 2016 3 hours ago, Lindy said: We're using 2FA on our managed/enterprise platform. It will be implemented in the retail product in coming months. Awesome. Just as an example are you using text message/emailcode/yubikey or authy/google app?
Jed Rosenzweig Posted June 1, 2016 Posted June 1, 2016 21 hours ago, Lindy said: We're using 2FA on our managed/enterprise platform. It will be implemented in the retail product in coming months. I'm using it for our site and it works great, nice little piece of mind.
Jswerv3 Posted June 1, 2016 Posted June 1, 2016 On 5/30/2016 at 10:58 PM, Lindy said: We're using 2FA on our managed/enterprise platform. It will be implemented in the retail product in coming months. For 3.4x as well?
Morgin Posted June 3, 2016 Posted June 3, 2016 On 5/30/2016 at 8:58 PM, Lindy said: We're using 2FA on our managed/enterprise platform. It will be implemented in the retail product in coming months. Is this likely to come before 4.2 do you think? 2FA is starting to become a must have given the number of data dumps that have happened and users simply cant be trusted to not reuse passwords (even moderators).
Management Lindy Posted June 5, 2016 Management Posted June 5, 2016 On 5/31/2016 at 11:49 PM, Jswerv3 said: For 3.4x as well? No. On 6/3/2016 at 7:16 PM, Morgin said: Is this likely to come before 4.2 do you think? 2FA is starting to become a must have given the number of data dumps that have happened and users simply cant be trusted to not reuse passwords (even moderators). Possibly, but I can't make any promises.
tAPir Posted June 5, 2016 Posted June 5, 2016 I hope there's a way to switch it off in ACP. I'm old and stupid and have difficulty remembering one password.
Aiwa Posted June 5, 2016 Posted June 5, 2016 4 minutes ago, tAPir said: I hope there's a way to switch it off in ACP. I'm old and stupid and have difficulty remembering one password. And you still only remember one password. The second one is sent to you, or you have to get it from an authentication app that has rolling codes.
tAPir Posted June 5, 2016 Posted June 5, 2016 Thanks for the info but I joined a forum recently with this. I left after 5 logins because I just found it as a PITA. I can understand someone with a techie forum wanting it (as above) but for my little forum most of my users would leave if I implemented this.
Aiwa Posted June 5, 2016 Posted June 5, 2016 1 minute ago, tAPir said: Thanks for the info but I joined a forum recently with this. I left after 5 logins because I just found it as a PITA. I can understand someone with a techie forum wanting it (as above) but for my little forum most of my users would leave if I implemented this. I don't disagree with you. I see it as an option for the member of they want the added security, and a must for admins to help secure the board.
The Dark Wizard Posted June 5, 2016 Posted June 5, 2016 I just want to know what kind of 2 factor does the Enterprise platform have?
Jswerv3 Posted June 5, 2016 Posted June 5, 2016 17 hours ago, Lindy said: No. Thanks for supporting your product! /sarcasm
The Dark Wizard Posted June 5, 2016 Posted June 5, 2016 31 minutes ago, Jswerv3 said: Thanks for supporting your product! /sarcasm No need to be rude. Development for 3.4x ended You only get security updates now.
Jed Rosenzweig Posted June 6, 2016 Posted June 6, 2016 22 hours ago, Jswerv3 said: Thanks for supporting your product! /sarcasm Also, the telegram-to-post feature is going offline.
Recommended Posts
Archived
This topic is now archived and is closed to further replies.