Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


freitasm

BDFL - Memuneh
73976 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

#203119 18-Sep-2016 15:23
Send private message

I have now added an option to enabled two factor authentication to your Geekzone account. You can do this from your profile page or directly from 2FA-enable your Geekzone account.

 

This is used for login on the main site only. Currently not used on mobile and APIs - those don't allow profile changes or PM so not a priority at the moment.

 

You will need an authenticator app - Authy or Google Authenticator for example.

 

 





Are you happy with Geekzone? Consider subscribing or making a donation.

 

 

 

freitasm on Keybase | My technology disclosure 

 

These links are referral codes: Sharesies | Mighty Ape | Norton 360 | Lenovo laptops | GoodsyncGeekzone Blockchain Project


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3
Affiliate link
 
 
 

Affiliate link: Buy anything now at AliExpress.
blakamin
4431 posts

Uber Geek
Inactive user


  #1635495 18-Sep-2016 16:00
Send private message

Quick thought about the login. With the 2FA and the captcha, what happens if you don't instantly get the tick that you're not a robot and your 2FA code times out? This could get frustrating, continually having to change codes and re-captcha. Any chance of a page after the captcha that you can insert your 2FA, for those that use it? 

 

I'm asking this as I use the full site on my mobile, and it nearly always tells me I'm a robot. Changing codes on it will be a pain.. eg, open auth app, open GZ, swap back to auth app, wait for keyboard in browser, captcha says I'm a robot, do the picture thing, switch back to auth app coz my code has expired, back to browser, wait for keyboard to change 2FA code... You get the idea...


michaelmurfy
/dev/ttys0
10979 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1635496 18-Sep-2016 16:01
Send private message

Perfect! Enabled.

 

Just noticed there is no badge for doing this though :)





Michael Murphy | https://murfy.nz | https://keybase.io/michaelmurfy - Referral Links: Sharesies | Electric Kiwi
Are you happy with what you get from Geekzone? Please consider supporting us by making a donation.


freitasm

BDFL - Memuneh
73976 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1635497 18-Sep-2016 16:02
Send private message

I thought of the timeout for the captcha - something for phase two where 2FA will actually be optional and only required if your connection triggers a warning.

 

Badges... Yes, will look at this.





Are you happy with Geekzone? Consider subscribing or making a donation.

 

 

 

freitasm on Keybase | My technology disclosure 

 

These links are referral codes: Sharesies | Mighty Ape | Norton 360 | Lenovo laptops | GoodsyncGeekzone Blockchain Project




michaelmurfy
/dev/ttys0
10979 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1635515 18-Sep-2016 16:31
Send private message

Boom! Badge achieved. That was quick!





Michael Murphy | https://murfy.nz | https://keybase.io/michaelmurfy - Referral Links: Sharesies | Electric Kiwi
Are you happy with what you get from Geekzone? Please consider supporting us by making a donation.


Lias
4865 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1635520 18-Sep-2016 17:06
Send private message

Sweet





I'm a geek, a gamer, a dad and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it.


mentalinc
2461 posts

Uber Geek

Trusted

  #1635557 18-Sep-2016 18:00
Send private message

No need to reauthenicate before setting up?

 

Should require username and password before the 2FA QR code is shown...





CPU: AMD 5900x | RAM: GSKILL Trident Z Neo RGB F4-3600C16D-32GTZNC-32-GB | MB:  Asus X570-E | GFX: EVGA FTW3 Ultra RTX 3080Ti| Monitor: LG 27GL850-B 2560x1440

 

 


freitasm

BDFL - Memuneh
73976 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1635559 18-Sep-2016 18:02
Send private message

Yes, could be a good idea to prevent un-authorised enable... Will add that.





Are you happy with Geekzone? Consider subscribing or making a donation.

 

 

 

freitasm on Keybase | My technology disclosure 

 

These links are referral codes: Sharesies | Mighty Ape | Norton 360 | Lenovo laptops | GoodsyncGeekzone Blockchain Project




mentalinc
2461 posts

Uber Geek

Trusted

  #1635565 18-Sep-2016 18:34
Send private message

And then I guess conversely if it's not there already, to disable 2FA requires user,pass and valid 2FA token..

 

 

 

But well done on adding 2FA!!!





CPU: AMD 5900x | RAM: GSKILL Trident Z Neo RGB F4-3600C16D-32GTZNC-32-GB | MB:  Asus X570-E | GFX: EVGA FTW3 Ultra RTX 3080Ti| Monitor: LG 27GL850-B 2560x1440

 

 


Handle9
7610 posts

Uber Geek

Trusted
Lifetime subscriber

  #1635567 18-Sep-2016 18:37
Send private message

Done! Good work.

Taubin
516 posts

Ultimate Geek

ID Verified
Subscriber

  #1635569 18-Sep-2016 18:41
Send private message

Thank you for adding this!





ZL2TOY/ZL1DMP


freitasm

BDFL - Memuneh
73976 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1635581 18-Sep-2016 19:13
Send private message

mentalinc:

 

And then I guess conversely if it's not there already, to disable 2FA requires user,pass and valid 2FA token..

 

But well done on adding 2FA!!!

 

 

It requires a valid 2FA token or a reset code created when you add the 2FA to account.

 

No password required because if an email account is compromised then password reset is trivial so the 2FA is independent of the password to reset.

 

Also I am planning to remove passwords from Geekzone. See discussion here.





Are you happy with Geekzone? Consider subscribing or making a donation.

 

 

 

freitasm on Keybase | My technology disclosure 

 

These links are referral codes: Sharesies | Mighty Ape | Norton 360 | Lenovo laptops | GoodsyncGeekzone Blockchain Project


mentalinc
2461 posts

Uber Geek

Trusted

  #1635818 19-Sep-2016 13:05
Send private message

michaelmurfy:

 

Perfect! Enabled.

 

Just noticed there is no badge for doing this though :)

 

 

I seem to be raining on this parade far more than I'd like as its a very positive step forward...

 

However, having the badge visible (must collect them all) on public pages now provides a way to easily identify who has and hasn't got 2FA on their account...

 

Not sure how the no password approach in the future will change or make this less of a concern...

 

but a good way to signal my account is more secure go look at another one..





CPU: AMD 5900x | RAM: GSKILL Trident Z Neo RGB F4-3600C16D-32GTZNC-32-GB | MB:  Asus X570-E | GFX: EVGA FTW3 Ultra RTX 3080Ti| Monitor: LG 27GL850-B 2560x1440

 

 


Sounddude
I fix stuff!
1879 posts

Uber Geek

Trusted
Vocus
Lifetime subscriber

  #1635821 19-Sep-2016 13:07
Send private message

Awesome! Done!

 

 

 

 


freitasm

BDFL - Memuneh
73976 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #1636102 19-Sep-2016 20:22
Send private message

mentalinc:

 

No need to reauthenicate before setting up?

 

 

Password now required to enable 2FA.





Are you happy with Geekzone? Consider subscribing or making a donation.

 

 

 

freitasm on Keybase | My technology disclosure 

 

These links are referral codes: Sharesies | Mighty Ape | Norton 360 | Lenovo laptops | GoodsyncGeekzone Blockchain Project


sjrhughes
6 posts

Wannabe Geek


  #1642262 29-Sep-2016 08:15
Send private message

Well done getting the 2FA enabled and also your fast responses to suggestions for improvements.

 

We are looking to provide similar authentication option to our clients and was wondering if you have any recommendations of the tools/controls to use or any pitfalls to avoid.


 1 | 2 | 3
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

D-Link G415 4G Smart Router Review
Posted 27-Jun-2022 17:24


New Zealand Video Game Sales Reaches $540 Million
Posted 26-Jun-2022 14:49


Github Copilot Generally Available to All Developers
Posted 26-Jun-2022 14:37


Logitech G Introduces the New Astro A10 Headset
Posted 26-Jun-2022 14:20


Fitbit introduces Sleep Profiles
Posted 26-Jun-2022 14:11


Synology Introduces FlashStation FS3410
Posted 26-Jun-2022 14:04


Intel Arc A380 Graphics First Available in China
Posted 15-Jun-2022 17:08


JBL Introduces PartyBox Encore Essential Speaker
Posted 15-Jun-2022 17:05


New TVNZ+ streaming brand launches
Posted 13-Jun-2022 08:35


Chromecast With Google TV Review
Posted 10-Jun-2022 17:10


Xbox Gaming on Your Samsung Smart TV No Console Required
Posted 10-Jun-2022 00:01


Xbox Cloud Gaming Now Available in New Zealand
Posted 10-Jun-2022 00:01


HP Envy Inspire 7900e Review
Posted 9-Jun-2022 20:31


Philips Hue Starter Kit Review
Posted 4-Jun-2022 11:10


Sony Expands Its Wireless Speaker X-series Range
Posted 4-Jun-2022 10:25









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.