Two-Factor Authentication lets you ensure only trusted networks have access to your account, by using your smartphone to validate login attempts from new IP addresses.
Why use Two-Factor Authentication?
The most common form of "hacking" a forum today is someone guessing or in some other way gaining access to the password to an administrator account. Even with password protection on your AdminCP and ModCP directory, irreparable harm can be done with an administrator account without needing to log in to any of these locations. Enabling two-factor authentication ensures that only trusted networks can access the accounts of your staff as well as your members.
Our two-factor authentication mod uses Google Authenticator to pair a member's forum account with their smartphone app. A "Recovery Key" shown on-screen during setup ensures that if a member should ever lose their phone, they can regain access to their account.
General / Other
- Adds a "Two-Factor Authentication" link in the UserCP under "My Account"
- Displays a page with a button to activate or deactivate the authenticator
- Logs the IP Address of members who have activated the authenticator
- Asks for verification code for untrusted networks
- Blocks forum, AdminCP and ModCP access attempts from untrusted networks
- Uses Google's authenticator to handle the QR barcode and code generation
- Works on Android and iOS
- Recovery Key ensures that if you lose your phone, you can deactivate the authenticator
- Adds a new config.php parameter, $config['TwoFactor']['ipwhitelist']
- Whitelists IPs for all accounts for as long as the IP is in config.php
- Follows the same rules as the AdminCP "IP Ban" interface for powerful IP management
General / Other
- Display version number
- Enter your Affiliate ID
This mod displays a copyright notification in the footer of all pages which includes:
- 1 Link to DragonByte Technologies homepage
- 1 Link to Product Description page of this modification