Totally agree with you about Lastpass.Might I also suggest Lastpass Authenticator as an alternative to the Google Auth App. It pairs extremely well with the Lastpass Password Manager which is free on Desktop and Mobile.
https://lastpass.com
https://lastpass.com/auth/
Password managers are a Lifesaver!
I agree about using 2FA. I disagree about using KeePass as opposed to Lastpass, but that is a personal thing. It comes down to ease of sync across devices for me.I'll clear a few things up. Every app that follows RFC 6238 will work with the forums enabled 2FA. GitHub, Outlook, Gmail, Facebook, Discord, Evernote, Dropbox, etc. all allow 2FA through this RFC. There are a few apps that follow the RFC, most popular ones being Google Authenticator and Authy, and some other ones such as Microsoft Authenticator and LastPass' Authenticator. Whereas Authy is more or less the LastPass of password managers that offers sync between devices, master password to unlock/allow devices, wherein the master password can be used in case your devices are screwed and you wish to get access through their web interface.
For me, KeePass and Authy is the way to go. With Google Authenticator and Microsofts Authenticator, if you loose your device or the app data gets corrupted, you loose all your added accounts and unless you have backup passwords (which should be given to you when an account has activated 2FA) you won't be able to get into your account. Authy will still allow access to adding new devices as long as you have a master password. Of course, they have stronger security than what I'm saying but I won't get into it. Reason for KeePass is that it has all your passwords in a database file and as long as you keep that stored safety and redundantly you will be safe from loosing any data.
I agree about using 2FA. I disagree about using KeePass as opposed to Lastpass, but that is a personal thing. It comes down to ease of sync across devices for me.
You can use other apps like Authy if you don't want to use a Google app. There are quite a few "compatible" applications, and the scheme relies on a purely time-based standardised algorithm that, based on a seed value (which is what you set the app up with) will generate log-in codes. It does not require any communication with third party services at all.*facepalm*
Google makes it safer, really?
Totally agree with you about Lastpass.
I didn't know they had their own authenticator. What does the LP Auth provide extra to the Google one?
Erm thanks. And what does that all mean in non geek old chap![]()
Greetings everyone,
I have completed some nightly maintenance here on the forums. Tonights maintenance includes the addition of Two Factor auth via the Google Authenticator Application on your mobile devices.
You can manage the functionality of it here: https://forums.frontier.co.uk/profile.php?do=twofactor
Additionally, I would recommend disabling the IP-validation method if you've previously enabled it. You can turn that validator off at the bottom of this page here: https://forums.frontier.co.uk/profile.php?do=editoptions (unless you want Triple Factor auth?!)
What's next? Just some CDN changes to further speed up the forums.![]()
If you set this up, when you login to the forums, you will receive a code on your cellphone that you will need to type in before you can log in. It's optional whether you want to use this or not.
Additionally, I would recommend disabling the IP-validation method if you've previously enabled it. You can turn that validator off at the bottom of this page here: https://forums.frontier.co.uk/profile.php?do=editoptions (unless you want Triple Factor auth?!)
Hi Brett,
are you sure disabling the IP-validation is only recommended? I managed to lock me out completely by letting it stay on.
I've made this account just to post this, my other account (bend_r) is not able to use the forums after turning on two-factor.
When I log in (seemingly ok) I'm then asked to verify my current IP with a token from the google app, which I enter and the system confirms 'Your authentication code has been verified.'
Then when the browser redirects I am again asked to verify my current IP. This goes on in an (seemingly) infinite loop.
Please note that I'm using IPv6, maybe this is related?
Hi Brett,
are you sure disabling the IP-validation is only recommended? I managed to lock me out completely by letting it stay on.
I've made this account just to post this, my other account (bend_r) is not able to use the forums after turning on two-factor.
When I log in (seemingly ok) I'm then asked to verify my current IP with a token from the google app, which I enter and the system confirms 'Your authentication code has been verified.'
Then when the browser redirects I am again asked to verify my current IP. This goes on in an (seemingly) infinite loop.
Please note that I'm using IPv6, maybe this is related?
thank you for your help,
Commander Benderson
I have the same issue. I had to click the link to disable 2fa in order to log in and post this. I was using Microsoft Authenticator but it did seem to be accepting the codes each time ("Your authentication code has been verified"). I log in from work and home, so perhaps simply having multiple IPs causes issues?
I believe it's coded to inherit vbulletins IP session settings, which is the 255.255.255.0/24 style right now - a class C block.