Thursday, 26 March 2020 13:27

Urging all clients to use 2 factor authentication (2FA)

Written by

We are urging all clients to enable "2FA" (2 factor authentication) for any web-related dashboards:

  • Domain registration (e.g. GoDaddy supports it, Network Solutions not yet)
  • Hosting control panel (e.g. InMotion, SiteGround)
  • CMS control panel (e.g. Joomla, Wordpress, Drupal)
  • Newsletter / Subscriber (e.g. Mailchimp supports it, Constant Contact not yet)
  • Google (Analytics, Adwords, Adsense, Webmaster Tools, etc.)

Here's How it Works:

  1. Download the Google Authenticator app onto your smart phone (Google Play, Apple)   
    (An alternative to Google Authenticator is the "Yubikey")
  2. Add the relevant dashboard into your Devices -> Google Authenticator App (scan barcode using smart phone camera)
  3. Sign into the related dashboard, edit your user account, locate the 2FA settings, and type the verification code into your user account.  Save.
  4. The next time you sign in you will be prompted to enter the verification code along with your password. 
    (Tip: don't just assume this works - test it!)

 

 

What is 2FA?

 Two Factor Authentication is an additional security layer that asks for an randomly generated verification code along with your standard username & password.  Since a username & password can be guessed, lost, or stolen, the additional security layer means that without physical access to your phone, a potential hacker still won't be able to get in!  

 

How about 3FA?

Great question!  Any login or set of credentials involves at least one of three of the following: something you know (a username & password), something you have (a phone), and something you are (a fingerprint, retina scan). 

This means that for the highest level of security, you'll have a username & password, a randomly generated verification code, AND a fingerprint/retina scan!  

However, this is not feasable in most situations, which is why we suggest using a combination of two: the username & password PLUS the randomly generated verification code.

Last modified on Thursday, 26 March 2020 14:03

Latest Comments

Got a similar email that seemed suspicious. Ignored it and they even followed up today.
My organization received one of these emails from "Linda," but uses https://www.bestprosintown.com/p...
Hi Nate, I got the same email template from the same email address today and found you through a ...
Just received one today (16 Aug 2022) from "Mailchimp". Thanks for sharing!
Thanks for posting this. I just got one today. I was 99% sure it was a scam, and your post confirmed...


Design & Development

Wordpress, Drupal, Joomla
New custom websites
Bespoke themes and extensions
Redesigns, upgrades, migrations

Web Design & Development


Optimization & SEO

Let us optimize and manage your overall online presence. We offer full service monthly SEO as well as one-time projects.  

Optimization Plans & Pricing


Maintenance, Patching

White glove monthly backups, security updates, maintenance and testing for your Wordpress, Drupal, or Joomla site.

Maintenance Plans & Pricing


Email Newsletter

Bring your web & marketing performance to the next level: monthly blog post roundup via email.  

Stay in Touch!