(Topic ID: 312320)

Two-Factor Authentication (2FA)

By jp1985

2 years ago


Topic Heartbeat

Topic Stats

  • 108 posts
  • 43 Pinsiders participating
  • Latest reply 2 years ago by joetechbob
  • Topic is favorited by 5 Pinsiders

You

Linked Games

No games have been linked to this topic.

    Topic Gallery

    View topic image gallery

    pasted_image (resized).png
    pasted_image (resized).png
    oopsie.png
    6E0C6ECF-A4F8-4517-878A-C61D51628336.jpeg
    2fa-phone (resized).jpg
    Screenshot_168.png
    logincode (resized).png
    email (resized).png
    login (resized).png

    You're currently viewing posts by Pinsider clearstar.
    Click here to go back to viewing the entire thread.

    #27 2 years ago
    Quoted from ForceFlow:

    I suppose I should step back and clarify since we were both making some assumptions.
    MFA (multifactor authentication) and 2FA (two-factor authentication) are more generalized terms for authentication methods that don't necessarily specify what technology is specifically being used. Just that it's something beyond simply a username and password. So, that could mean just SMS OTP (one-time password) or TOTP (timed one-time password). There are also a few other technologies, such as a physical security token or biometrics.
    The current security technology that has become standardized in the last few years is TOTP, so usually when the topic of MFA/2FA comes up, it's more often than not related to TOTP.

    Correct. As another IT leader chiming in, this is what I immediately thought the OP and you were talking about in the original post. I'm not sure why there was confusion. Regardless, I, for one, am all for 2FA/MFA here. I don't even think we need to go all the way to the point of an Authenticator App requirement. I think even SMS-based auth is sufficient for a site such as this, since the risk of a hacker 'spoofing/cloning' a SIM card to gain real-time access to your text messages just to hack into Pinside, is LOW. Regardless, in this day and age MFA isn't really a burden on users, especially if you give them options of delivery.

    I also second the idea of just make it optional to turn on...or at least flexible (i.e. text, app, or email). All of those can be set to expire within some period of time. If you don't turn it on and get hacked that's on you. No different than it being optional still for sites like eBay.

    You're currently viewing posts by Pinsider clearstar.
    Click here to go back to viewing the entire thread.

    Reply

    Wanna join the discussion? Please sign in to reply to this topic.

    Hey there! Welcome to Pinside!

    Donate to Pinside

    Great to see you're enjoying Pinside! Did you know Pinside is able to run without any 3rd-party banners or ads, thanks to the support from our visitors? Please consider a donation to Pinside and get anext to your username to show for it! Or better yet, subscribe to Pinside+!


    This page was printed from https://pinside.com/pinball/forum/topic/two-factor-authentication-2fa?tu=clearstar and we tried optimising it for printing. Some page elements may have been deliberately hidden.

    Scan the QR code on the left to jump to the URL this document was printed from.