What's New
Off Topix: Embrace the Unexpected in Every Discussion

Off Topix is a well established general discussion forum that originally opened to the public way back in 2009! We provide a laid back atmosphere and our members are down to earth. We have a ton of content and fresh stuff is constantly being added. We cover all sorts of topics, so there's bound to be something inside to pique your interest. We welcome anyone and everyone to register & become a member of our awesome community.

2FA

Ash

Platinum Member
Member
Joined
Nov 13, 2012
Posts
8,299
OT Bucks
507
Do you like to enable two-factor authentication for your website so that your user accounts are better protected? At Discussion Hub, we only force staff members to enable 2FA. I believe users are able to set it up if they want to but I haven't checked
 
I use it on all important accounts and all staff accounts.
 
I don't enforce it, not everyone likes it and I've seen where it can fail at times.
Wouldn't you be worried about the damage someone could do though if they gain access to one of your staff member's accounts?
 
I feel that all staff should have it enabled, but as far as members, no, not unless they truly want it.
 
Wouldn't you be worried about the damage someone could do though if they gain access to one of your staff member's accounts?
This is why daily and hourly backups are vital & very important.

If anything ever occurs, you can roll back your forum and use a backup.
 
I like my staff to have 2FA enabled to ensure main accounts are protected. Users can enable it if they wish to, but if you force it on people, they won't use the forum / software again.
 
Do you like to enable two-factor authentication for your website so that your user accounts are better protected? At Discussion Hub, we only force staff members to enable 2FA. I believe users are able to set it up if they want to but I haven't checked
I enabled two-factor authentication for all my accounts on forums. I use Google authenticator for my 2FA. It's better to be safe than sorry.
 
  • Like
Reactions: Cam
With forum administration, 2FA isn't needed probably with very strong passwords. However,with things like banking, 2FA is badly needed, along with strong passwords, due to identity theft.
 
I wouldn't force everyone to do it, but it is something I use religiously. If it's an available feature on a site I'm on, I use it.
 
Do you like to enable two-factor authentication for your website so that your user accounts are better protected? At Discussion Hub, we only force staff members to enable 2FA. I believe users are able to set it up if they want to but I haven't checked
No. Don't use at Conversations 2 and don't care for it unless forced to use it.
 
I wouldn't force everyone to do it, but it is something I use religiously. If it's an available feature on a site I'm on, I use it.

Those whom haven't suffered from being hacked doesn't know the importance of using 2FA. It only takes less than a minute to do it which isn't stressful.
 
I understand why its good and I do use it for certain accounts, but it is so annoying!
 
I use 2FA on every important account I have, and all the sites I run support it as well. The security boost you get from adding that second layer of verification is huge compared to relying on a password alone. That said, I don’t force regular members to enable it. Some people simply don’t like using 2FA, and as others in the thread mentioned, forcing it can push users away rather than make them feel safer. I’d rather give them the option, explain why it’s valuable, and let them decide.

I’ll admit I wasn’t a fan of it at first either, but once you use it consistently, it becomes second nature. The real trick is choosing a good authenticator app. I highly recommend using one that works across multiple devices so you’re not stuck if your phone dies or gets replaced. Authy is a solid choice, but I personally use Zoho Auth because it syncs across devices and even has a desktop option, which makes the whole process far less of a hassle.

For staff accounts, though, I’m firmly in the “required” camp. A compromised staff login can do real damage, and backups alone don’t prevent the chaos that can happen in the meantime. For everyday members, optional is fine, but for anything critical, 2FA is absolutely worth it.
 
Back
Top Bottom