October: Add two-factor authentication to octobercms.com accounts

Created on 27 Feb 2019  路  11Comments  路  Source: octobercms/october

As of today we have 12 plugins published on the octobercms.com marketplace that are used by around 1500 projects.

Currently, the only security measure that prevents a bad actor from releasing a malicous update to those 1500 projects is our account password.

I feel like this is a huge security risk that is waiting to be exploited. The ability to set up two-factor auth on octobercms.com accounts would reduce this risk considerably.

In Progress Website / Marketplace / Docs

Most helpful comment

Hi @tobias-kuendig. @daftspunk will look at it!

All 11 comments

Hi @tobias-kuendig. @daftspunk will look at it!

Maybe something like this plugin (if anyone feels like _doogfooding_ it):
https://octobercms.com/plugin/vdlp-twofactorauthentication

Thanks for the suggestion! We'll see what we can do. For now it is highly recommended that you follow best practice when it comes to passwords, ie. use a password manager with 2FA

This issue will be closed and archived in 3 days, as there has been no activity in the last 30 days. If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.

This issue will be closed and archived in 3 days, as there has been no activity in the last 30 days.

  • If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue. - If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 30 days.

  • If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue. - If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 30 days.
If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.
If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 30 days.
If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.
If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 60 days.
If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.
If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 60 days.
If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.
If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

This issue will be closed and archived in 3 days, as there has been no activity in the last 60 days.
If this issue is still relevant or you would like to see it actioned, please respond and we will re-open this issue.
If this issue is critical to your business, consider joining the Premium Support Program where a Service Level Agreement is offered.

Was this page helpful?
0 / 5 - 0 ratings