Henrik Schack
Forum Replies Created
-
No problem 🙂
Best regards
Henrik SchackOk, feel free to email me at henrik at schack dot dk
Best regards
Henrik SchackHmm what’s different for this particular site ? compared to those other sites ?
I really want to help, but I need info 🙂Best regards
Henrik SchackSounds pretty much like you don’t have the plugin enabled on the account you’re using.
Could you check your settings ?
Best regards
Henrik SchackHi Rubin110
I don’t agree on your idea, if such a feature was possible, the next feature request in this support area would be for a way to avoid it 🙂
Educating/informing your users is a much better way of getting them to use two factor authentication, then they’ll love you for installing the plugin, instead of hating you for bugging them 🙂
Stories like the one about the Mat Honan hack seems to be pretty effective when it comes to explaining the importance of security,
to many people probably much more effective than fancy calculations demonstrating their password strength etc.Best regards
Henrik SchackWouldn’t this make it somewhat easy to gain access if you already have hacked the persons mail account ?
I would assume that if a person has lost his phone he is going to get a new one where he can setup the Google Authenticator again.
Or he could use this Chrome extension to generate a code assuming he has a copy of the secret : https://chrome.google.com/webstore/detail/ilgcnhelpchnceeipipijaljkblbcobl?utm_source=chrome-ntp-icon
Best regards
Henrik SchackHi
Regarding #3
That’s a big no, then my plugin would in effect be a 1 factor authentication plugin.
But what about Google and Dropbox ? That’s the way they do it.
That’s right, but if you loose your 2. factor authentication for Google or Dropbox you’re helpless against a big company that doesn’t normally provide end-user support on the product you just lost access to, they MUST provide some way for users to get out of trouble on their own.As a WordPress users using my plugin you allways have the option to delete the plugin via a shell or FTP, or even create a support ticket at your hosting provider, and have your hosting provider delete the plugin.
Or you could create a screenshot of the QR code or even write down the secret and transfer it to another phone.Regarding #4 : On my todo list, great idea 🙂
Regarding #1 & #2 : Still thinking.
Best regards
Henrik SchackHi
No, you won’t be able to access your blog without your phone.If you loose your phone you can disable/delete the plugin via a shell or FTP.
Best regards
Henrik SchackIt’ available to all users, unless disabled by an administrator.
Best regards
Henrik SchackHi Dan
You’ll have to remove the plugin manually via FTP or a shell.
Simply delete/rename the wp-content/plugins/google-authenticator/google-authenticator.php file.Best regards
Henrik SchackForum: Plugins
In reply to: [Google Authenticator] [Plugin: Google Authenticator] Great plugin!Thanks a lot 🙂
Best regards
Henrik SchackForum: Plugins
In reply to: [Google Authenticator] [Plugin: Google Authenticator] Can't loginOk, Glad you got it working 🙂
I think I’ll follow your suggestion and change the default 🙂
ThanksBest regards
Henrik SchackYes, it is mentioned in the FAQ, would be nice if the Android and iPhone app would agree on what’s possible 🙂
http://wordpress.org/extend/plugins/google-authenticator/faq/
Best regards
Henrik SchackNo response, closing issue