Support

Admin Tools

#18042 Tow-Factor Authentication !!

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by user80532 on Monday, 04 November 2013 08:56 CST

user80532
Mandatory information about my setup:

Have I read the related troubleshooter articles above before posting (which pages?)? yes
Have I searched the tickets before posting? yes
Have I read the documentation before posting (which pages?)? yes
Joomla! version: (3.1.5)
PHP version: (5.3.3)
MySQL version: (5.1.69)
Host: (optional, but it helps us help you)
Admin Tools version: (2.5.8)

Description of my issue: Hi i followed instructions of how to activate Tow-Factor Authentication, its been validated and activated. i am using Isis template for back end.
The Back end login page has a new field where you have to put your google code, problem is if i try to login using username and password only without putting google code i can still access it without any error or warning messages. did i miss something here?

regrads

nicholas
Akeeba Staff
Manager
Your IP address is in the IP Whitelist or in one of the two allowed IP areas in the Configure WAF page. As a result any request coming from this IP does not have any security check performed, including two factor authentication.

Please note that Admin Tools' two factor auth feature is going to be retired in the future. A much better implementation was added in Joomla! 3.2 by yours truly. As you'll be upgrading in a couple of weeks to Joomla! 3.2 you needn't worry much about Admin Tools' feature.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user80532
you right.... My IP is in Never block these IPs under Auto-ban Repeat Offenders. When i tried a 3G device a new Security Exceptions issued ... great.

It is good news indeed, but is it ( new Joomla 3.2 feature ) for back-end only?

Thanks

nicholas
Akeeba Staff
Manager
The new Joomla! 3.2 feature is MUCH better. Since I was writing a core Joomla! feature I was allowed to modify core code (something I couldn't do when writing Admin Tools). For starters, each user can have his/her own Google Authenticator code. In other words, if you have ten Super Users each one has a different secret code, making the implementation much safer. Then you can select if this feature will be available only to the back-end, only to the front-end or both in the front- and back-end. I recommend the latter: both front- and back-end. It's more secure.

In addition to Google Authenticator I also added support for YubiKey two factor authentication in Joomla! 3.2. If you've never heard of it it is an inexpensive (~20 US Dollars) hardware token that plugs in a USB port. The idea is: go to your site, enter your username and password, click on the Secret Code field, plug in the YubiKey to a USB port in your computer and touch its button. The YubiKey produces a secret code which is then validated both on your site and through a third party service. This is even more secure and easier to use than Google Authenticator.

On top of that Joomla! 3.2 has a much better password encryption algorithm (bCrypt instead of salted MD5) and a massively improved "Remember Me" functionality. All these featured combined offer an excellent upgrade in your site's security.

Nicholas K. Dionysopoulos

Lead Developer and Director

πŸ‡¬πŸ‡·Greek: native πŸ‡¬πŸ‡§English: excellent πŸ‡«πŸ‡·French: basic β€’ πŸ• My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

user80532
This is a huge leap in joomla security .... thanks Nicholas for the information provided above.

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!