sgrayban Posted March 17, 2013 Share Posted March 17, 2013 According to http://requests.whmcs.com/responses/2-factor-authentication-with-google-authenticator It was completed as of 5.2 but I don't see it. Was it removed ? 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Chris Posted March 18, 2013 Share Posted March 18, 2013 Hello, It's there - under Two Factor Authentication. You would use the Google Authenticator OATH application available in your Windows, iPhone, or Android store. 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 18, 2013 Author Share Posted March 18, 2013 The only thing related to Google Auth is something called TOTP which is a thirdparty addon you have to pay for to use a free service from google -- not exactly ethical is it ? Just like Yubikey it should be a standalone feature instead of bleeding us for more money. 0 Quote Link to comment Share on other sites More sharing options...
WHMCS Chris Posted March 18, 2013 Share Posted March 18, 2013 WHMCS' software is extremely inexpensive for the functionality it provides. With TOTP included, it ultimately comes out to .56 CENTS a day (branded monthly version) to effectively be the only piece of software a Web Hosting Provider needs other than a server control panel to run their business. I personally wouldn't call that bleeding. 0 Quote Link to comment Share on other sites More sharing options...
brianr Posted March 18, 2013 Share Posted March 18, 2013 WHMCS' software is extremely inexpensive for the functionality it provides. With TOTP included, it ultimately comes out to .56 CENTS a day (branded monthly version) to effectively be the only piece of software a Web Hosting Provider needs other than a server control panel to run their business. I personally wouldn't call that bleeding. Given that Matt had previously stated it would be free.... I must respectfully disagree. http://forum.whmcs.com/showthread.php?48074-DuoSecurity-coming-to-WHMCS-soon!/page2&p=226272#post226272 0 Quote Link to comment Share on other sites More sharing options...
MemoryX2 Posted March 19, 2013 Share Posted March 19, 2013 Given that Matt had previously stated it would be free.... I must respectfully disagree. http://forum.whmcs.com/showthread.php?48074-DuoSecurity-coming-to-WHMCS-soon!/page2&p=226272#post226272 I am right along with you on this. While I wouldn't call it bleeding I'm also not using it currently either. Very Very Frustrating to say the least. 0 Quote Link to comment Share on other sites More sharing options...
merlinpa1969 Posted March 19, 2013 Share Posted March 19, 2013 Does anyone know, will this work with the Kindle Fire as a tablet? 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 19, 2013 Author Share Posted March 19, 2013 I am right along with you on this. While I wouldn't call it bleeding I'm also not using it currently either. Very Very Frustrating to say the least. Careful Mr. Chris doesn't like Mr. Matt getting called out on morals. Mr. Chris likes deleting posts that do that... he deleted mine when I pointed out that. 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 19, 2013 Author Share Posted March 19, 2013 Mr. Chris needs to remember that it is the WHMCS USERBASE that pays the payroll checks. Something to ponder Mr. Chris and Mr. Matt. All of us have played a role in WHMCS popularity in one fashion or another. 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 19, 2013 Author Share Posted March 19, 2013 Does anyone know, will this work with the Kindle Fire as a tablet? Yes and no. It will show you the QR code but you still need a cell phone that will scan that code. 0 Quote Link to comment Share on other sites More sharing options...
MemoryX2 Posted March 19, 2013 Share Posted March 19, 2013 Mr. Chris needs to remember that it is the WHMCS USERBASE that pays the payroll checks. Something to ponder Mr. Chris and Mr. Matt. All of us have played a role in WHMCS popularity in one fashion or another. Are you using two-stage authentication yet? 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 19, 2013 Author Share Posted March 19, 2013 Are you using two-stage authentication yet? Yes because I don't want to end up being hacked like what happened here. 0 Quote Link to comment Share on other sites More sharing options...
brianr Posted March 19, 2013 Share Posted March 19, 2013 Yes because I don't want to end up being hacked like what happened here. Just keep in mind, with everyone running around screaming for 2FA, it's only one piece in the puzzle. If I can exploit another vulnerability and download your entire WHMCS DB (this is a hypothetical, BTW) the fact you had 2FA in place becomes security theater. 2FA protects against bad guys using good credentials and, really, nothing more. On the client-side, limiting what occurs w/o administrator intervention (eg auto-order setup, or cancellation), and strong process review policies in place ("gee, this guy from California, US, logged in from China..."), will mitigate a great deal. On the admin side, obviously, it's harder to mitigate and 2FA, coupled with strong perimeter and application security, would likely provide a good benefit. That said, I would like to see WHMCS start to provide better permitter security advice -- perhaps, for example, a tight set of mod_sec rules that could govern the members and admin areas. That sort of thing could help stop/prevent attacks that could otherwise be successful. 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 19, 2013 Author Share Posted March 19, 2013 Anything is possible brianr but reducing any possibility of being hacked whether its server side or not is a goal everyone should have. 0 Quote Link to comment Share on other sites More sharing options...
brianr Posted March 20, 2013 Share Posted March 20, 2013 Anything is possible brianr but reducing any possibility of being hacked whether its server side or not is a goal everyone should have. /agreed However there is a point of diminishing return.... At what point does a) the cost involved, or b) the end-user complexity / support "cost" outweigh the benefit? Given that Google Auth is an open protocol, and open app, and have an open source implementation, the "cost" involved should be zero. Now teach end users how to use it... That hurts. 0 Quote Link to comment Share on other sites More sharing options...
sgrayban Posted March 20, 2013 Author Share Posted March 20, 2013 /agreed However there is a point of diminishing return.... At what point does a) the cost involved, or b) the end-user complexity / support "cost" outweigh the benefit? Given that Google Auth is an open protocol, and open app, and have an open source implementation, the "cost" involved should be zero. Now teach end users how to use it... That hurts. Uhhh please explain what you are saying cause it just reads like ramblings or a tired person. 0 Quote Link to comment Share on other sites More sharing options...
brianr Posted March 20, 2013 Share Posted March 20, 2013 Uhhh please explain what you are saying cause it just reads like ramblings or a tired person. Let me try to simplify.... WHMCS has applied a cost ($$$) to an open and fee standard (Google Authenticator free app and it's related IETF standards). This directly goes against Matt's prior posts in this forum on the subject. Second, trying to get users to use 2 factor auth, specifically Google Authenticator is, simply, a royal pain in the ass. If you have non-technical users (and if you don't you're very lucky), many simply have a hard time "getting" it, and often require hand-holding through the setup process. This is complexity and it drives up the support costs for you and I to implement it for the end user. 0 Quote Link to comment Share on other sites More sharing options...
cenourinha Posted March 21, 2013 Share Posted March 21, 2013 I would like to see a free Google Authenticator and Duo Security option: https://www.duosecurity.com/pricing 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.