**** Please enable 2FA on your OcUK forum account ****

Permabanned
Joined
9 Aug 2008
Posts
35,707
I have to log in every time I want to use the forums and every time I haven't done anything on the forums for more than a minute. Every 6 hours would be a huge improvement for me, especially since logging in to the forum now requires me to open two additional apps, log in to each, look through the junkmail and then enter the code.

The constant claims that it's only entering a code once every 30 days are only true in some circumstances. The backup codes don't work either, so I can't simply enter the same code each time I log in or go AFK during each period of 30 days.

Are you clearing your cookies?
 
Soldato
Joined
26 Dec 2011
Posts
5,830
Location
City of London
I think if a new browser or isp is detected would be the way to retrigger 2FA instead of a lazy expiry. I expect this is out of OCUK's hands though, they likely using a feature in the forum and didnt code it themselves.
Yep no doubt this is the case, and to be fair it's web forum run by volunteers.
 
Soldato
Joined
27 Feb 2015
Posts
12,621
from the Lloyds website:

“When you bank online, we use two-factor authentication (2FA) to make sure it’s you. This makes it harder for someone to get into your account, even if they guess your password.”

It says that, but they not using what I consider to be using 2FA. I can login without using a second device.
 
Permabanned
Joined
9 Aug 2008
Posts
35,707
That would certainly ease the duplicate account problem, but would simultaneously remove a lot of GD talking points.

I can live with that, I thought this was a tech forum? :cry:

It says that, but they not using what I consider to be using 2FA. I can login without using a second device.

2FA isn't about two devices - It's about 2 authentication methods. In this case it could be an app that's installed on a PC to do the second token auth, or another device or email authentication so in reality someone needs 2 things to get into your account.

Without both they not getting in captain.
 
Commissario
Joined
17 Oct 2002
Posts
33,023
Location
Panting like a fiend
It says that, but they not using what I consider to be using 2FA. I can login without using a second device.
Let me guess you log in using the app on your phone?

Your phone being one level of security (hardware ID), the log in onto your phone being another (face/fingerprint/pin/gesture to unlock the phone), and the password in the app being a third?
 
Man of Honour
Joined
5 Dec 2003
Posts
20,999
Location
Just to the left of my PC
Are you clearing your cookies?

Yes. Every time I close the browser. Every time I close a tab, for all cookies set within that tab. Every time a cookie hasn't been used for 1 minute.

I could probably set an exception for OcUK...but is it OcUK? Just this page alone runs scripts from 11 different places. My security and privacy settings are blocking 9 of those 11. I've no doubt that if I allowed them to run they would in turn run more scripts from more places and I've no doubt that some of them would be some form of spyware (even if it's "just" tracking every webpage I visit and keeping a log to sell to advertisers).
 
Soldato
Joined
21 Jan 2010
Posts
22,220
Yes. Every time I close the browser. Every time I close a tab, for all cookies set within that tab. Every time a cookie hasn't been used for 1 minute.

I could probably set an exception for OcUK...but is it OcUK? Just this page alone runs scripts from 11 different places. My security and privacy settings are blocking 9 of those 11. I've no doubt that if I allowed them to run they would in turn run more scripts from more places and I've no doubt that some of them would be some form of spyware (even if it's "just" tracking every webpage I visit and keeping a log to sell to advertisers).
Just switch to Lynx and software glued to the front of magazines. Pixel tracking knows what pr0n you prefer so get over it already.
 
Man of Honour
Joined
5 Dec 2003
Posts
20,999
Location
Just to the left of my PC
There's your problem then. Don't clear them every time you close your browser.

Make a script and stick it on the desktop to clear them when you choose to clear them.

They are already cleared when I choose to clear them. That's why I choose to have the settings the way I have them. Clearing them every 30 days may as well be never, so that wouldn't be a solution to anything.
 
Soldato
Joined
15 Feb 2003
Posts
10,053
Location
Europe
It's once every 30 days man! :cry:

For OCUK, then times that by about 50 for other sites you use and you end up doing it everyday. Especially in some implementations that require it at every IP change, or worse SMS so you can't actually log in if you don't have a signal, as happened to me in St Maarten.

I wasn't going to bother if it was email/sms but OCUKs implementation is relatively quick and easy if I have my phone next to me.
 
Back
Top Bottom