Admin Posted October 24, 2015 Posted October 24, 2015 I have just added some extra great features to the site that I hope you may find useful especially the extra focus on site security: Thread Tagging In the forums now you can tag a thread with a keyword. Using the advanced search you can search by Tag however the system is limited to the tags that users have attributed to forum threads. The tags currently are mostly in the Media section however I encourage all users to start adding Tags to threads. Having Tags on threads also helps the search engines like Google etc find your thread here on Recreational Flying by the Tags: 2 Step Verification Two-step verification, also known as two-factor authentication, requires you to provide two pieces of information to login. The general form is expressed as "something you know and something you have". "Something you know" is your password. "Something you have" is the new part. You may have seen this with other services, such as Google accounts. If you're familiar with that, you'll understand how it works here in Recreational Flying. Two-step verification is something a user has to opt into sometime after they have registered. Enabling it increases security at the expense of a more complex login procedure. For many users, particularly ones that just lurk or only have a few posts, the "value" of their account is low so the cost may outweigh the benefit. However, for some users, the extra security could be worthwhile. NOTE: 2 STEP VERIFICATION IS AN OPTION THAT USERS CAN NOW TURN ON OR LEAVE OFF - IT IS ONLY FOR USERS THAT WISH TO HAVE GREATER SECURITY AND PROTECTION When you've enabled two-step verification, you will login with your username or email and password as normal. Once those are verified, we will determine if two step verification is needed. If so, you'll need to take the appropriate steps to complete that. Upon receiving that verification, you'll be logged in as normal. Let's look at how each step works in more detail... To enable, you enter the two-step verification page in your account section (displayed as an option in the drop down when you click your avatar in the site side column). Note that you'll need to confirm your password before you can do any manipulation to the two-step verification settings. To enable, you simply pick the method of verification you want to use. Recreational Flying provides you with two "primary" verification methods: Verification code via app - this will use an app on your phone (such as Google Authenticator or Authy) to generate a 6 digit code. This code changes every 30 seconds. Email confirmation - this will send a unique, one-time-use code to the email address associated with your account. This method is not preferred over the app-based verification because if an attacker has access to your account, they may also have access to your email. However, it's certainly better than nothing. To enable any method, you will need to go through the verification process to ensure that everything works as expected. This prevents you from being locked out by a system you didn't successfully complete once. Password and Email Change Beyond the above two-step verification, we have also made several other small account security-related improvements. Now, if your password is changed, you will receive an email to make you aware of this. Normally you can disregard this, but it serves to help notify you if someone is accessing your account and attempting to block your access to it. Similarly, if your registered email is changed, you'll receive an email (to the previous address) to make you aware of this. Password Reset Process Changed The password reset process has been simplified to be more user friendly and not send a password via email. Once you receive the email for the password reset request, the link will allow you to set a new password directly. This is more in line with current approaches to password resetting. New Forum Posts Now on the right side of the Forums Main Page, the latest posts are displayed as well as the latest profile posts New User Email Confirmation One thing that has been bugging me is that the core software doesn't allow me to resend a new user their registration confirmation link email. This has now been added so I can do this for new users Plus many other small enhancements 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now