Sublime Forum

Security account management - Failure on two factors

#1

Hello,

I noted that it was impossible for me to add a software authenticator to my account in the case of your forum.

I first thought it was a time zone problem …

I then realized that the key of the proposed authenticator was systematically the same, as if it were a constant, and this, whether for the QR code or the manual code.

Incidentally, in terms of security, this code must be regenerated, in order to avoid any problem of compromised account … whether this code is unique or shared, which would be even worse.

0 Likes

#2

Thanks for finding that, we’ll look into it.

0 Likes