We do show a CAPTCHA after a number of failed log in attempts.
If you have people brute forcing your user's accounts then your problems begin there.
Your users need to be using secure passwords and 2factor authentication.
I tested this all out in the last hour or two and have to say I'm very disappointed..
A malicious person can take over your account with just a password.
- Resetting an account password requires no email confirmation.
- Changing an account email address requires no confirmation from the already ESTABLISHED / CONFIRMED email under the forum account.
Also review settings such as account lock out settings etc.
This really is no different to other services. Twitter requires no email confirmation for a password change, it only sends an email to say that the password has already been changed. As for a change of email address, Twitter sends the confirmation to the NEW email address, not the old one.
If you're really that concerned then there is a solution already. 2 factor authentication. Enable the "Require two-step verification" for all users. It's the only real secure solution.
I tested this all out in the last hour or two and have to say I'm very disappointed..
- Resetting an account password requires no email confirmation.
From XF 1.5 a confirmation email is emailed to the user which must be clicked before being allowed to change your password.
In the majority of cases, a user wants to change an email address because they no longer have access to the old/current email address. Sending an email confirmation to an old/current address would only stop the user from being able to do so.A malicious person can take over your account with just a password.
- Changing an account email address requires no confirmation from the already ESTABLISHED / CONFIRMED email under the forum account.
I believe we might have been talking about different things.You're saying that Chris is wrong, and on a default XF current version install without any add-ons a confirmation email with click requirement is not the process?
I just bought Password Requirements from @Liam W
We use essential cookies to make this site work, and optional cookies to enhance your experience.