|
Hi there! I hope that everything is well.
Here at All of Life XL, we have done a round of security checks, and made some adjustments on how some things work.
1) First of all, we now require 2FA on the website – meaning that you will need to go to the login screen (use the button below) and enable it. You should be taken there automatically when you use a feature that requires a login – which is currently anything around bookmarks.
On the user profile, there is another 2FA system mentioned as well, but please don't switch that on for now. You would then be required to use both the email code and a code in an Authenticator app, which is silly. We are working on switching this second option off completely.
2) And new users will be approved manually – which means that it can take some time before they will be able to log in. Usually it will be in place within 24 hours, but it can vary.
3) These are some of several measures taken to harden the security – to prevent data theft and hacking, as well as spamming and impersonation.
4) Other measures include such as requiring strong passwords and checking them against the HIBP database of passwords that have been hacked and put on the Dark Web.
5) Also, users will now be logged out automatically after 4 hours. Then they will need to log in again.
6) Oh, and you may see a captcha on some forms, to ensure that only humans use these. We use different kinds, due to the varying compatibility with the features they are used with, but they should be easy to handle – for a human 😉
7) And there are more features, which in general work in the background, to make the site secure for all real users.
8) One thing left for the near future: we need to polish the user profile setup pages a bit! They are somewhat confusing and with some elements that are without value for a normal user. This will be fixed soon, promise! |