Protecting your account

Account security is an important concern to us. There are seemingly endless stories about social media accounts being hacked but the usual suspect is usually the users password being recorded or guessed. Because password reuse is common, and maintaining account security is a big priority. To help this, we advise villagers to take advantage of the following features.

Two-Step Verification

Two-step verification, also known as two-factor authentication, requires you to provide two pieces of information to login. The general form is expressed as “something you know and something you have”. “Something you know” is your password. “Something you have” is the new part. You may have seen this with other services, such as Google accounts. If you’re familiar with that, you’ll understand how it works in KenyaTalk.

Two-step verification is something a user has to opt into sometime after they have registered. Enabling it increases security at the expense of a more complex login procedure. For many talkers–particularly ones that just lurk or only have a few posts (New Villagers) --the “value” of their account is low so the cost may outweigh the benefit. However, for Senior Villager and Village Elders, the extra security should be worthwhile.

When you’ve enabled two-step verification, you will login with your username or email and password as normal. Once those are verified, we will determine if two step verification is needed. If so, you’ll need to take the appropriate steps to complete that. Upon receiving that verification, you’ll be logged in as normal.

Let’s look at how each step works in more detail…

Two-Step Verification: Setup

http://www.kenyatalk.com/index.php?account/two-step

https://xenforo.com/community/attachments/two-step-setup1-png.108815/https://xenforo.com/community/attachments/two-step-setup2-png.108816/

To enable, you enter the two-step verification page from the account section. Note that you’ll need to confirm your password before you can do any manipulation to the two-step verification settings.

To enable, you simply pick the method of verification you want to use. KenyaTalk supports two “primary” verification methods:
[ul]
[li]Verification code via app - this will use an app on your phone (such as Google Authenticator or Authy) to generate a 6 digit code. This code changes every 30 seconds.[/li][li]Email confirmation - this will send a unique, one-time-use code to the email address associated with your account. This method is not preferred over the app-based verification because if an attacker has access to your account, they may also have access to your email. However, it’s certainly better than nothing.[/li][/ul]
To enable any method, you will need to go through the verification process to ensure that everything works as expected. This prevents you from being locked out by a system you didn’t successfully complete once.

You can enable multiple two-step verification methods.

The two-step verification “provider” system can be extended by third-party developers to add different methods (for example, YubiKey support, phone/text-based verification, etc).

There is also a third method that is automatically enabled when the first two-step verification provider is enabled: backup codes. These are designed to be saved for emergencies when you can’t verify your login through any other method (if you don’t have your phone, for example). Each backup code can be used once and you will be sent an email whenever a backup code has been used.

Two-Step Verification: Login

If you have enabled two-step verification, this covers logging in via the public-facing login.

https://xenforo.com/community/attachments/two-step-login-png.108814/

After verifying your password, if two-step verification is required, you’ll be taken to a page such as the one shown above. By default, the highest priority, currently enabled two-step verification method will be triggered. (The priority is set by the developer.) If you wish to use an alternative method, you can choose to do so for this login.

This also gives you the option to trust this device for 30 days. You may be familiar with this approach with other two-step verification systems. If you trust this device, you can log out and log in without being prompted to complete two-step verification for 30 days. This helps to mitigate the annoyance that two-step verification can create.

Once the 30 days are up, you will be prompted to complete the two-step verification again (even if you have chosen to stay logged in).

In the event that you want to stop trusting a device or you need to revoke that trust for other devices, you can do this from the two-step verification setup page in the account system:

https://xenforo.com/community/attachments/two-step-trust-png.108817/

Two-Step Verification: Losing Access

A common concern with two-step verification is what happens if you lose access to all of your two-step verification methods. We have attempted to mitigate that as much as possible.
[ul]
[li]Backup codes are really generated for this exact situation. If you lose your phone or your email is no longer valid, the backup codes will still work. However, this does require saving them once they’re generated. This is something that not all users will do.[/li][li]Disabling two-step verification only requires access to the password when you’re already logged in. If users choose to trust a device, this very likely means that they will still have access to their account. Once they verify their password, they’ll be able to change their two-step verification settings as necessary.[/li][li]Finally, admins can see the current two-step verification status and disable it if necessary:[/li]https://xenforo.com/community/attachments/two-step-admin-png.108813/
[/ul]

Password and Email Change Notifications

Beyond two-step verification, we also have other small account security-related features.

If your password is changed, you will receive an email to make you aware of this. Normally you can disregard this, but it serves to help notify you if someone is accessing your account and attempting to block your access to it.

Similarly, if your registered email is changed, you’ll receive an email (to the previous address) to make you aware of this.

Password Reset Process Changed

The password reset process is simplified and more user friendly and does not send a password via email. Once you receive the email for the password reset request, the link will allow you to set a new password directly. This is more in line with current approaches to password resetting in the industry.

2FA my ass, this ain’t my bitcoin wallet. P. S tl;dr.

1 Like

You should be more worried about breach of privacy by your own mods using back-end info rather than this irrelevant nonsense!

No one’s checking for anyone’s password here! Da fvck I’m gon’ do once I access anyone’s account? Steal their “likes”?

10 Likes

Summary mkubwa?

Hata bank account siambiangwi niweke hizi 2 step na hapo ndio pesa iko, huku je?

2 Likes

Mimi hapana taka hiyo…hata nimeshindwa kusoma yote

Hii account nitaprotect kushinda ATM ya nini brathe?

BOOOM:D:D:D:D

See you next month.

hii nitasoma monday. tl’dr

1 Like

Me thinks someone was trynna steal my likes though. My password got rejected several times. Got this message
[ATTACH=full]21798[/ATTACH]
Apparently my account got locked. A few minutes later, I used the previously rejected password and I was able to log in…just like that. Very strange.

2 Likes

Two-step verification for what?? let them steal all the accounts. they will have the most useless info ever…dummy email addresses filled with invites for HOT LADIES IN YOUR AREA WAITING FOR YOU RIGHT NOW…and a whole bunch of hekayas. Plus we have more robots than ashley madison.

[ATTACH=full]21814[/ATTACH]

3 Likes

Ive given you a like. ya backup just in case…

2 Likes

Someone kindly tell me how much my ktalk handle is worth. I may just decide to sell it.

1 Like

Not much… just keep selling your ass, you are better that way.

1 Like

By the way… who started all this?

Kacheze na nyonyo za wamanyonyo nugu hii.

Hii ni upus.wapi free xxx

1 Like

hehe mtafanya Michael Fowler a catch feelings

amekazana kuandika composition alafu _______________

1 Like