Bookapy.com is now 'ZBookStore.com'. Please update your bookmarks if you have any.
Hide
Home ยป Forum ยป Site Announcements

Forum: Site Announcements

Major Changes to the Login System and 2FA

Lazeez Jiddan (Webmaster)

Today I made some important changes to the log in system in order to enhance security.

Many may be happy to know that now WLPC's log in system supports TOTP (FINALLY).

For those who don't know what TOTP is, TOTP stands for Time-based One-Time Password. It is a type of two-factor authentication (2FA) method used to enhance the security of online accounts by generating temporary, one-time passwords based on the current time.

Usually you use either a third party authentication app like Google Authenticator or Authy (spit). Many password managers also handle TOTP like the Mac's password app/manager.

I deprecated the code-by-email 2FA due to the extreme email blocks that stand in our mail servers way and the low deliverability of such verification codes.

Codes are still used to verify email addresses during registration, but now not used for 2FA.

Those who have code-by-email set in their account, for now, it still works. But at some point you'll be prompted to switch to either personal security questions or TOTP.

Next I will implement support for Passkeys to allow for passwordless log in.

But for now TOTP is the big news.

To switch your account to TOTP 2FA, go to the 'My Account' page and click 'Update' next to security setting.

You can also follow this link:

https://storiesonline.net/sol-secure/user/my_account.php?cmd=secset

awnlee jawking ๐Ÿšซ

@Lazeez Jiddan (Webmaster)

Will dinosaurs like myself still be able to login with a password?

AJ

Lazeez Jiddan (Webmaster)

@awnlee jawking

It's all optional.

Email and password required as usual. That's it.

If you want more security, you can activate 2FA (TOTP or Personal Security Questions). TOTP would require an authenticator app. You can easily download Google Authenticator or KeyPass (open source) to your phone and use that if you wish. 2FA doesn't require a modern system.

2FA is a very good idea for authors who publish at bookapy, as money is involved.

If you want easier log in, and your browser supports it, then you will be able to create a passkey (not implemented yet). To create the passkey you would need your email and password and a browser that supports WebAuth. If your browser has a passkey for the site, then you won't be asked for your email and password, instead your browser will be asked for the passkey. Think of it as a securely stored cookie that doesn't expire, but you can delete it if you wish.

Replies:   awnlee jawking
awnlee jawking ๐Ÿšซ

@Lazeez Jiddan (Webmaster)

Thank you.

AJ

Michael Loucks ๐Ÿšซ

@Lazeez Jiddan (Webmaster)

Awesome news! Very much appreciated.

Also happy to see TOTP via email being disabled, as it's not secure (for those who wonder โ€” email is stored in plain text, not encrypted, in most instances; it's often transmitted in plain text as well)

Looking forward to passkey implementation!

Replies:   anim8ed
anim8ed ๐Ÿšซ

@Michael Loucks

Yep, best to think of email as a postcard. Anyone handling it can read it.

TMax ๐Ÿšซ

@Lazeez Jiddan (Webmaster)

You rock, thank you for updating the system.

Back to Top

 

WARNING! ADULT CONTENT...

Storiesonline is for adult entertainment only. By accessing this site you declare that you are of legal age and that you agree with our Terms of Service and Privacy Policy.


Log In