Introducing Two-Factor Authentication

Joey
Dawnsong - Derpi er
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Lunar er - Helped forge New Lunar Republic's freedom in the face of the Solar Empire's oppressive tyrannical regime (April Fools 2023).
Flower Trio - Helped others get their OC into the 2023 Derpibooru Collab.
Roseluck - Had their OC in the 2023 Derpibooru Collab.
A Lovely Nightmare Night - Celebrated the 12th anniversary of MLP:FIM!
Cool Crow - "Caw!" An awesome tagger
Tree of Harmony - Drew someone's OC for the 2022 Community Collab
Elements of Harmony - Had an OC in the 2022 Community Collab
Non-Fungible Trixie -

PM me your cute OCs
Hello Everyone!
 
We are happy to announce the availability of Two-Factor Authentication (2FA) on Derpibooru! For those who don’t know, 2FA is an excellent way to help secure your against someone trying to access it without your permission.
 
Two-factor authentication works on the basis of generating a time-based one-time-use six digit code (known as a “one time ” or “OTP”), which is submitted alongside your when logging in. That way, if your is ever compromised (such as someone guessing it or you using the same on another site that got hacked), an attacker would still not be able to access your without your OTP.
 
To use two-factor authentication and generate one time s, you will need to install an authenticator app on your smartphone, such as Google Authenticator for Android and iOS. Then go to your page, and you will see a QR code. Scan that using your authenticator app, and then enter the “response” number it provides to confirm it is setup correctly and click “save”. Your will then be enabled for 2FA, and you will be given a list of “backup codes” which are not time-based, so that you can to the site still if your authentication app is unavailable.
 
It is very important to keep those backup codes in a safe place, because if your authenticator app ever becomes unavailable (such as if you lose your phone), you will not be able to to your and/or disable 2FA without them.
 
After two-factor authentication is setup on your , every time you , you will be prompted to enter your one time . Simply open your authenticator app, and enter the six digit code your app generates, and it will log you in. And if you ever need to, you can disable it via your page. If you do not have access to your authenticator app, you can use one of the backup codes you were provided.
 
Note that if you enable two-factor authentication on your , and then lose access to both your authenticator app and your backup codes (or if you don’t save your backup codes), we will not likely be able to help you regain access to your . So please, be very certain to keep your backup codes in a safe place (or two safe places) if you use this feature.
 
This is an optional feature, you do not need to enable two-factor authentication on your if you do not wish. Additionally, once it’s enabled you can disable it by going back to your settings and entering a OTP or backup code to disable it.
 
I would like to give a huge thank you to both DJDavid98 and MrMeow for implementing this feature on the site, as well as byte[] for testing and bug fixing.
 
Cheers!  
Joey
Jamie-P-Rose
Office Culture - These water cooler conversations sure get heated around here.
Fifth Yacht -
Bronze Trophy - Achievement Hunter
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Pixel Perfection - Hot Pockets Spotted
Lunar Guardian - Earned a place among the ranks of the most loyal New Lunar Republic soldiers (April Fools 2023).
Non-Fungible Trixie -
Preenhub - We all know what you were up to this evening~
My Little Pony - 1992 Edition
Wallet After Summer Sale -

Always Horny She/Her
Two-factor is BAD news. As someone who has worked as an apple tech rep I have had to tell people, sorry all your info is lost, because you have two-factor and lost access to your device/email and cannot get the reset code. I personally take a stand against any and all two-factor authentication s. Too much can go wrong with it to make it worth while.
Joey
Dawnsong - Derpi er
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Lunar er - Helped forge New Lunar Republic's freedom in the face of the Solar Empire's oppressive tyrannical regime (April Fools 2023).
Flower Trio - Helped others get their OC into the 2023 Derpibooru Collab.
Roseluck - Had their OC in the 2023 Derpibooru Collab.
A Lovely Nightmare Night - Celebrated the 12th anniversary of MLP:FIM!
Cool Crow - "Caw!" An awesome tagger
Tree of Harmony - Drew someone's OC for the 2022 Community Collab
Elements of Harmony - Had an OC in the 2022 Community Collab
Non-Fungible Trixie -

PM me your cute OCs
@Mike  
Any decent authenticator app would have a built in QR scanner. You don’t need to exactly read what the QR says, it’s just gonna be the information the authenticator needs to generate the OTPs specific to your .
 
@Jamin-P-Rose  
I mean, this is an optional feature, so you don’t have to use it. But at the same time, I personally wouldn’t form any opinions on a specific technology based on how Apple does it. They’re always form-over-function, so I imagine their specific implementation of 2FA is quite different from the standard.
Joey
Dawnsong - Derpi er
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Lunar er - Helped forge New Lunar Republic's freedom in the face of the Solar Empire's oppressive tyrannical regime (April Fools 2023).
Flower Trio - Helped others get their OC into the 2023 Derpibooru Collab.
Roseluck - Had their OC in the 2023 Derpibooru Collab.
A Lovely Nightmare Night - Celebrated the 12th anniversary of MLP:FIM!
Cool Crow - "Caw!" An awesome tagger
Tree of Harmony - Drew someone's OC for the 2022 Community Collab
Elements of Harmony - Had an OC in the 2022 Community Collab
Non-Fungible Trixie -

PM me your cute OCs
@JP  
Financial firms are always a bit slow to implement new technology. There’s so many regulations in place regarding banks that any change requires a ton of testing, compliance approval, justification, etc.
Background Pony #9279
Regarding not being able to if the backup codes are lost, would it be too much trouble to have some kind of “Answer these questions you yourself set up” backdoor or something? I’d probably never need it, but just saying that it doesn’t have to be a complete lost cause if that happens. Especially if the first needed to the s to even get to those questions.
Chaotic Mind
"I solemnly swear I am truly insane." - Derpi er
Daring Do Dakimakura - Attended a Derpibooru  at a MLP convention
Fifth Yacht -
Non-Fungible Trixie -
My Little Pony - 1992 Edition
Thread Starter - Started a thread with over 100 pages (Random Useless Facts Thread)
Wallet After Summer Sale -
Silver Bit -
Ruby -
Friendship, Art, and Magic (2018) - Celebrated Derpibooru's six year anniversary with friends.

Crazy Pone
I may fire the old google Authenticator app up again for this. I’m very security conscious and have had attempted attacks before due to things I best not say. Nothing bad I assure you.
WingbeatPony
Daring Do Dakimakura - Attended a Derpibooru  at a MLP convention
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Elements of Harmony - Had an OC in the 2022 Community Collab
Twinkling Balloon - Took part in the 2021 community collab.
My Little Pony - 1992 Edition
Wallet After Summer Sale -
Friendship, Art, and Magic (2019) - Celebrated Derpibooru's seventh year anniversary with friends.
Equality - In our state, we do not stand out.
Friendship, Art, and Magic (2018) - Celebrated Derpibooru's six year anniversary with friends.
Cool Crow - "Caw!" An awesome tagger

Tag horse
So I think there are a couple of things that makes this sound intimidating that the OP could address:  
  1. Clarifying this is an opt-in, not a mandatory change.  
  2. Expanding on the bit about disabling the feature, and similarly more detail on what to do should you need to use a backup code.  
  3. A link to a guide, or a short explanation here, of how to migrate the authentication to a new device, since upgrading/losing your phone is a much higher likelihood for a lot of people than having your credentials compromised.
Hmm. I discovered the 2FA option before this thread! ;3
 
As long as one knows how to fully and securely utilize this option, it’s a good way to protect one’s . And it works with 1 too.
Stake2
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Lunar er - Helped forge New Lunar Republic's freedom in the face of the Solar Empire's oppressive tyrannical regime (April Fools 2023).
Wallet After Summer Sale -
Artist -

Stake2
Oh this new feature is good, email otp or authentication is equally good and secure so you guys can implement it together with authentication app?
Joey
Dawnsong - Derpi er
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Lunar er - Helped forge New Lunar Republic's freedom in the face of the Solar Empire's oppressive tyrannical regime (April Fools 2023).
Flower Trio - Helped others get their OC into the 2023 Derpibooru Collab.
Roseluck - Had their OC in the 2023 Derpibooru Collab.
A Lovely Nightmare Night - Celebrated the 12th anniversary of MLP:FIM!
Cool Crow - "Caw!" An awesome tagger
Tree of Harmony - Drew someone's OC for the 2022 Community Collab
Elements of Harmony - Had an OC in the 2022 Community Collab
Non-Fungible Trixie -

PM me your cute OCs
@WingbeatPony  
Updated the OP, thanks!
 
@TNBi  
Yeah, I think it was added to the site on Thursday night so that we could do some last minute testing and tweaking.
 
@clopper from the future  
No it’s not. Imagine someone’s using the same for both this site and their email , and their gets compromised. If we used email-based 2FA, then an attacker would be able to compromise their OTP as well.
 
reuse is an incredibly dangerous thing to do, but sadly, a lot of people do it anyway.
LemonDrop
Duckinator - Same nonsensical quacks in every pond
Fifth Yacht -
Grass - ...has been touched
Diamond Trophy - Are you a TAS by any chance?
Nightmare in the Moon - Had their OC in the 2024 Derpibooru Collab.
Pixel Perfection - I still call her Lightning Bolt
Lunar Guardian - Earned a place among the ranks of the most loyal New Lunar Republic soldiers (April Fools 2023).
Crystal Roseluck - Had their OC in the 2023 Derpibooru Collab.
Elements of Harmony - Had an OC in the 2022 Community Collab
Non-Fungible Trixie -

C++ Crazed
@Joey  
If the is being used like that then that’s the ’s fault, there’s nothing stopping that same situation of negligence from applying to a mobile device as well. Just look at something like steam guard, that got along just fine for many years and it’s 2FA in that sense.
 
IMO I think this is pretty lame as just like many other 2FA features it excludes people like me who refuse to own a smartphone from a perfectly fine computer-based alternative like email.
Interested in advertising on Derpibooru? Click here for information!
My Little Ties crafts shop

Help fund the $15 daily operational cost of Derpibooru - us financially!

Syntax quick reference: **bold** *italic* ||hide text|| `code` __underline__ ~~strike~~ ^sup^ ~sub~

Detailed syntax guide