Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Two Step WordPress Security

Kaspars
February 22, 2016

Two Step WordPress Security

From WordCamp Norway 2016.

Kaspars

February 22, 2016
Tweet

More Decks by Kaspars

Other Decks in Technology

Transcript

  1. • One “Master” Password • Password Generation • Password Auto-fill

    • Available on Desktop 
 and Mobile Use a Password Manager
  2. • One “Master” Password • Password Generation • Password Auto-fill

    • Available on Desktop 
 and Mobile Use a Password Manager Social Engineering
  3. You still have to type in 6 digits every time

    Two Step: One-Time Passwords
  4. Two Step: PKI Smartcards Have to use a SmartCard reader

    and install drivers on every computer Uses a secure element for all cryptographic functions
  5. FIDO Alliance Fast IDentity Online • Formed in 2012 to

    create 
 a new industry standard • Initially worked on a Password-less protocol • U2F started by Google, Yubico and NXP in 2011 and joined FIDO in 2013
  6. July 2015
 A feature plugin was approved for core.
 https://wordpress.org/plugins/two-factor/

    December 2015
 “We can’t have users lock themselves out” January 2016
 Decided to work only on Application Passwords to meet the 4.5 cycle (April 2016). Join #core-passwords on WordPress Slack! Two Step in WordPress Core