Skip to Main Content
GOb2b Ideas Portal
Status Shipped
Categories Security
Created by simon knagg
Created on Oct 16, 2024

Two Factor Authentication (2FA)

I propose adding two-factor authentication (2FA) as a feature for the Gob2b platform. This will enhance security by providing an extra layer of protection against common attacks like phishing and password breaches.

Benefits include:

  • Improved customer trust and brand reputation.

  • Compliance with security regulations (e.g., GDPR).

  • Competitive advantage by offering a more secure platform.

  • Prevents account takeovers even if passwords are compromised.

Various methods (SMS, email, authenticator apps) can be offered for flexibility, giving users more control over their security.

  • Attach files
  • Chris Turner
    Reply
    |
    Dec 19, 2024

    I would like it on the CMS by default as someone could do a lot of damage if they got access. I take on board however that not all users of the website may want it.

  • Admin
    Paul Dorey
    Reply
    |
    Nov 7, 2024

    We have considered extending this to Trade Purchasers and Retail Customers but have decided not to for the following reasons:

    • We are not convinced that 'trading' accounts for ecommerce websites need to to be protected to such a high degree compared to the administration accounts.

    • Extra security is another barrier to purchasing

    • 2 Factor resetting for changed phones, email addresses etc is a support burden on our customers

    • Complications around resetting 2FA could lead to an increased support burden on GOb2b

    We are prepared to keep an open mind on this if presented with Use Cases or examples of external demand from end customer organistions.


  • simon knagg
    Reply
    |
    Nov 7, 2024

    I have since had this added to the admin; I did mean for the end user too. Is this in the road map ?

  • Admin
    Paul Dorey
    Reply
    |
    Nov 4, 2024

    2FA is available in GOb2b providing you have had the jQuery V3 update rolled out (this has been done for all themed customers and 80% of bespoke template customers so far) Please contact support to have it turned on.

2 MERGED

Add 2FA to all logins - I gather this has already been dealt with in another post sorry

Merged
Someone could do a lot of damage if they got access to the CMS for example and this would help reduce this risk. Could possibly roll out in stages focusing on the CMS first and then adding to the customer side at a later date. NB: I have a really ...
Chris Turner 4 months ago in GOb2b General (If you are not sure!) / Security 0 Shipped