• There has been a recent cluster of spammers accessing BARFer accounts and posting spam. To safeguard your account, please consider changing your password. It would be even better to take the additional step of enabling 2 Factor Authentication (2FA) on your BARF account. Read more here.

Issue with email 2 step verficiation

bojangle

FN # 40
Staff member
Super Moderator
Joined
Jun 10, 2008
Location
Bay Area
Moto(s)
Kawasaki Versys 1000LT,
Work: BMW R1250RT-P
Prior: Honda 600RR Graffiti, Kawi 650R
Name
D
So I think this is the same for everyone on barf. Barf requires 2 step verification by email or authenticator app, and it requires this again every 30 days. I had mine set up for email since this requirement went into effect, and up until now, have never experienced an issue with it.

Over the last couple days, my access to barf on my tablet required a new log in and authentication. The issue is, I never received the verification code to my email. And yes, I definitely checked the junk email folder. I tried a few times, and on different days, and was unable to get a code emailed, which effectively locked me out of barf on the tablet, though I was still logged in on my phone.

Anyways, I downloaded the Google Authenticator App and was able to get logged back in just fine. The reason for the email is just to put out the word that something might possibly be broken on the barf end, and other users might start experiencing the same issue, if something is preventing barf from sending out 2 step verification code emails.
 
I am doing Email V too. No issues.

I am sure getting frustrated with the world thanks to spammers and hackers that should be burning in hell.

I will add in the Corp overlords that keep thinking they are making shit better and it is not. Might be better for their bottom line, but not us.
 
2 factor on barf??? Have never experienced this.
 
Just curious...
1) Does Xenforo notify you and/or BARF Admins of malicious activity and is it identified as a user account being compromised?
2) Are these user account hacks a result of a social engineering / phishing exploit on the user? The user using a common
password across several of their accounts and one of their accounts on another web site was whacked first?
3) Is BARF running the current version Xenforo. Looks like they have released a new version 2.3.9 with security fixes.
At the bottom of BARF pages it identifies only this: "Community platform by XenForo © 2010-2024 XenForo Ltd.
 
Just curious...
1) Does Xenforo notify you and/or BARF Admins of malicious activity and is it identified as a user account being compromised?
2) Are these user account hacks a result of a social engineering / phishing exploit on the user? The user using a common
password across several of their accounts and one of their accounts on another web site was whacked first?
3) Is BARF running the current version Xenforo. Looks like they have released a new version 2.3.9 with security fixes.
At the bottom of BARF pages it identifies only this: "Community platform by XenForo © 2010-2024 XenForo Ltd.
  1. @budman and the mods are more experienced in reviewing that.

  2. It's hard to tell the "why" on something like a social engineering or phishing attack. This is simply that we don't have the intel to deduct that. And there's really no value to the forum to triage what a random internet user did to get themselves pwned. Sharing an easy password across multiple web platforms is not a smart philosophy. Many websites are compromised all the time, and user credentials are often widely published, so yes a "hacked" account could be tested on BARF.

  3. I don't see myself divulging that information in this setting. Goal #1 is keeping BARF running as well as possible at all times. We went through a lengthy period of time where VBulletin was running like complete garbage. We lost a significant amount of the user base and site traffic due to this. Steps are now taken to ensure that doesn't happen again.
 
1. We have no clue on user accounts.
2. The hackers hit older account created before the Xenforo update. So no 2 factor for sure.
3. Not looking to update but then again I have zero clue on security stuff.
 
2 factor on barf??? Have never experienced this.
That's interesting. Barf has required this since the upgrade. I just tried to opt out when I was having this issue and it would not let me.

Every 30 days it makes me log back in with user name, password, and 2FA. It doesn't do this for you?
 
I can't post on SVRiders.com anymore because I never get the e-mail code.
Been several years. Mods don't even respond to DMs.
Making the web more and more useless.
 
I can't post on SVRiders.com anymore because I never get the e-mail code.
Been several years. Mods don't even respond to DMs.
Making the web more and more useless.
Is that a Vertical Scope Forum?
 
That's interesting. Barf has required this since the upgrade. I just tried to opt out when I was having this issue and it would not let me.

Every 30 days it makes me log back in with user name, password, and 2FA. It doesn't do this for you?
IIRC, only mods and admins had 2FA enforcement turned on. It would be good if everyone turned it on, but making it mandatory would cause a lot of headaches initially.

A common way for BARF accounts to be compromised is when a user was compromised somewhere else and uses the same password on BARF. We had a fairly high frequency of that a year or so ago and that was when I posted the sticky encouraging people to turn on 2FA. The best way [1] to avoid your account being hacked is still to use a unique password on the site, along with 2FA.

[1] "The best way," in this case means the best way available with this platform currently. On systems that support them, phishing resistant credentials such as passkeys or hardware security keys are a better option.
 
Don't recall anymore. The one that bought out all the moto forums at the time, so probably.
They may have an outbound node on a blacklist or two and just don't care.
 
"Issue with email 2 step verficiation"

Can be a real hassle. For an example, to log into one of my emails, it sent a code to my other email. I try go to the other email to get the code, but it wants to do the same to log in with the email I was trying to log into to begin with.

So I then have two email systems that I cannot use because of the two step verification. This BS is getting ridiculous, IMO.
 
One of my credit card providers requires 2FA to see my account online. Its asks me to choose email or text to get the code. For three months- the code never arrives.
 
when 2fa was rolled out after the upgrade, i went the Authenticator route, and it's been fairly painless, other than the "remember for 30 days" means i get hit with the 2fa prompt pretty often across the 5 devices (phone, tablets, desktop, and laptop).
 
Back
Top