Homepage › Forums › Support › Announcements › Two-Factor Authentication – What It Is, Why It Matters
Tagged: 2 factor authentication, 2fa, safety
- This topic has 0 replies, 1 voice, and was last updated 1 month, 1 week ago by
conecshon.
-
Quick step-by-step summary
To enable 2FA
- Install an authenticator app
- Go to your account settings
- Scan the QR code
- Tick Active
- Enter your current password
- Save your settings
When logging in
- If you have enabled 2FA, enter the code from your authenticator app
- If you have not enabled 2FA, leave the authentication code field blank
Keeping your account secure is important for both you and the wider Conecshon community. One of the best ways to protect your account is by enabling Two-Factor Authentication, often shortened to 2FA.
This guide explains what 2FA is, why we recommend it, how to set it up, and what to do if something goes wrong.
What is Two-Factor Authentication?
Two-Factor Authentication adds an extra layer of security to your account.
Usually, logging in only requires two things:
- your username or email address
- your password
With 2FA enabled, there is one more step:
- a temporary authentication code from your authenticator app
This means that even if someone manages to get hold of your password, they should not be able to access your account without also having access to the code generated on your device.
In simple terms, it makes your account much harder for anyone else to get into. 2FA is much more secure than other authentication methods such as codes sent to your phone or email address, both of which can be hacked/intercepted. Your authentication app is installed on your device and needs a password, pin or biometrics to access.
Why should I enable 2FA?
We strongly recommend 2FA because it helps protect:
- your Conecshon account
- your personal profile information
- your messages and activity
- your privacy
- your connection to the community
Passwords can sometimes be guessed, reused, stolen, or exposed in data breaches on other websites. Even if you use a good password, 2FA gives you a valuable extra layer of protection.
It only takes a few minutes to set up, but it can make a big difference to your account security.
Do I have to use Google Authenticator?
No. Even though many people use and prefer Google Authenticator, you do not have to use that specific app.
You can use any compatible authenticator app, including for example:
- Google Authenticator
- Microsoft Authenticator
- Authy
- Proton Authenticator
- other compatible TOTP authenticator apps
So if you already use an authenticator app for something else, there is a good chance you can use the same one here too. However, this is not guaranteed, so please test out which one works for you.
What does an authenticator app do?
An authenticator app generates a short code, usually 6 digits long, that changes regularly.
When 2FA is enabled on your account, you enter that code when logging in. The code is only valid for a short time, which is what makes it secure.
You do not need a text message for this. The app generates the code directly on your device.
How do I set up 2FA on my account?
Please follow these steps carefully.
Step 1: Install an authenticator app
If you do not already have one, install an authenticator app on your phone or device.
Step 2: Go to your account settings
Open your account settings and go to the Two-Factor Authentication section at the bottom.
Step 3: Scan the QR code
Open your authenticator app and scan the QR code shown on the page.
This will add your Conecshon account to the app.
Step 4: Enable the setting
Tick the Active box to switch on two-factor authentication.
Step 5: Enter your current password
You will need to enter your current account password to save changes to your settings.
Step 6: Save your settings
Save the page.
Once this is done, two-factor authentication should be enabled for your account.
Very important warning
Please make sure you scan the QR code before saving your settings.
If you tick Active, save your settings, and then log out without scanning the QR code first, you may be locked out of your account because your app will not have the code needed to generate login codes.
So the safe order is:
- open your authenticator app
- scan the QR code
- tick Active
- enter your current password
- save your settings
Please do not skip the QR scanning step.
What happens after I enable 2FA?
After enabling it, logging in will work like this:
- enter your username or email address
- enter your password
- enter the current authentication code from your authenticator app
That extra step is what protects your account more effectively.
Do I always need to enter an authentication code when logging in?
No. You only need to enter an authentication code if you have enabled 2FA on your account.
If you have not enabled 2FA, you can leave the authentication code field blank.
So if you see that field on the login page, do not worry. It is only required for members who have set up two-factor authentication.
What if I enter the wrong code?
If the code is not accepted, a few common things may have happened:
- the code expired and refreshed to a new one
- the wrong account is selected in your authenticator app
- the time on your device is out of sync
- the QR code was not scanned correctly when setting up
If that happens:
- wait for the next code to appear
- try again carefully
- make sure you are using the code for the correct account
- check that your device time is set correctly
Sometimes simply waiting for a fresh code solves the problem.
What if I lose my phone or no longer have access to my authenticator app?
If you lose access to your authenticator app, you may not be able to log in to your account.
If this happens, please contact the site admin for help. We can confirm who you are and then remove the 2FA from your account until you can log in again.
Because of that, it is a good idea to:
- make sure your authenticator app is set up correctly before logging out
- keep your device secure
- use any backup, sync, or recovery options offered by your authenticator app where appropriate
Different authenticator apps handle backups differently, so it is worth checking the options in the app you choose. Conecshon strongly recommends Proton Authenticator as it is secure, private and synced across devices.
What if I get locked out?
If you are locked out because 2FA was enabled before the QR code was properly scanned, or because you no longer have access to your authenticator app, please contact the site admin.
We will help you regain access where possible.
What does “Relaxed mode” mean?
You may see an option called Relaxed mode.
This allows a little more tolerance if your device clock and the server clock are not perfectly in sync.
Most members will not need to change this. It is generally best to leave it as it is unless you are having repeated trouble with codes not being accepted.
Is 2FA difficult to use?
Not really 🙂
Once it is set up, it is usually very simple:
- open your authenticator app
- look at the current code
- type it into the login page
Most people find it easy after the first time. It may seem fiddly and unnecessary, but it’s a small price to pay for keeping your account secure.
Why are we recommending it?
Conecshon is a community site, and account security matters.
The stronger each account is protected, the safer the whole community becomes. Two-factor authentication helps reduce the risk of account takeover, protects your personal access, and adds peace of mind.
It is one of the most effective security improvements you can make with very little effort.
Final reminder
Please do not enable 2FA and then log out before scanning the QR code.
That is the easiest way to lose access to your account.
Scan first, then save.
Need help?
If you are unsure which authenticator app to use, have trouble setting it up, or lose access to your codes, please contact the site admin for help.
We would much rather help you set it up safely than have you locked out of your account later.
- You must be logged in to reply to this topic.
