viking272 wrote: Thu Jan 29, 2026 7:18 pm
Is it possible with phpBB to setup a once a month multi-factor authentication email?
That will protect legitimate users that are inactive, as they will need to authenticate using MFA.
Obviously if the email is hacked too then that presents a problem!
I'm not aware of it. I can force account reactivations, but a lot of people never changed from hotmail etc, so it wouldn't work
I did wonder on the way home, if the user in question password is compromised , the googlemail account could also be compromised.. If the user comes back, spamming again.. then what ? We have no choice but to ban that user.
Its all a bit of a problem, as all the "protections" for a forum are mostly for signup and new users. We get thousands of those every week. Its rare they get as far as signing up.
BUT, humans can sign up, its either to gain a reputation to get off the moderated list, then sometime later start spamming.. as we have seen recently. Or users passwords / accounts become compromised where they are already off the moderation list. Then start spamming.
Its one reason not allowing post edits past 2 days are a must.. If a few regular members accounts got hacked, and had thousands of posts, each one could be edited with spam.. it would destroy the forum very quickly. There is basically no protection, or moderation, for registered users.. That is what's worrying me right now..
I said earlier today in fact, normally when something like this happens, it opens the flood gates to similar happening.. thats whats worrying.. The only workaround is every single user on the forum gets moderated.. but that's a lot of work for the moderators then. Or fall back to a automated service like CleanTalk, but detection isn't perfect and its a bit slow for real time stuff. I think it would overall do more harm than good.
MFA could possible be done, but it would likely involve credit cards. Where for example they, make a £1 donation, so then chances are they are a legit user. But it doesn't solve the hacked accounts issue. It also would cause problems with those who don't have a credit card.
Also we been talking about scanning the database every day for typical spam stuff.. but its likely not going to be perfect either.
I've thought about multiple ways to deal with it all.. but as we are a small forum, I hope things won't progress any more.. and we can just depend on the community to keep itself safe. Then if it starts to become a fulltime job with spam, then more drastic type action will have to be taken..