WP Admin Page with CLEF
-
Hi Team,
First, congrats on comming up with such a cool app π
Here is my question / concern:
1. Our WP login is secured with a captcha to mitigate brute force attacks.
2. With CLEF, having a captcha is pointless since all a valid user has to do is to scan his/her phone to login (this is a good thing)
3. With CLEF, you can force users to only use the ‘clef wave’ while tucking away the login/password URL in a safe location. (this is a good thing too)
3. However, I notice that if i login as an “unauthorized user” who has a CLEF app , it accepts my credentials but it then shows me the login page. (and my captcha is gone) Hence how can we mitigate such a scenario as this brings us back to be open to brute force attacks? Ideally it should reject the user and not show the login page.Thanks.
The topic ‘WP Admin Page with CLEF’ is closed to new replies.