Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Contributor inthylight

    (@inthylight)

    Hi xarain,

    Thanks for the encouragement, we appreciate it.

    On your question, there are two things here:

    a) I’m not sure what you mean by #3 above. If you’d like to follow up on this, can you email [email protected] with the URL of the site in question, and we’ll take a look.

    b) There are many ways to handle the brute-force vector. Clef 2FA stops brute-force cold at the application layer (i.e., you don’t need Clef 2FA + captcha). Depending on your server setup, traffic volume, and security goals, it may make better sense to consider pre-application layers of defense rather than sorting out a plugin conflict between Clef 2FA and a captcha plugin; see the second half of this guide.

    Thread Starter xarain

    (@xarain)

    Hi Laurence,

    Sorry for my long winded posted. Basically what i am trying to say is If i found another site using CLEF and if i used my CLEF WAVE, while it rejects my login the login page (ID/PWD) will be shown to me which to me makes it less secure (kinda like guessing the backdoor URL address to login via ID/PWD)

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘WP Admin Page with CLEF’ is closed to new replies.