We had enforced password reset on all accounts a couple of years ago but if the users' email account itself gets compromised then there is very little that can be done. Have again enforced password reset for accounts which have not logged in after 1st November 2024.
Perfect!
Is there a way this can be automated?
That way we wouldn't have to rely on manual intervention ever so often.
Something like as soon as account go inactive for 6 months or 1 year, their passwords are reset automatically.
This has been the most requested feature from that 3070 thread in light of the recent scam.
Maybe something that can be looked into after we migrate to the new platform!
Cannot enforce 2FA on all accounts as that is a personal choice.
This however is something that I disagree with.
I think it should be mandatory. Not just here, but everywhere.
Many people don't follow security best practices.
They'll use the same password everywhere if they can get away with it.
And since we cannot enforce changing that habit, maybe we can enforce something that is under our jurisdiction and can help mitigate issues stemming from it.
2FA would also prevent unauthorized entries to TE if users' emails are broken into, which is an additional benefit imo!
I also feel like 2FA setup has certain inertia that once overcome, results in a good habit that everyone maintains.
Case in point, my parents.
Old. Technologically averse.
When I set up 2FA on their most important accounts, they complained a lot about the additional step.
But soon, they got used to it.
And once they did, it wasn't as much of a hassle as it used to be for them.
Afterwards, they started using 2FA on all their new signups as well just because that initial inertia of using a new thing was overcome.
Hoping everyone uses 2FA on their emails is just that, a hope.
If we can do something concrete to change their habits, we should.
Especially with something we can control, like sign ins to this forum.
And besides, we are a technologically focused forum. If we aren't at the forefront of security best practices, then who else.
And in 2025, 2FAs are a security best practice, not merely a suggestion.
Maybe this would make individuals on this forum who still haven't set up 2FA get over from their inertia of it and open them up for 2FAs on their other accounts as well, as it did for my parents.
Besides, while I realize that the marketplace is not the main motivation of this forum, it is still a part of it.
And every scam there sullies the name of TE by being associated with it bit by bit, which I'm sure none of us want.
With mandatory 2FA, we can cut down on a certain type of scam that was recently perpetrated.
I totally get not trying to make it work with Xenforo since we're moving away from it, but I strongly feel that we should mandate 2FA for all accounts once we migrate to the new platform for the reasons I've mentioned above.
It would be the most opportune time for it.
Don't get me wrong though, I don't want to impose anything on the running of this forum.
I think you lads are doing a pretty darn good job already.
I'm just offering some suggestions as a user, and as someone who wants TE to prosper.