enTrail

Platform

Two-factor Beta

A time-based code from an authenticator app, enrolled by scanning a QR code on the page. No SMS, no emailed codes at sign-in, no third-party identity provider.

Who needs one

Enrolling

  1. Enter your password again, even though you are signed in.
  2. A QR code appears. It belongs to that browser session and to nobody else.
  3. Scan it with any authenticator app.
  4. Type a current code to confirm. Until you do, nothing is stored against your account.

The page carrying the code is never cached, the image is drawn on the server as a plain picture with no script, and the key is never written to a log.

Why a QR code and not an emailed link

An earlier design emailed a set-up link, which had one real advantage: someone who had stolen only your password could not add their own authenticator, because they would also need your inbox. Scanning on the page is easier, and it gives that up.

So the protection changed from prevention to detection, and we would rather say so than let you assume otherwise. Every authenticator added is announced to your email. If you receive that message and it was not you, the password is compromised: ask an admin to reset the factor and change it. The exposed window is between a password being set and the first enrolment, which is why admins must enrol immediately.

Codes and guessing

Codes are limited to five attempts per fifteen minutes per user, and the same limit applies to the password check that guards enrolment. Every failure gives the same answer, so nothing tells an attacker which part was wrong.

Replacing or losing an authenticator

What this does not cover

Two-factor protects sign-in by a person. It is not what protects your events: those are authenticated with project keys, described in send events. Rotate a key when someone leaves, and disable their account too.