{"id":111,"date":"2010-06-11T14:13:45","date_gmt":"2010-06-11T13:13:45","guid":{"rendered":"https:\/\/www.onverify.com\/blog\/?p=111"},"modified":"2024-11-15T07:35:30","modified_gmt":"2024-11-15T07:35:30","slug":"how-to-add-two-factor-authentication-to-your-web-site-using-phone-verification-by-onverify-com","status":"publish","type":"post","link":"https:\/\/www.onverify.com\/blog\/2010\/06\/11\/how-to-add-two-factor-authentication-to-your-web-site-using-phone-verification-by-onverify-com\/","title":{"rendered":"How to add two factor authentication to your web site using phone verification by onverify.com"},"content":{"rendered":"<p>Securing a web business has never been hard as now. As a web business owner or developer, you may have added several mechanisms to combat hacker from stealing passwords. To access a membership site, you probably implemented username and password checking together with several anti-hacker solutions, like checking last ip, checking logs for suspicious activity, etc. But still passwords, shared computers, passwords in e-mail are your weakest part in overall security.<\/p>\n<p>I want to show how you can add more security to your web site, as a general algorithm. In my example, I will point to phone verification, but it&#8217;s also possible to do it with reverse phone verification or sms verification.<\/p>\n<p>Your current flow is possibly as this way, providing you a one point to check the user<\/p>\n<ol>\n<li>Display login form<\/li>\n<li>Get username and password<\/li>\n<li>Check username and password from database<\/li>\n<li>If matches, give access<\/li>\n<\/ol>\n<p>I do not suggest you to change this flow, it will be same. But I will suggest you to add another step, to get a two factor authentication with otp (One Time Password) tokens, tokens to be announced on the phone:<\/p>\n<ol>\n<li>Display login form<\/li>\n<li>Get username and password<\/li>\n<li>Check username and password from database<\/li>\n<li>If matches, start a phone verification to the number on file<\/li>\n<li>Ask for the &#8220;token&#8221;\/&#8221;pin&#8221; that&#8217;s announced on the phone<\/li>\n<li>Check entered pin<\/li>\n<li>If matches, let the user access<\/li>\n<\/ol>\n<p>With this method, you&#8217;ll have a real two factor authentication and a second password token that is generated on the fly; cannot be stolen by a third party.<\/p>\n<p>Check out a live <a href=\"http:\/\/www.onverify.com\/\">Phone Verification<\/a> Demo at onverify.com. Drop us an e-mail to get ideas, and implementations. We like to hear and help.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Securing a web business has never been hard as now. As a web business owner or developer, you may have added several mechanisms to combat hacker from stealing passwords. To access a membership site, you probably implemented username and password<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/www.onverify.com\/blog\/2010\/06\/11\/how-to-add-two-factor-authentication-to-your-web-site-using-phone-verification-by-onverify-com\/\">Read more <span class=\"screen-reader-text\">How to add two factor authentication to your web site using phone verification by onverify.com<\/span><span class=\"meta-nav\"> &#8250;<\/span><\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_robots_primary_cat":"","footnotes":""},"categories":[6],"tags":[43,45,68,184,7,8,67],"class_list":["post-111","post","type-post","status-publish","format-standard","hentry","category-phone-verification","tag-one-time-password","tag-otp","tag-password-token","tag-phone-verification","tag-reverse-phone-verification","tag-sms-verification","tag-two-factor-authentication"],"_links":{"self":[{"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/posts\/111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/comments?post=111"}],"version-history":[{"count":3,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/posts\/111\/revisions"}],"predecessor-version":[{"id":114,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/posts\/111\/revisions\/114"}],"wp:attachment":[{"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/media?parent=111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/categories?post=111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.onverify.com\/blog\/wp-json\/wp\/v2\/tags?post=111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}