Announcement

Collapse
No announcement yet.

Passwordless login for vBulletin

Collapse
X
Collapse
First Prev Next Last
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Passwordless login for vBulletin

    I used ChatGPT to help me to translate from swedish to english. Hope it is okey. The idea is good

    -----

    The idea is to implement a passwordless authentication system for vBulletin, enhancing user convenience and security. The process begins when a user enters their email address on the login page. Instead of using a traditional password, the system generates a unique, secure token and sends it to the user's email. This token is embedded in a link. When the user clicks on this link, the token is verified by the server, and upon successful verification, the user's browser is authenticated.

    This system employs two key components: email verification and token-based authentication. The token is time-sensitive, adding an extra layer of security, and each token is uniquely tied to the user's email address and login session. Once authenticated, the user's session is stored either using browser cookies or server-side sessions in PHP. This ensures that the user remains logged in, even if they restart their browser or computer.

    Integrating this with vBulletin would involve modifying the existing authentication flow. The custom script would intercept the login process, replacing the password field with this token-based method. Furthermore, the system is designed to be flexible enough to work on non-vBulletin pages as well, making it a versatile solution for a website that uses vBulletin for its forum but also has other non-forum pages.

    Implementing this feature would not only streamline the login process but also enhance security, as it eliminates the risks associated with password theft or misuse. It's a modern approach to user authentication, aligning with current web security best practices.

    #2
    That's a good idea for a mod. But email is not secure. If a hacker intercepted your email, then they would be able to login to the forum you were attempting to sign in to.

    The more secure authentication that also doesn't require a password is using Passkeys (fingerprint, face id, etc). See this demo for more details:

    Try a Realistic Passkey Demo Login and User Profile. Browse the Passkey Directory and Find Websites With Passkey Support. Learn About Device Compatibility and Technical Details.


    I'm currently implementing this at my work website.
    Helpful? Donate. Thanks!
    Buy me a coffeePayPal QR Code
    Fast VPS Host for vBulletin:
    A2 Hosting & IONOS

    Comment


      #3
      Google is already using Passkey authentication. I recommend using it to your Google accounts for easy and secure login.
      Helpful? Donate. Thanks!
      Buy me a coffeePayPal QR Code
      Fast VPS Host for vBulletin:
      A2 Hosting & IONOS

      Comment


        #4
        I do not want login with third-party like Google. My forum is in Europe that is more restrictive.

        usernamen and password (with ability to reset password) sounds as (un)secure as mail and token? I still think it is a good idea. My users login is not to anything secret, only forum about aquarium fishes.

        Slack uses it for example

        Comment


          #5
          Passkey authentication is not a third-party login provider. I just mentioned Google as an example who implemented the Passkey login method to their website.
          Helpful? Donate. Thanks!
          Buy me a coffeePayPal QR Code
          Fast VPS Host for vBulletin:
          A2 Hosting & IONOS

          Comment


            #6
            How would one sign on using a device that is not theirs with passkey? Would you have to go back to the old school way?

            Comment


              #7
              You could set up another Passkey for that device if you want. You can have multiple passkeys for a site if you use different devices to access the site.
              Helpful? Donate. Thanks!
              Buy me a coffeePayPal QR Code
              Fast VPS Host for vBulletin:
              A2 Hosting & IONOS

              Comment


                #8
                Or you don't have to set up another Passkey for that device by scanning a passkey QR code using your phone that already has a passkey set up for that site.

                Btw, I have filed a feature request to vB. Please vote for it.



                Helpful? Donate. Thanks!
                Buy me a coffeePayPal QR Code
                Fast VPS Host for vBulletin:
                A2 Hosting & IONOS

                Comment

              Users Viewing This Page

              Collapse

              There is 1 user viewing this forum topic.

              • Guest Guest

              Latest Posts

              Collapse

              Working...
              X
              Searching...Please wait.
              An unexpected error was returned: 'Your submission could not be processed because you have logged in since the previous page was loaded.

              Please push the back button and reload the previous window.'
              An unexpected error was returned: 'Your submission could not be processed because the token has expired.

              Please push the back button and reload the previous window.'
              An internal error has occurred and the module cannot be displayed.
              There are no results that meet this criteria.
              Search Result for "|||"