Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Brute force - login solution

    Scheduled Pinned Locked Moved pfSense Packages
    4 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U Offline
      UnderCover
      last edited by

      here is a possible solution to integrate into the login

      http://www.phonefactor.com it is free and basically once the username and password is authenticated it will send a phone call to you and ask you to hit the pound sign.  Obviously if you are not trying to login and you get a phone call then you know someone has a username and password and they will not be able to get in without you hitting the pound sign on the phone.

      what do you think?

      1 Reply Last reply Reply Quote 0
      • ? This user is from outside of this forum
        Guest
        last edited by

        Commercial software, not BSD licensed so no.  I don't see this happening ever, assuming there was even a FreeBSD port.

        1 Reply Last reply Reply Quote 0
        • U Offline
          UnderCover
          last edited by

          @submicron:

          Commercial software, not BSD licensed so no.  I don't see this happening ever, assuming there was even a FreeBSD port.

          I was just giving it as an option.  The software issue is there is none.  If you look they have some sample code for a php script to get it to work with there systems.

          But I do understand the licensing.  The free version is there for anyone who wants to use it.

          1 Reply Last reply Reply Quote 0
          • Cry HavokC Offline
            Cry Havok
            last edited by

            But free doesn't mean that it can be used in an open source project.  There's a world of difference between free, GPL<versionx>, BSD, MPL, etc.

            Plus, frankly, if you switched to using key only logins, it wouldn't be a problem as the attacker would need both your private key and your passphrase.</versionx>

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.