AuthMe / AuthMeReloaded

The best authentication plugin for the Bukkit/Spigot API!
https://www.spigotmc.org/resources/authmereloaded.6269/
GNU General Public License v3.0
616 stars 515 forks source link

REQUEST > Option for staff login #1137

Open AmazedMender16 opened 7 years ago

AmazedMender16 commented 7 years ago

Is there any possibility that there will be a second login option for staff members? like a pincode. or something.

Twonox commented 7 years ago

Now, there is only two options for login.

You want a global password ? If true, why want you that exactly ?

AmazedMender16 commented 7 years ago

I mean that people with sprcial perms or in a list have the default login but also a staff login. So its harder to get hacked

sgdc3 commented 7 years ago

A second layer authentication?

AmazedMender16 commented 7 years ago

Yes for staff members

ljacqu commented 7 years ago

If we take one step back, what problem are you trying to solve? Did one of your staff members get hacked?

When mentioning a staff login, do you mean that all users with that permission would need to enter the same password? That could be an interesting idea that would bring advantages. There's a good post about this on StackOverflow: Does an additional company-wide password offer any real security?

I'd be less for two individual passwords for certain players. I think then whoever on your staff was using a weak password will just use a second weak password, along the lines of "I can best remember my two passwords by just using minecraft1 and minecraft2".

In the end it's also important for you to educate your staff as well as your players. I think a lot of them are not really conscious of the fact that on an offline server, that one password they chose is the only thing that keeps their account safe. Staff members have the obligation to protect their account accordingly (but they need to be told so to be aware :smile:)

AndrewAubury commented 7 years ago

Mender i could do this for you, As we both know your server needs it