New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments
I suppose I do have the forum to apologise to. So that works out.
MS LOL. Sad it doesn't have a number.
I wouldn’t do that, most of the forum are genuinely awful.
Too late now, Nekki
you don't enjoy the experience of scrolling past rehashed weeb content, pictures of busses, slightly entitled but at least extremely highendbrain commentary just to find out out you missed the deal or couldn't find it?
He should have limited his apology to the first 5 that responded with chrisfarleybusdriver.Jif
King Rejards,
-Geff
And that's why we are still here, right?
Oh yes, please don't think it's s complaint, it's simply a statement of fact.
I am shocked that you passed on the opportunity to call him twat there.
--
also you twat @TheBrokenBee don't fucking quote 817257817857817851785871785 lines please.
I feel a bit sorry for him, tbh.
Idk it was a nice summation. I didn't know what was going on and I still don't. Is a wheel still spinning when no busses are posted?
Maybe, it does have one, and it's 128, but we can never be sure
spin me @VirMach
Invoice 1321184
I just woke up from a dream where some twat was bad mouthing buses in this thread. Weird thing is that Nekki was there too, being civil.
ok just bf2021
Is anyone else seeing a change when you log in to your Virmach account.
For me it just goes to a page with:
and will not let me go anywhere else, other then to set up two factor authentication.
Is this now mandatory?
Spin
@VirMach
Order Number is: 8566746579
Thanks
Yeah, I'm seeing that too. It must be mandatory
Short answer, yes, since we added 2FA by email as an option. Too many accounts getting hacked. If we enable captcha on login, then there's other issues with China not being able to load Google Captcha. If we do Cloudflare captcha on the login, it's not as effective because I assume they can bypass hCaptcha to some degree already (plus if CloudFlare allows them to do anything for 30 minutes then it's pretty ineffective. Protect login option no longer works because WHMCS changed it to where it's a query in some cases and then it can be bypassed.)
We do have other protection(s) but it's not enough.
This mainly affects people with basic passwords that are not very secure and people who have their email/password combo on some third party database leak. We do have some idea of what it is but pretty much just go on https://haveibeenpwned.com/ and if your VirMach email and password are the same as any of these, it could be it. And it looks like the people bruteforcing have thousands of IP addresses in a botnet so it's difficult to protect against it. We're already at a point where customers get getting themselves banned from some of the protection so we can't lower it much.
If we get a lot of complaints or other feedback we can reconsider.
(edit) I wouldn't be opposed to allowing people to "remember" a device if I can find a module for it or if we can code something for it. That was the original idea, to only do it when there's an IP or cookie change.
(edit2) Oh and we're going to obviously evaluate what happens after this is enabled to see if the quantity of hacks goes down.
Honestly, I think it is time for all providers to enforce 2FA on all customer accounts.
With password managers like 1Password, LastPass, Bitwarden, etc you can easily set it up without much hassle (they auto-copy your 2FA codes in clipboard upon logging in). Duo can be another option.
ok then.
@ganonk I thought it was going to stop at some moment
My order :2698203457, thanks. spin me @VirMach
2FA forced?
Hell yeah! However RIP support.
is this why my one time code did not work last time and I had to move my ass and pickup phone for time based 2fa code?
Couldn't agree more. It's nearly 2022, whatever device you're using to get on the internet can do your 2FA easily. There's really no reason not to require it, people need to get used to it.
@VirMach please give it a spin thanks - 2978258466