fierydragonlord wrote:
I don't use IP whitelisting because I don't have static IP addresses, and I would end up having to whitelist a whole bunch of IPs that would only be used temporarily. I do use two-factor authentication with Google Authenticator, though.
While this requires manual review, a list of recent login attempts (with geolocation for the IPs) is more useful that an IP whitelist for people with dynamic IP addresses.
--DragonLord
So? I use whitelisting and Google Authenticator (well, with Authy). And I tend to log in from various places depending on where I am. Is it hassle? Yes!
But security should be a hassle. Like I have a Yubikey - I never let it sit in my computer - I use it and take it back out.
To be frank, if it was all easy, and no hassle with security, I wouldn't trust the security. When you have to check your email for 20th time that day to get your current IP whitelisted or when you have to reach out for your phone to get the Google Authenticator code for the 25th time that day, that's when you start having decent security.
_________________
lakridserne
Serverfruit - shared and managed VPS hosting, SSL certificates and domains
Awesome servers rented from Linode!