• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Two Factor Authentication

paul

Staff member
Founder
Administrator
Jul 20, 2000
7,488
2
8,493
Texas
www.talkbass.com
Beginning Feb 5th 2024 we will be requiring all members to enable two-factor authentication (2 factor verification) in order to log in. Two factor authentication consists of a secret 6-digit code that is provided to you after entering your username/password.

There are two options available: A 6-digit code can be emailed to you, or you can use an authenticator app (like Google Authenticator) to generate a code.

Both options are accessed in your Two Step Verification page in your account: https://www.talkbass.com/account/two-step

In both cases, your code will only need to be re-entered once every 30 days.

The rationale behind this decision is simply to protect all TalkBass members from bad actors. Lately these bad actors have taken over scores of TB accounts and posted bogus For Sale ads, ripping off innocent TB members.

Note that you will have to perform 2FA on each device that you use to access TalkBass (you'll be asked for a code on each device). Each device will remember the code for 30 days, unless cookies are cleared.

Thank you for your patience and understanding. If you have any issues, please don't hesitate to use the "contact us" link in the page footer to create a help ticket.
 
Last edited:
The apps seem to think my secret code is not long enough. And I can’t exactly scan the QR code when it’s on my phone’s screen. ?

Email it is for now.

Depending on which authenticator app you're using, there will be an option to enter a code manually to activate the 2FA in the app if you prefer to use an app. Email works fine too though.

-Mike
 
2FA is a serious annoyance for those of us who use multiple devices and multiple browsers.

On any given day, I might log in from my iPhone, my iPad, my PC (dual boot), or my laptop (also dual boot), and each one of them has at least three different browsers I might be using: Safari, Firefox, Chrome, or Orion, depending on the system.

I don't mind being forced to turn it on, but if I can't then turn it off, that's not very fun.

I use very strong randomized passwords on everything. I'm not worried about anyone breaking into my account.
 
2FA is a serious annoyance for those of us who use multiple devices and multiple browsers.

On any given day, I might log in from my iPhone, my iPad, my PC (dual boot), or my laptop (also dual boot), and each one of them has at least three different browsers I might be using: Safari, Firefox, Chrome, or Orion, depending on the system.

I don't mind being forced to turn it on, but if I can't then turn it off, that's not very fun.

I use very strong randomized passwords on everything. I'm not worried about anyone breaking into my account.
Ya, its a bummer to have this policy foisted upon us... But, the powers that be are doing it to protect us good guys. My bank (TD) has implemented policies that at first seemed a PIA, but, I grew to appreciate them, as they have ultimately protected me from the bad guys.
So, the bad guys have infiltrated our bass community.
We should thank the powers that be for being active/proactive before more damage is done.
It would seem that they are not just sitting on their asses, & wringing their hands in inaction.
For that, we should be thankful, despite the relatively small inconvenience.
I also say this in anticipation of cursing like a drunken sailor when my codes don't work!
 
Last edited:
Ya, its a bummer to have this policy foisted upon us... But, the powers that be are doing it to protect us good guys. My bank (TD) has implemented policies that at first seemed a PIA, but, I grew to appreciate them, as they have ultimately protected me from the bad guys.
So, the bad guys have infiltrated our bass community.
We should thank the powers that be for being active/proactive before more damage is done.
It would seem that they are not just sitting on their asses, & wringing their hands in inaction.
For that, we should be thankful, despite the relatively small inconvenience.
I also say this in anticipation of cursing like a drunken sailor when my codes don't work!

It would be fine if, instead of requiring 2FA, they simply enforced a robust password complexity policy, and offered 2FA as an option. I’m in Internet security, so I know the whats and whys of this.

I no longer know most of my passwords, because they are randomly generated and highly complex, and different for each site. I have to use a cross-platform password manager (Bitwarden, in my case) to remember them.

Ironically, I started this convo on one device, and picked it up on another, so I had to reauth.
 
It would be fine if, instead of requiring 2FA, they simply enforced a robust password complexity policy, and offered 2FA as an option. I’m in Internet security, so I know the whats and whys of this.

I no longer know most of my passwords, because they are randomly generated and highly complex, and different for each site. I have to use a cross-platform password manager (Bitwarden, in my case) to remember them.

Ironically, I started this convo on one device, and picked it up on another, so I had to reauth.
I'm just an anolog shmoe,
I'm just glad they're not complacent...
Maybe you could offer some suggestions to them!!??
They might be very grateful of input from someone in the biz/know!
 
why not just require special permissions to people who use the buy and sell? why does the entire membership have to deal with it? i dont use enough of this site to make it worth putting up with that nonsense. it's bad enough i have to do it to pay my freakin power bill, i'm not putting up with that nonsense so i can participate in the couple few threads i follow here. good luck in the future, it looks like once the authentication begins i'll be moving along.
 
It would be fine if, instead of requiring 2FA, they simply enforced a robust password complexity policy, and offered 2FA as an option. I’m in Internet security, so I know the whats and whys of this.

I no longer know most of my passwords, because they are randomly generated and highly complex, and different for each site. I have to use a cross-platform password manager (Bitwarden, in my case) to remember them.

Ironically, I started this convo on one device, and picked it up on another, so I had to reauth.
This is the way. I also use Bitwarden, myself. Apple users have a great tool for this built right into their OS too.

I’m part of a lot of forums and groups… TB is the only single-interest forum that is forcing 2FA… it’s ironic that this is ostensibly to protect classified users from getting ripped off just a little while after the mods decided to allow F&F payments. Who would have thought that removing protections would have made for a higher likelyhood of getting off? ;)
 
This is unfortunate, I've just tried to activate this and it turns out I can't remember my password. Not seeing any way to create a new one either

Tell me about it. When I first made this account, I just used the "login via twitter" function that seems to have been disabled a while ago, so my account doesn't have a password. Somehow, though (I blame sleep deprived stupidity in years past), I tied this to my old yahoo email account...which I haven't been able to log into for ages, and even though when last I could log into it I put my main email account as the recovery email for it, it never actually sends the recovery code or anything like it's supposed to. As I'm sure people can imagine, yahoo customer support has been less than helpful with that.

So I can't add a password without going through an email I can't get into, I can't change the email without having a password, and of course there's no way I'm able to log in without a password if I ever get logged out, let alone any of the new 2FA fun.
 
  • Like
Reactions: mikewalker
So I can't add a password without going through an email I can't get into, I can't change the email without having a password, and of course there's no way I'm able to log in without a password if I ever get logged out, let alone any of the new 2FA fun.
You’ve only been a member for a few years (2019) and have only 1 feedback rating. The fellow that you replied to is even younger, with an account started only in 2022 and has no feedback rating at all.

Y’all lose almost nothing if you just create a new account and set it up correctly from the start. This is a non-issue for you and others in your situation.
 
  • Like
Reactions: /\/\3phist0