You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Two-factor authentication enables you to add an extra layer of protection from getting your account compromised. You can set up two-factor authentication using any device capable of generating Time-based One-Time Password (TOTP) authentication codes (RFC-6238) to log in to your HackerOne account. You can use Google Authenticator or Duo Mobile or any other compatible application to generate the codes.
7
+
Two-factor authentication (2FA) enables you to add an extra layer of protection from getting your account compromised. You can set up two-factor authentication using any device capable of generating Time-based One-Time Password (TOTP) authentication codes (RFC6238) to log in to your HackerOne account. You can use Google Authenticator or Duo Mobile or any other compatible application to generate the codes.
8
8
9
9
To set up two-factor authentication for your account:
10
10
1. Go your profile’s **Settings > Authentication**.
@@ -23,13 +23,13 @@ To set up two-factor authentication for your account:
23
23
Once your two-factor authentication is successfully enabled, you’ll be prompted to enter a 6-digit verification code from your authenticator app to log in to your HackerOne account.
24
24

25
25
26
-
You can choose to change your account recovery phone number, turn off two-factor authentication or regenerate your backup codes.
26
+
You can choose to change your account recovery phone number, turn off two-factor authentication, or regenerate your backup codes.
27
27

28
28
29
29
Once your two-factor authentication has been verified, when you log in to HackerOne, you’ll be prompted to enter a 6-digit verification code from your authentication application. You must enter the verification code in order to successfully log in to HackerOne.
30
30
31
-
On your user management settings, under <b>Settings > General > User Management</b> you'll be able to see those with 2FA off and on. Users with **N/A**means that they have 2FA through a 3rd party. Most triagers will have a 2FA status of N/A because they use SSO through Okta.
31
+
On your user management settings, under <b>Settings > General > User Management</b>, you'll be able to see those with two-factor authentication on or off via the 2FA column. Users with **N/A**mean that they are authenticating via Single Sign-On (SSO) using a third-party identity provider. For example, HackerOne Security Analysts will have a 2FA status of N/A because they use SSO.
32
32
33
33

34
34
35
-
><i>Note: Two-factor Authentication is on a per-user basis. You can’t have single-source sign-on (SSO) and 2FA simultaneously.</i>
35
+
><i>Note: Two-factor Authentication is on a per-user basis. You can’t have SSO and 2FA simultaneously.</i>
0 commit comments