Royal Scottish Country Dance Society

Belfast Branch

Scottish Country Dancing in and around Belfast

RSCDS Belfast Branch

Passwords provide very weak securty and most can be cracked in a matter of seconds. To overcome this Multi Factor Authentication, or MFA as it is also known, is used on many websites. MFA is a security mechanism that us used to bolster security on websites, apps, and other internet services. 

You are not required to use MFA when logging into the RSCDS Belfast website but it is highly recommended.

The RSCDS Belfast website supports two types of MFA, Authenticator based and Email Code based.

 

Authenticator:

Authenticator based MFA is preferred as it is more reliable and secure, however to use this you need to install an Authenticatior App on your computer, smartphone or tablet. There are a number of free and paid authenticator apps available. Some password vault apps (e.g. 1password) also have authenticator capability built in.

Authenticator works by generating a new code every thirty seconds.  When you turn on MFA on a website you will be given a secret code (unique to you) and a QR code will be displayed.  You enter the secret code into your authenticator app (or scan the SQ code) and this synchronises your app with the website server. When you log into that website you just enter the code that is currently displayed on your app into the "verification" box on the website and click verify.

Authenticator verify

When you turn on Authentocator based MFA you will also get a set of backup codes. These can be used if something happens to your authenticator app (e.g. you lose or break your phone). You should print these codes out and put them somewhere safe.

Some suitable apps are:

  • 1Password - https://1password.com/ 
    • Paid - The current cost (November 2023) for personal use is about £2.50 per month.
    • This is the one that I use myself (Colin).
    • 1Password is a password vault.  It will securely store your passwords and fill them in (and the MFA code) for you when you log into a website.  It will also generate strong passwords when you sign up to new websites.
    • Synchronised across your devices, you can have it on your computer, phone and tablet.
  • WinAuth - https://winauth.github.io/winauth/download.html
    • Free
    • Only works on Microsoft Windows
  • Google Authenticator - Available from Google Play App Store
    • Free
    • Works on Android smartphones and tablets

Email Code:

Email Code based MFA does not require you to install an app however you do need to have access to your emails at the time you are logging into the website.

Whenever you log into the site, the system will generate a code and send you an email containing this code.  When you receive the email you just enter the code into the "Authentication Code" box and click verify.

Some email systems can identify these MFA emails as spam so you may need to check your spam folder for them. The code is also only valid for 2 miniutes so if there is a delay in you receiving the email you may need to try logging in again.