{"id":666,"date":"2018-05-22T14:55:18","date_gmt":"2018-05-22T14:55:18","guid":{"rendered":"http:\/\/blog.mozilla.org\/services\/?p=666"},"modified":"2018-05-24T15:44:08","modified_gmt":"2018-05-24T15:44:08","slug":"two-step-authentication-in-firefox-accounts","status":"publish","type":"post","link":"https:\/\/blog.mozilla.org\/services\/2018\/05\/22\/two-step-authentication-in-firefox-accounts\/","title":{"rendered":"Two-step authentication in Firefox Accounts"},"content":{"rendered":"<h3>Two-step authentication in Firefox Accounts<\/h3>\n<p>&nbsp;<\/p>\n<p>Starting on 5\/23\/2018, we are beginning a phased rollout to allow Firefox Accounts users to opt into two-step authentication. If you enable this feature, then in addition to your password, an additional security code will be required to log in.<\/p>\n<p>We chose to implement this feature using the well-known authentication standard <a href=\"https:\/\/en.wikipedia.org\/wiki\/Time-based_One-time_Password_algorithm\">TOTP<\/a> (Time-based One-Time Password). TOTP codes can be generated using a variety of authenticator applications. For example, Google Authenticator, Duo and Authy all support generating TOTP codes.<\/p>\n<p>Additionally, we added support for single-use recovery codes in the event you lose access to the TOTP application. It is recommend that you save your recovery codes in a safe spot since they can be used to bypass TOTP.<\/p>\n<p>To enable two-step authentication, go to your Firefox Accounts <a href=\"https:\/\/accounts.firefox.com\/settings\">preferences<\/a> and click \u201cEnable\u201d on the \u201cTwo-step authentication\u201d panel.<\/p>\n<p><a href=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/open_menu.gif\"><img decoding=\"async\" loading=\"lazy\" class=\" wp-image-667 aligncenter\" src=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/open_menu.gif\" alt=\"\" width=\"225\" height=\"368\" \/><\/a><\/p>\n<p>Note: If you do not see the Two-step authentication panel, you can manually enable it by following these <a href=\"https:\/\/support.mozilla.org\/en-US\/kb\/secure-firefox-account-two-step-authentication\">instructions<\/a>.<\/p>\n<p>Using one of the authenticator applications, scan the QR code and then enter the security code it displays. Doing this will confirm your device, enable TOTP and show your recovery codes.<\/p>\n<p><a href=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/save_2fa.gif\"><img decoding=\"async\" loading=\"lazy\" class=\" wp-image-668 aligncenter\" src=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/save_2fa.gif\" alt=\"\" width=\"265\" height=\"468\" \/><\/a><\/p>\n<p>Note: After setup, make sure you download and save your recovery codes in a safe location! You will not be able to see them again, unless you generate new ones.<\/p>\n<p>Once two-step authentication is enabled, every login will require a security code from your TOTP device.<\/p>\n<p><a href=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login.png\"><img decoding=\"async\" loading=\"lazy\" class=\"size-medium wp-image-669 aligncenter\" src=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login-252x328.png\" alt=\"\" width=\"252\" height=\"328\" srcset=\"https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login-252x328.png 252w, https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login-768x999.png 768w, https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login-600x780.png 600w, https:\/\/blog.mozilla.org\/services\/files\/2018\/05\/2fa_login.png 918w\" sizes=\"(max-width: 252px) 100vw, 252px\" \/><\/a><\/p>\n<p>Thanks to everyone that helped to work on this feature including UX designers, engineers, quality assurance and security teams!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Two-step authentication in Firefox Accounts &nbsp; Starting on 5\/23\/2018, we are beginning a phased rollout to allow Firefox Accounts users to opt into two-step authentication. If you enable this feature, then in addition to your password, an additional security code &hellip; <a class=\"go\" href=\"https:\/\/blog.mozilla.org\/services\/2018\/05\/22\/two-step-authentication-in-firefox-accounts\/\">Continue reading<\/a><\/p>\n","protected":false},"author":1558,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[41992],"tags":[41994,42008],"_links":{"self":[{"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/posts\/666"}],"collection":[{"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/users\/1558"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/comments?post=666"}],"version-history":[{"count":0,"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/posts\/666\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/media?parent=666"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/categories?post=666"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.mozilla.org\/services\/wp-json\/wp\/v2\/tags?post=666"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}