Has Joomla replaced the MFA with Passkeys?

Discussion regarding Joomla! 5.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 5:05 pm

Hi there, i was searching for MFA to add to my super user account but i have noticed that is removed from the users>manage>user account and is replaced with Passkeys, is this true?

Thanks in advance

User avatar
Per Yngve Berg
Joomla! Master
Joomla! Master
Posts: 31093
Joined: Mon Oct 27, 2008 9:27 pm
Location: Romerike, Norway

Re: Has Joomla replaced the MFA with Passkeys?

Post by Per Yngve Berg » Fri May 17, 2024 5:08 pm

Passkeys have its own Tab in User Manager in addition to MFA.

hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Re: Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 8:20 pm

Hi, in J5? Because i cannot see it
Screenshot 2024-05-17 at 23.19.35.png
You do not have the required permissions to view the files attached to this post.

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12811
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Has Joomla replaced the MFA with Passkeys?

Post by brian » Fri May 17, 2024 8:36 pm

Is that your user account page? The MFA tab is only displayed on your own account.

If it is your user account page then check the plugins in the multifactorauth group. There must be at least one plugin enabled in that group

If you still can't see the tab then check the options for the users component and on the multifactorauth tab make sure that you have not set any groups where Disable Multi-factor Authentication
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Re: Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 8:48 pm

Yes this is from my super user account and all the extensions for MFA are enabled...
Screenshot 2024-05-17 at 23.47.38.png
You do not have the required permissions to view the files attached to this post.

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12811
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Has Joomla replaced the MFA with Passkeys?

Post by brian » Fri May 17, 2024 9:09 pm

is this a new install or an upgrade
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Re: Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 9:27 pm

Upgrade, but the issue was solved because a core plugin was disabled, thanks for your help mate!

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12811
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Has Joomla replaced the MFA with Passkeys?

Post by brian » Fri May 17, 2024 9:48 pm

Which plugin was it?
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/

hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Re: Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 9:54 pm

i disabled and enabled again those 2 plugins and worked
Screenshot 2024-05-18 at 00.53.23.png
You do not have the required permissions to view the files attached to this post.

hackermade
Joomla! Intern
Joomla! Intern
Posts: 92
Joined: Thu Jan 25, 2024 9:15 am

Re: Has Joomla replaced the MFA with Passkeys?

Post by hackermade » Fri May 17, 2024 9:58 pm

The only issue i noticed is that now i am required to use MFA for both the administrator and site sides, is possible to use the MFA only if i am logged in to the backend?

User avatar
brian
Joomla! Master
Joomla! Master
Posts: 12811
Joined: Fri Aug 12, 2005 7:19 am
Location: Leeds, UK
Contact:

Re: Has Joomla replaced the MFA with Passkeys?

Post by brian » Fri May 17, 2024 10:08 pm

The fixed code plugin should be disabled. It is only there as an example.
"Exploited yesterday... Hacked tomorrow"
Blog http://brian.teeman.net/
Joomla Hidden Secrets http://hiddenjoomlasecrets.com/


Post Reply

Return to “Security in Joomla! 5.x”