Enhancing Security: A Guide to Two-Factor Authentication (2FA)
|
Click play to LISTEN to the article below
|
At Our-Hometown Web Publishing, protecting your newspaper’s digital integrity is our top priority. To ensure your website remains secure against unauthorized access, we are introducing Two-Factor Authentication (2FA) for all backend dashboard logins.
What is 2FA?
Standard passwords can sometimes be guessed or stolen. 2FA adds a second layer of protection by requiring not just something you know (your password), but also something you have (your phone or email access).
How to Log In with 2FA
Once 2FA is active on your account, the login process will look like this:
- Enter Credentials: Log in with your username and password as usual.
- Verify Identity: You will be prompted to enter a 6-digit verification code.
- Submit: Enter the code from your email or app to gain access to the dashboard.
Your 2FA Options
You can choose the method that best fits your workflow from your user profile:
| Method | How it Works | Best For… |
|---|---|---|
| SMS (Text Message) | A code is sent directly to your mobile phone. | Convenience. The quickest way to log in without needing a specialized app. |
| Authenticator App | A code is generated on an app like Google Authenticator or Authy. | High Security. Works even if you don’t have cell service or a signal. |
| A one-time code is sent to your account’s email address. | Simplicity. Good for those who prefer not to use their personal phones. |
How to Set Up or Switch Your Method
You can update your security settings at any time:
- Log into your WordPress dashboard and go to Users > Your Profile.
- Scroll down to the OHT 2FA Settings section.
- Select your Preferred 2FA Method from the dropdown menu.
- If you choose SMS: * Enter your mobile number in the Phone Number field.
- Note: US numbers do not require +1; our system adds it automatically.
- By selecting this, you consent to receive security codes via text; message and data rates may apply.
- If you choose Authenticator App: * A QR code and manual setup code will appear. Scan this with your app. More details are provided in the next section.
- Click Update Profile at the bottom of the page to save your changes.



Setting Up an Authenticator App
If you choose the Authenticator App option for maximum security, follow these steps to link your device:
- Step 1: On your profile page, select “Authenticator App.” A QR Code and a Text Setup Code will appear on your screen.
- Step 2: Open your preferred app (Google Authenticator, Authy, etc.) on your smartphone.
- Step 3: Tap the “+” icon in the app and select “Scan a QR Code.”
- Step 4: Point your camera at your computer screen to scan the code.
- Note: If your camera isn’t working, you can manually type in the provided Setup Code instead.
- Step 5: Once the account “[Your Website]: username” appears in your app, enter the current 6-digit code into the confirmation box on your WordPress profile to verify the link.

Pro-Tips
- The 30-Second Rule: Authenticator codes refresh every 30 seconds. If the code is about to expire (usually indicated by a blinking red timer in your app), wait for the next code to ensure it doesn’t “time out” while you’re typing.
- Switching Back: If you ever lose your phone or find the app inconvenient, you can always log back in (using a backup method or admin help) and switch your setting back to Email.
Frequently Asked Questions
What if I don’t receive my SMS or Email code?
- Email: Check your “Spam” folder and whitelist
@our-hometown.com. - SMS: Ensure you entered your number correctly without the “+1” prefix. Codes usually arrive within seconds, but network delays can occur.
Which Authenticator apps do you recommend? We recommend Google Authenticator, Microsoft Authenticator, or Authy. All are free and available on the iOS App Store and Google Play Store.
Will I have to do this every single time I log in? You can check the “Remember this device” box during login. This will keep you authenticated on that specific browser for 30 days, so you won’t need a code every morning.

I’m locked out! What do I do? If you lose access to your phone or email, don’t worry. Please contact the Our-Hometown Support Team at ops@our-hometown.com for further assistance.
NOTE: Never share your 2FA code with anyone. Our-Hometown staff will never ask you for your 6-digit code over the phone or via email.


Recent Comments