[WordPress] 外掛分享: UFP Identity

首頁外掛目錄 › UFP Identity
WordPress 外掛 UFP Identity 的封面圖片
30+
安裝啟用
尚無評分
4198 天前
最後更新
問題解決
WordPress 3.5+ v2.2.3 上架:2013-11-27

內容簡介

UFP Identity 是專為電商網站、設計公司和開發人員創建的動態安全平台,可以簡化登錄驗證過程。

只要有令牌,我們都支援。UFP Identity 支援多種安全令牌,可實現更快速、更便捷地訪問網站,同時保護用戶帳戶不被入侵,防止垃圾註冊網站。

我們的挑戰

UFP Identity 的目標是解決一個巨大的技術挑戰:保護線上用戶的個人資訊,使訪問多個網站變得非常容易,防止不良分子入侵。

我們的技術平台包括:

最強大的密碼驗證和加密!
防止垃圾郵件註冊的防護措施
帳戶入侵防護
威脅級別調整,增加用戶的登錄保護
無縫的令牌集成(密碼、Yubico、OTP、各種OATH令牌、一次性密碼到手機/電子郵件/irc)
用戶更快速的登錄。順帶一提,我們正在開發相應的移動應用程式。
支援多個網站的通用密碼,讓登錄憑據可在多個網站上使用。
每次登錄的實時監控,確保您的用戶是您的用戶
網站管理員的報告工具可細節每次登錄的交易情況和結果(即將推出!)
單一帳戶支援多個令牌
單一帳戶支援多個帳戶

證書簽名請求(CSR)

證書簽名請求需要私有/公共密鑰對,而私有密鑰則使用秘密密鑰進行加密。為了獲取良好的秘密密鑰,該外掛會嘗試從/dev/urandom獲取良好的隨機數據。如果失敗,該外掛將會嘗試從 https://www.random.org 安全地獲取隨機數據

用戶註冊

啟用這個外掛通過安裝證書會上傳有關用戶的資訊至我們的伺服器。我們只會上傳使用者名稱、電子郵件和雜湊密碼,使用私人SSL連接,使用2048位元金鑰。我們永遠不會為任何目的使用有關您用戶的任何資訊,甚至不包括重設凭据或身份驗證用途。我們永遠不會出售或提供有關您用戶的任何資訊。

遙測

我們透過具備2048位元金鑰的SSL連接將遙測資料傳送至我們的伺服器。此遙測資料只包含在成功安裝UFP Identity外掛時可以獲取的資料。這可通過添加選項‘identity_telemetry_enabled’ => ‘no’啟用。

位置資訊

我們調用http://freegeoip.net/json/獲取證書簽名請求的位置資訊。這是為了幫助預填必要欄位並最小化所需的工作量。我們只會在安裝時執行一次。

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.2.3) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「UFP Identity」→ 直接安裝(推薦)

原文外掛簡介

UFP Identity is the only dynamic security platform created for e-commerce sites, design agencies and developers that simplifies login authentication.
If there is a token, we support it. UFP Identity supports a wide variety of secure tokens enabling faster, more streamlined access to your websites all the while protecting user accounts from being compromised and preventing spam enrollments to your website.
Our challenge
UFP Identity set out to solve a huge technical challenge: To protect (I mean really, really make private!) online user’s personal info, make the process to access any number of websites at once really easy, and stop bad guys from hacking your stuff.
Our technology platform includes:

Strongest level of password authentication and encryption!
Spam protection preventing unwanted user account creation
Account-compromise protection
Threat level adjustment to heighten login protection for your users
Seamless token integration (password, Yubico, OTP, various OATH tokens, one-time codes to phone/email/irc)
Quicker logins for your users. By the way we’re building a mobile app for that.
Universal password support for websites that use UFP Identity. This means login credentials can work on multiple websites.
Real-time monitoring of every login ensures your users are your users
Reporting tool for website administrators details every login transaction and outcome (coming soon!)
Multiple tokens to single account
Multiple accounts to single account

Certificate Signing Request
The Certificate Signing Request requires a private/public key
pair and the private key is encrypted with a secret key. In order to
create a good secret key the plugin attempts to get good random data
from /dev/urandom. If this fails, the plugin makes an attempt to
securely retrieve random data from https://www.random.org
Enrolling users
Activating this plugin by installing the certificate will upload
information about your users to our servers. We only enroll the
username, email and hashed password over a private SSL connection
using 2048 bit keys. We will never use any information about your
users for any purpose other than authentication and verification. We
will never use the email for any purpose other than resetting
credentials or authentication. We will never sell or give up any of
the information about your users.
Telemetry
We send telemetry data to our servers over an SSL connection with 2048 bit keys. This telemetry data only contains data that we
would otherwise get with a successful install of the UFP Identity plugin. The telemetry can be turned off by adding an option
‘identity_telemetry_enabled’ => ‘no’.
Location Information
We make a call to http://freegeoip.net/json/ to get location information for the Certificate Signing Request. This
is to help pre-populate the required fields and minimize the amount of work you need to do. We only do this once, upon install.

延伸相關外掛

文章
Filter
Mastodon