Blocked from KiCad forums: TWO-FACTOR AUTHENTICATION

I had to create a new acct here on KiCad because of TWO-FACTOR AUTHENTICATION error message I’ve been getting.

" I’ve been a member in good standing of the KiCad.info Forum for several years and a few weeks ago, I got one of their form em’s that showed a few of the recent posts. I visited and didn’t participate this time like I’ve done in the past, but that’s not the issue. A couple weeks later, I get one of their em’s and when I tried to sign in like always, I get this message:

Welcome back

📷

Log in to your account

TWO-FACTOR AUTHENTICATION

Please enter the authentication code from your app:"

I’ve been going around and around trying to install a 2-factor app on my Linux Ubuntu 22.10 machine unsuccessfully. I finally gave up and came here and created a 2nd acct. But I would like to reclaim my actual KiCad Info Forum acct but when I tired to email Admin, here’s what happened:

"Your message couldn’t be delivered to admin@kicad.info because the remote server is misconfigured. See technical details below for more information.

The response from the remote server was:

454 4.7.1 <admin@kicad.info>: Relay access denied"

Does anyone know anything about this situation and how I can get past this request for 2-factor?

Thanks.

@ChrisGammell would have to look into this. I’ve got now clues or access into how authentication is configured on the server. Best to PM Chris directly on this is my best guess.

I sent Chris a PM 3 days ago and haven’t received an answer yet. Probably due to the holidays.

I find it puzzling why you should start getting the 2FA prompt if you didn’t enable and setup 2FA yourself. 2FA is not something you install an app retroactively to use.

In fact 2FA could use any number of methods, often a one-time code sent via email or SMS. Separate authenticator apps are usually for services like banks, credit cards or internet providers e.g. Outlook accounts.

How have you registered to the forum originally? Is it possible that you are using a 3rd party login (for example I use Google) and it asks for 2FA?

This is what I get if I test 2FA option in this forum (I’ll cancel this, I’m not really going to use it). No way it happens accidentally IMO.

@Chris never contacted me and it’s been 10 days or more.

It’s puzzling to me too. I nearly always opened one of the links I was emailed from the forum, read and sometimes posted, closed the forum and that would be it. No experimenting with my acct settings or anything.

It’s been a long time since I joined the group and I don’t recall how I signed up though generally, I just go to a website, check it out, then sign up. No 3rd party.

You would think that someone would be interested in the fact that the contact info: admin@kicad.info isn’t working during this fund raising period.

Maybe it’s just me, but I don’t now who Jim-HiTek is, nor do I know whether he is who he claims to be. Two factor authentication does not turn itself on, and anyone could be phishing. (I have also never been very good with names nor social relationships).

That said, “@ Chris” is not the same as “@ ChrisGammell”, and you may have sent the PM to the wrong Chris. According to the software, Chris Gammell was last seen here on 2022-12-25 (You can see this on anyone’s profile). As far as I know he is not directly connected with “The KiCad developers Team” (by lack of a better name), and he is financing this website as his way of a donation to KiCad.

The forum software works quite well on it’s own and with a bit of moderator input, but very little maintenance is done on the forum software itself. For example, the FAQ link on top of the page is hacked in, and it’s location varies with the width of your web browser, and can overlap with other things. This has been so for years and is still not fixed.

agreed, and to state this another way, admin@kicad.info is a forum administrator email with no direct connection to the KiCad development team or to the people responsible for KiCad fundraising. The forum is not run by the KiCad developers.

There is this “other” Jim_HiTek:

who has last logged in on 2022-06-26 and last posted on 2022-02-23.

I sent a PM to that account, we’ll see what happens next.

Will the real Jim_HiTek pleas stand up.

If someone hacked the password for the original account, they could have turned on the 2 factor authentication to prevent account recovery.

THAT’S ME! That picture is moon rise over Death Valley way off in the distance from a tiny, off the road turn around spot where I’d spent the night in my RV. I took the picture at 6 AM while trying to get my engine to start. The cold wasn’t helping.

My last visit to this forum I believe, according to what I can find in Google mail search, was in Dec. of 2022. There were two nudge emails from KiCad forum and I ignored the first and visited the second time. I don’t remember the last time I posted a thread.

Has anyone tried to post as me? Doesn’t appear so. If it was a hacker, they’d want to see if my password worked so they could try to get into other accounts I have that would be of more value. FB, banking, that sort of thing. Why they’d bother to switch on Two-factor is unknown.

PS I got notification of the message you’d posted via my email address, that is the one for Jim_HiTek so I suspect that proves it’s me.

I used @ChrisGammell so he got the PM. However, he may be European and may be one of the lucky ones that gets an extended vacation from Xmas well past NY.

IF the 2-factor auth was set up here as DEFAULT then it’s remotely possible that when I went around the internet changing my passwords here and there that I may have stopped here and done that and didn’t realize that the 2-factor set itself automatically…but that begs the question, why wasn’t there a question about it? I’ll have to go check that for my acct.

Edit: Checked the 2-factor for my new acct, and no, it’s a multi-step process and 2-factor isn’t default. Using social settings is. So I wouldn’t have changed that back when I changed passwords.

Hey, sorry for the delay on things, I’m just now catching up after the holidays like you guessed.

You have pointed out a few things I need to fix (email is a big one), but let’s get back to the original thing: You’re trying to recover the original account?

Yes, I am. I’ve responded to your email sent to my backup addy:

Yes, Chris. I am trying to recover my original acct.

Thank you for getting back to me.

I can’t find any way to bypass the sudden appearance of Two-Factor sign in, I didn’t set it up, so of course your system doesn’t have the 2nd factor installed…that I know of. Not likely a hacker would have gotten into my barely active acct for any nefarious reason, so I’m stumped as for a cause of this suddenly showing up and there being no visible means of getting around it. Can you help me recover my account?

Sure, let’s get working on verifying you own the account and seeing if we can recover it.

Well, Chris, I was hoping you’d be able to get this straightened out sooner but I know you’re likely putting out fires after your extended time off over XMas & NYs so hopefully soon.

You sent a couple emails to my main and my backup email addy’s and I’ve responded to them. Was there a problem? Did you not get them? Or not get one or the other?

BTW, I’m not sure it was embedded in your last email you sent to my jimmrgn backup email addy but when I tried to close your email, I got one of those Windows scam pages jump up and pretend that I couldn’t reset the computer until I called them for them to fix it. Couldn’t move from that page. Total scam and I rarely see them these days on the Ubuntu computer I use all the time. Of course I rebooted the machine and saw no more of it, but then I came back to that Gmail acct and deleted ALL the emails (cus I was pissed) in it so I can’t check now if it was definitely from your email or not, doh! Linux doesn’t have much need for virus checkers so I don’t have one aboard my computer.

Anyway, did you get any of my emails? From my main and backup Gmail accts?

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.