How to Keep WordPress Locked Down with Duo Security

Duo Security

WordPress blogs are one of many targets for hackers, and with so many people making simple mistakes, it becomes clear why. There are many ways of protecting your blog, and weโ€™ve outlined five mistakes you might be making.ย While using a stronger password or keeping your plugins and theme updated tend to be common advice, you can take additional measures. In fact, you can ensure that absolutely no one, even if they were to get your password, will ever be able to access your blog.

Two-factor authentication is a wonderful thing, and was first used in the workplace to protect sensitive data. Nowadays, companies like Google or Microsoft offer the functionality, and all thatโ€™s required is a mobile phone.ย How it works is when you go to login someplace, and have two-factor authentication enabled, you are required to enter a special pin. For example, Google has its โ€œAuthenticatorโ€ app which you fire up to see the special pin, or you can opt to receive a text message or phone call instead.ย A special pin isnโ€™t always required, and Twitter recently implemented its own solution which involves approving a trusted device.

Thanks to the help of Duo Security, you can bring this same functionalityย to your WordPress blog.ย With Duo, you can approve or deny logins with the tap of a button, or use a special pin delivered through the app or via SMS. Once youโ€™ve installed and activated the plugin, click on its โ€œSettingsโ€ from the plugin page.ย Before you can start benefiting from Duo Security, you have to setup an account on the appropriate website which is listed on the settings page.

While Duo does offer a free trial on its paid plans, it has a free โ€œPersonalโ€ plan which supports up to 10 users, plenty for the average WordPress user.ย Once youโ€™ve signed up, make sure you activate your account via email. From there, youโ€™ll create a password, and add your phone number. Duo Security verifies your identity via phone either by calling or sending you a text message with a special pin. Now that your identity is verified, itโ€™s time to setup your blog.

Duo Security

After verifying your identity, you should have been redirected to a page that says โ€œNew Integration.โ€ Where it says โ€œIntegration type,โ€ click on the box and scroll down to the bottom to select โ€œWordPress.โ€ Next to โ€œIntegration name,โ€ add whatever name youโ€™d like, and then hit โ€œCreate Integration.โ€

Duo Security

This is where you receive the integration key, secret key and API hostname that needs entered on the pluginโ€™s settings page via your blog. Simply copy and paste over the appropriate details, and then click โ€œSave Changes.โ€ Once youโ€™ve saved changes, switch back over to the Duo Security website, and under โ€œIntegrationsโ€ on the left hand side, select โ€œUsersโ€.

Duo Security

On the top right, click the green button that says โ€œNew user,โ€ and once youโ€™ve created a username, click โ€œAdd user.โ€ Scroll down to where it says โ€œAdd phone,โ€ and add your phone number. Next to โ€œTypeโ€ select โ€œMobile,โ€ and next to โ€œPlatformโ€ select your appropriate mobile operating system. Once youโ€™re finished, click โ€œSave Changesโ€ and under your phone number in large text, you should now see a link that says โ€œActivate Duo Mobile.โ€

Duo Security

Click the activation link, select the button that says โ€œGenerate Duo Mobile Activation Code,โ€ and then โ€œSend Instructions by SMS.โ€ The installation instructions will help you to download and install the appropriate app while the activation instructions are what you use to successfully add your account to the app. Duo Security works on all major mobile operating systems such as Android, iOS, BlackBerry and Windows Phone.

See Also
person playing with tarrot cards

Once your account has been added to the app by clicking the link in the activation SMS, your blog is ready to benefit from two-factor authentication! To test it, log out of WordPress, and sign in as you normally would. Now, youโ€™re met with the Duo Security prompt.

Duo Security

I recommend logging in by way of โ€œDuo Push.โ€ย With Duo Push selected, click the blue login button. Your phone will then get an alert about a login request, and all you have to do to accept is click the Duo Push button within the mobile app, and then click the green โ€œApproveโ€ button. In a matter of seconds, youโ€™ll automatically be logged into your blog.

Duo Security

With just 5 to 10 minutes of setup time, Duo Security adds an extra level of security to your Wordpress blog that really canโ€™t be beat.

Photo credit: Davide Del Vecchio

Picture of Mike Stenger

Mike Stenger

Mike Stenger is a writer with a love of all things technology.

RECENT ARTICLES

TRENDING AROUND THE WEB

7 things you don’t realize you’re doing that keep you from moving forward in life, says psychology

7 things you don’t realize you’re doing that keep you from moving forward in life, says psychology

Global English Editing

If you can travel for more than a week with just a backpack, you probably have these 7 unique traits

If you can travel for more than a week with just a backpack, you probably have these 7 unique traits

Global English Editing

If you want to get older with dignity and class, say goodbye to these 7 habits

If you want to get older with dignity and class, say goodbye to these 7 habits

Global English Editing

Why we stand still for the screen: a closer look at subtle patterns

Why we stand still for the screen: a closer look at subtle patterns

Hack Spirit

6 things emotionally intelligent people do when their adult children pull away

6 things emotionally intelligent people do when their adult children pull away

Global English Editing

Perfect life checklist: real desire or a really good commercial?

Perfect life checklist: real desire or a really good commercial?

The Vessel