J4 Issue ?
avatar YoKoGFX
YoKoGFX
19 Mar 2017

It would be great if Joomla 4.0 would have an Option to Activate ReCaptcha on the Administrator Loginscreen! This would make the Login more secure and prevent ( make it harder ) that bots acess the Adminpage!

Feature Request:

  • ReCaptcha on the Login Screen
  • Option to make the ReCaptcha always vissible or just after some failed Logins.

Votes

# of Users Experiencing Issue
2/4
Average Importance Score
4.00

avatar YoKoGFX YoKoGFX - open - 19 Mar 2017
avatar joomla-cms-bot joomla-cms-bot - change - 19 Mar 2017
Labels Added: ?
avatar joomla-cms-bot joomla-cms-bot - labeled - 19 Mar 2017
avatar tonypartridge
tonypartridge - comment - 20 Mar 2017

+1 for this

avatar Simon-Davies
Simon-Davies - comment - 20 Mar 2017

+2

avatar brianteeman
brianteeman - comment - 20 Mar 2017

@Simon-Davies no it wont as captcha can be defeated

avatar Simon-Davies
Simon-Davies - comment - 20 Mar 2017

I was thinking that may be the case although I thought the new Recaptcha couldn't?

avatar brianteeman
brianteeman - comment - 21 Mar 2017

yet

avatar tonypartridge
tonypartridge - comment - 21 Mar 2017

@Simon-Davies no you are semi right. Recaptcha has a massively reduced attacks. It's a benefit to include It regardless.

avatar brianteeman
brianteeman - comment - 21 Mar 2017

The best way to protect your admin is with htaccess. As this doesn't use php but is at the server level it is far more efficient on server resources etc

avatar tonypartridge
tonypartridge - comment - 21 Mar 2017

Of course it is @brianteeman there is no question on that.

This is a further improvement against random bots that's all.

avatar alikon
alikon - comment - 21 Mar 2017

instead of recaptcha you prefer to use 2FA on admin login

avatar cokencorn
cokencorn - comment - 29 Mar 2017

I'm planning to implement Google's recent invisible recaptcha on the login button, you will still be able to turn it off or set failed login count for it to start checking. What do you think? I believe it's a good alternative to 2FA. (NOT A REPLACEMENT)


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/14791.

avatar Simon-Davies
Simon-Davies - comment - 29 Mar 2017

I personally think implementing Google's invisible recaptcha is a great idea especially if it can be toggled on and off for those who do not want to use it.

avatar YoKoGFX
YoKoGFX - comment - 29 Mar 2017

Yeah, the new invicible recaptcha would be great for that :)


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/14791.

avatar joomla-cms-bot joomla-cms-bot - change - 29 Mar 2017
Title
[4.0] ReCaptcha on Login
[4.0] - Feature Request: ReCaptcha on Login
avatar joomla-cms-bot joomla-cms-bot - edited - 29 Mar 2017
avatar franz-wohlkoenig franz-wohlkoenig - change - 30 Mar 2017
Category Feature Request
avatar joomla-cms-bot joomla-cms-bot - change - 30 Mar 2017
Title
[4.0] - Feature Request: ReCaptcha on Login
[4.0] ReCaptcha on Login
avatar joomla-cms-bot joomla-cms-bot - edited - 30 Mar 2017
avatar joomla-cms-bot joomla-cms-bot - change - 30 Mar 2017
Title
[4.0] - Feature Request: ReCaptcha on Login
[4.0] ReCaptcha on Login
avatar franz-wohlkoenig franz-wohlkoenig - change - 30 Mar 2017
Title
[4.0] - Feature Request: ReCaptcha on Login
[4.0] ReCaptcha on Login
avatar franz-wohlkoenig franz-wohlkoenig - change - 3 Apr 2017
Category Feature Request Authentication External Library Feature Request
avatar franz-wohlkoenig franz-wohlkoenig - change - 3 Apr 2017
Status New Discussion
avatar joomla-cms-bot joomla-cms-bot - change - 3 Apr 2017
Title
[4.0] ReCaptcha on Login
[4.0] - Feature Request: ReCaptcha on Login
avatar joomla-cms-bot joomla-cms-bot - edited - 3 Apr 2017
avatar joomla-cms-bot joomla-cms-bot - change - 3 Apr 2017
Title
[4.0] ReCaptcha on Login
[4.0] - Feature Request: ReCaptcha on Login
avatar franz-wohlkoenig franz-wohlkoenig - change - 3 Apr 2017
Priority Medium Very low
avatar joomla-cms-bot joomla-cms-bot - change - 3 Apr 2017
Title
[4.0] - Feature Request: ReCaptcha on Login
[4.0] ReCaptcha on Login
avatar ChathuraT
ChathuraT - comment - 8 Sep 2017

Hello, I am going to implement this feature on the Administrator login screen. Found out that google Invisible reCAPTCHA with internal on off functionality would be a great solution. Do any one have more better ideas?


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/14791.

avatar alikon
alikon - comment - 8 Sep 2017

look at #16599,
i still prefer 2fa for admin login

avatar sanek4life
sanek4life - comment - 11 Jan 2018

Please add this feature so that after 3 or 5 or 10 failed attempts ReCaptcha is shown!

ReCaptcha Invisible

avatar RichardEb
RichardEb - comment - 21 Feb 2018

+1

avatar RichardEb
RichardEb - comment - 21 Feb 2018

I still would prefer captcha instead of 2fa. And I think a huge amount of websites don't use 2fa. If you don't belive me check your telemetry.

Of course you can say: "This people are all idiots and it's their fault." But this won't help anyone. Or you do something! You won't change the peoples behaviour by repeating the same thing. Mine neither.

I want this feature even if it's an optional one.

If you plan to enable this by default you could add an additional Captcha-Plugin that works without google. (This would be a nice thing anyway) Or you can continue contributing an insecure software and blame the user for it.


This comment was created with the J!Tracker Application at issues.joomla.org/tracker/joomla-cms/14791.

avatar brianteeman brianteeman - change - 25 Mar 2018
Labels Added: J4 Issue
avatar brianteeman brianteeman - labeled - 25 Mar 2018
avatar Simon-Davies
Simon-Davies - comment - 12 May 2018

Invisible ReCAPTCHA should definitely be an option in Joomla 4. There is a free plugin that activates it for WordPress.

I use 2FA but still believe that Invisible ReCAPTCHA should be used by default to prevent bruteforce attacks with tools such as Burp Suite Pro as many people don't enable 2FA.

I'm speaking as a Web Application Penetration Tester for one of the big three and a Security Researcher.

avatar brianteeman
brianteeman - comment - 4 Jun 2018

@RichardEb please stop with these posts - they are not helpful

avatar tonypartridge
tonypartridge - comment - 4 Jun 2018

I use 2FA where it needs to be secure.
On 4 Jun 2018, 12:37 +0100, Brian Teeman notifications@github.com, wrote:

@RichardEb please stop with these posts - they are not helpful

You are receiving this because you commented.
Reply to this email directly, view it on GitHub, or mute the thread.

avatar RichardEb
RichardEb - comment - 4 Jun 2018

I said that I dislike 2fa and dont find at an improvment and I dont want to use it. But for you 2fa seems to solv every Problem of the World.

avatar Simon-Davies
Simon-Davies - comment - 4 Jun 2018

Both 2FA and Invisible reCAPTCHA should be implemented. They could both be optional. Let the user decide.

avatar stutteringp0et
stutteringp0et - comment - 22 Oct 2018

If you want to stay away from 3rd party services - I did the same thing (invisible captcha) years ago - it's in the JED as HashCash

I think it would be super cool if it was included in the core.

Before I get accused of advertising - that's one of my free extensions, and I'm offering it to the project.

avatar gersteba
gersteba - comment - 17 Jul 2019

I am sure, Joomla would not provide users with captcha in contact and registration forms, if there was no sense to do that. The only problem is, that Joomla still is leaving out its login form.
So, please, add captcha to the login form, too!
Thank you very much in advance!

avatar RichardEb
RichardEb - comment - 17 Jul 2019

I still think this is a must have. I really don't know why avoid this feature at all costs. An optional feature wouldn't harm anyone. On the other hand you already added a lot of functions to joomla that I wish you hadn't.

There are a lot of plug ins to archieve a better login protection and they have a lot of users. So why don't add an (optional) feature to joomla?

avatar SniperSister
SniperSister - comment - 17 Jul 2019

On the other hand you already added a lot of functions to joomla that I wish you hadn't.

Exactly that’s the point. You have to decide per case if I feature is useful enough for the majority of users to be added to core - what’s a must have for you is pointless to a lot of other people.

avatar RichardEb
RichardEb - comment - 17 Jul 2019

There are a lot of plug ins to add protection to the login. If you say no one wants them why there are a lot of them?

Search for Brute Force protection
https://extensions.joomla.org/instant-search/?searchall=Bruteforce&filter%5Btags%5D%5B%5D=&filter%5Bcore_catid%5D=&filter%5Bincludes%5D=&filter%5Bversions%5D=&filter%5Btype%5D=&filter%5Bhasdemo%5D=&order=&filter%5Bnewupdated%5D=&filter%5Bscore%5D=&filter%5Bfavourites%5D=&q=Bruteforce

The Brute Force Stop plug in has 40 five star ratings. The ECC+ Plug-in has 168 five star ratings. Rsfirewall 110.

Obviously there are people who want to secure their login. Or are this all idiots who can't use Joomla properly?

avatar franz-wohlkoenig
franz-wohlkoenig - comment - 17 Jul 2019

@RichardEb can you please stay on issue and respect other Volunteers comments?

avatar SniperSister
SniperSister - comment - 17 Jul 2019

If you say no one wants them

I didn’t say that „no one“ wants them. I tried to point out that the existence of plugins and/or a commenters individual usecase not necessarily means that a majority of users need a feature.

avatar BkrBkr
BkrBkr - comment - 24 Jul 2019

I followed your discussion a long time and decided to make a small simple plugin to add a captcha to all login forms. Please feel free to use it, It's free and open source (GPLv3)

https://github.com/BkrBkr/JoomlaAuthCaptcha

It's an alpha version at the moment

avatar brianteeman brianteeman - change - 17 Feb 2020
Status Discussion Closed
Closed_Date 0000-00-00 00:00:00 2020-02-17 15:26:20
Closed_By brianteeman
avatar brianteeman
brianteeman - comment - 17 Feb 2020

I am closing this. It has sat here for a year and its not going to move forward.

avatar brianteeman brianteeman - close - 17 Feb 2020

Add a Comment

Login with GitHub to post a comment