At Drupalcamp Colorado I'm presenting on improving the registration, login, and security of accounts in Drupal sites. I'm sharing the slides as well here on this site as there are lots of links to modules that folks should consider using. My talk is sponsored by HeroDevs and their Never Ending Support for Drupal.
This talk was inspired and draws inspiration from the blog post Drupal 10: Adding Extra User Account Protection.
Which Drupal modules did I recommend?
- Email Registration
- Simple Password Reset
- Passwordless
- Login History
- Session Inspector
- CAPTCHA
- reCAPTCHA
- hCaptcha
- Honeypot
- Pwned Passwords
- Password Strength
- User Expire
- Genpass
- TFA
Some more module suggestions came up from discussion.
A few were suggested for dealing with stale accounts or
And several were suggested for blocking automated/spam activity:
And here are the slides:
Photo credit to Matthew Saunders.
Comments