We know your blog is important to you, and today we’re proud to announce Two Step Authentication: an optional new feature to help you keep your WordPress.com account secure. For those of you who use Two Step Authentication with your Google account, you’ll know how useful this feature is for keeping your account secure.
Two Step Authentication works like this: when you log in to your WordPress.com account, we’ll prompt you to enter a secret number. To get that secret number, you’ll need to download the Google Authenticator App on your smartphone. It generates a new number every 30 seconds, making it virtually impossible to guess. All you need to do is open the app on your phone, and type in the number it’s showing. If you don’t have a smartphone, you can instead opt to have the number SMSed to you.
To enable Two Step Authentication, head on over to the new Security tab in your WordPress.com account settings, and go through the setup wizard. The wizard will help you make sure that everything is configured correctly:
Once you enable Two Step Authentication on your account, there are a couple of extra steps we recommend you take:
Print backup codes
Print out some backup codes to keep in a safe place — your wallet, a filing cabinet or your document safe in case your phone is lost or stolen. You can print backup codes right from your WordPress.com Security tab:
Generate application-specific passwords
Some apps that connect to your WordPress.com account (such as the WordPress mobile apps) don’t yet fully support Two Step Authentication. For these apps, you can generate unique passwords to use with each one (for example, you can have a different password on your phone and your tablet). If your device ever goes missing, you can disable its password with a single click, locking it out of your account.
If you need any extra help setting up Two Step Authentication, detailed instructions are available in the Support documentation.
Have feedback or suggestions? Leave them in the comments!
Apr 5th at 9:24 pm
great timing this is something that we need. As an aside, will this also be enabled for self-hosted blogs, as a Jetpack service perhaps?
Apr 5th at 9:34 pm
Great. I don’t have a cell phone, so can’t download the app. Does this mean my blog is no longer accessible?
Apr 5th at 10:34 pm
And for those of us who don’t have a smart-phone? What then? There are some of us our here, you know……
Apr 6th at 12:04 am
@showmescifi or anyone else who’s wondering about self-hosted WordPress – it seems .org has had it for a while: http://wordpress.org/extend/plugins/google-authenticator/
Apr 6th at 12:21 am
Now if Apple will just send me an iPhone to test out.
(I’m waiting Apple…)
Apr 6th at 12:24 am
Optional means I don’t have to do this, right? Because we don’t have cell phones. I don’t want to discover that I have no choice. We can’t afford cell phones, so we don’t have them and amazingly, life is fine — even though sometimes, we are out of touch for a few hours. Just like in the good old days!!
Apr 6th at 1:23 am
That’s all fine and dandy if you have a data package on your phone, otherwise useless.
Apr 6th at 6:46 am
Nothing for Windows Phone??
Apr 6th at 8:11 am
Great function but what happens if you loose your smartphone?
Apr 6th at 9:35 am
This is a great step forward WordPress and should become a standard feature for all the other providers of internet services.
As I am no professional for security questions do you think that with 2-Step-Authentication a periodic change of the password is dispensable?
Apr 6th at 10:27 am
It would be nice if this could be extended in future to use Yubikeys.
Apr 6th at 12:02 pm
Great, security is always top priority.
Apr 6th at 1:38 pm
Excuse me, where is Security Tab in Dashboard?
Apr 7th at 11:17 pm
If you don’t have a smartphone or cell but have an iPod touch with a camera, you can still do this! Just download the Google Authenticator app from the App Store and follow the instructions for the two-step authentication in the security settings. It still works and it’s a piece of cake.
Apr 9th at 12:17 am
Finally, a long wait security feature come. A MUST enable feature.
Apr 10th at 3:54 pm
Is this available for all WP websites…or just the free blogs people sign up for? My clients websites are all on WordPress and I dont see the security tab anywhere (including under settings)…and most of them are in 3.5.1…so am I missing it…or is it not available for WP websites yet?
Apr 12th at 11:51 pm
This is sometimes called two-factor authentication.
Apr 13th at 8:22 am
Awesome Work. Thanks a lot for integrating with Google Authenticator. I would like to request the option to move from one phone to another without disabling this app on phone. Since, I have rooted phone, I would love to have this feature, in case I formatted the phone.
Apr 13th at 7:37 pm
@Salman Backup the Google Authenticator using something like Titanium Backup before formatting and it will restore without any issues just fine.