I like to start using Third Party Authentication using Twilio SMS to cellphone or email.
This will gave the opportunity of provide one more layer of security prior to authenticate with just a simple user/password.
When user submit user/passowrd redirect to another page expecting the PIN or Token or whatever you want to call it... which was sent vis SMS to the stored cellphone number or email. then once entered goes directly the de desired page.
If for some reason more than 5 or 10 minutes pass. perhaps that is not a valid or expire another request need to be sent. good thing is all the login attempts are stored for reporting.
I saw Twilio have some nice interface, but wondering if somebody in the K2 community have some other suggestions/alternatives ?
Happy Friday !!!