Further security guidelines
This thread started with a discussion of passwords and password complexity. For the AWF site, members have the option to increase login security levels in several ways. To do so, look at the top line of any of the site's post pages or the section-names list. (Remember that the top 2 or 3 lines of your display belongs to your browser, not this site.) Starting
from the right and moving to the left, you see the Search button (with its magnifying glass); the bell icon (alerts) button; the envelope icon (messages) button; and a button with your login name and a thumbnail of your avatar/image. This button leads to your AWF account information.
Click the profile button to see a list of options on the left side of the screen under "Account Details." As you click each one of those items in the list, you will see different aspects of what AWF knows about you. You might wish to browse through this area to see what you can - and can't - do. However, this discussion is about login security. Click on the list item "Password and Security" to see your options. NOTE: To actually use any of the options discussed here, you MUST know your current login method because you must essentially log in a second time to alter security settings.
The top line offers you a chance to use a passkey (in place of a password.) In this context, a passkey requires some kind of device to supply that key. It can be a commercial passkey generator that generates a new key every so many seconds. You have to synchronize to it. There is also the passkey on your phone if that is what you use. It can be a photograph of your face, a retina scan, a fingerprint, etc. Generally, passkeys require an extra device that has the biometric sensor OR the commercial extra device to generate the code. Your modern cellphone usually has one of these options. Note: If you have an accident and were using the "facial recognition" option, hope that you don't have too many scars. If you are not comfortable with passkeys, don't worry. The site allows them as an option, not a requirement. Once you start to log in this way, you can later remove it and return to password logins or other methods mentioned below.
The next line offers multi-factor authentication options - called two-step verification. By default it is DISABLED - but you can change that by clicking the CHANGE button. If you click on this option, you must enter your password again. You have two options. You can set up an app on your phone to provide the required code, or you can set up an e-mail method where the AWF site and XENFORO will send you a validation code. In either case, you can't complete the login until you enter the validation code. It is possible to do both but that might be a bit of overkill. Note that the XENFORO folks prefer the "code via app" option vs. e-mail. This is a guess on my part, but the concern is that it is easier to intercept e-mail and thus get a false login vs. using a verification code from an app.
Note that if you log in from multiple places,
either of these methods MIGHT become difficult for you to use. If you choose to generate verification codes on your phone, you will need that phone handy if you want to log in from your PC that probably can't run Android or MAC apps. If you use an e-mail confirmation, then when trying to connect via your phone, you will need to have e-mail access from that phone.
The bottom of the Passwords and Security options panel is the traditional password method. Provide your current password then you can enter your new password TWICE (the 2nd time for confirmation).
But there is one last security option. What do you do if you forgot your password? This is easy. Go to the home page and try to log in. Enter your username and at the bottom of the dialog box you have a link "forgot your password." Click that and you will get an e-mail containing a temporary password allowing you to log in and reset your account's password. When you set up your account you were asked for an e-mail and this is what will be used to send you that temporary password.