Devise Two Factor

Barebones two-factor authentication with Devise

Cybersecurity & Ethical HackingRubyMIT

Abstract

Devise Two Factor is an open-source Cybersecurity & Ethical Hacking project. Barebones two-factor authentication with Devise. It is built using Ruby. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

Barebones two-factor authentication with Devise

2. Objective

Barebones two-factor authentication with Devise

This project demonstrates how Ruby can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Ruby

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Ruby and Bundler
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/devise-two-factor/devise-two-factor.git
cd devise-two-factor
  1. A Rails application with devise installed
  2. Secrets configured for ActiveRecord encrypted attributes
  3. Create a new migration which adds a few columns to the specified model:
  4. Edit app/models/MODEL.rb (where MODEL is your model name):
  5. add the :two_factor_authenticatable devise module
  6. remove the :database_authenticatable devise module, if present; having both modules enabled will lead to issues described below.
  7. Add a Warden config block to your Devise initializer, which enables the strategies required for two-factor authentication.
# Generates a random key set and outputs it to stdout
./bin/rails db:encryption:init
# Copy the generated key set into your encrypted credentials file
# Setting the EDITOR environment variable is optional, but without it your default editor will open
EDITOR="code --wait" ./bin/rails credentials:edit
# Copy the generate key set and set them as environment variables

config.active_record.encryption.primary_key = ENV['ACTIVE_RECORD_ENCRYPTION_PRIMARY_KEY']
config.active_record.encryption.deterministic_key = ENV['ACTIVE_RECORD_ENCRYPTION_DETERMINISTIC_KEY']
config.active_record.encryption.key_derivation_salt = ENV['ACTIVE_RECORD_ENCRYPTION_KEY_DERIVATION_SALT']
# Gemfile

gem 'devise-two-factor'

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by devise-two-factor and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship