• Resolved Pat K


    Hi AITpro. I love your plugin, but I’m getting emailed reports, complaints and general confusion from clients about this JTC-lite thing. I get wanting to thwart dictionary attacks, but please don’t enable features like this by default. For people trying to access their admin dashboards using password utilities, they very quickly lock themselves out (because they ignore the 3rd input field). And many people already have measures in place to deal with this sort of thing.

    Two thumbs down on having this stuff enabled out of the box.

    That said, thanks for sharing your excellent plugin and expertise with the WP community.


Viewing 9 replies - 16 through 24 (of 24 total)
  • Thanks, I’ve managed to log.

    Here is another challenge, after renaming the file back to its original I cant find it on the plugins folder.

    Secondly am trying to stop the email alerts am getting after every 5 minutes and am getting this message “CSRF Error: Invalid Nonce used in BPS MU Tools must-use plugin GET Request”

    Plugin Author AITpro


    Thank you for getting me off YouTube and Twitter and back to something that is similar to reality. Jeez, I don’t claim to be anyone who has it all together, but only spending 30 minutes on YouTube or Twitter starts to make me feel like I might be insane and living on an insane planet full of insane beings. What the hell is up with that? Tell me I am not alone please. ha ha ha.

    You would be renaming a folder and not file. The BPS plugin folder is here > /wp-content/plugins/bulletproof-security/. I assume that is just a misunderstanding/typo.

    The new BPS 2.7 release fixed the CSRF error so maybe you just need to upgrade to BPS 2.7?

    Plugin Author AITpro


    Continued rant – I don’t know what’s worse – a president that acts like a 13 year old girl or religious nuts that think they know what is really going on or people killing each other in fear. What the hell? So much for “take me to your leader”. This whole planet is freakin nuts.

    Thanks so much I’ve succeeded. Have a nice day.

    Plugin Author AITpro



    Hi AITpro,

    Now that the panic has subsided and I figured out why my login page suddenly changed (I had a website hacked years ago, so I tend to be pretty on-edge when I see things I didn’t explicitly put there), everything looks good and I like this new feature. ??

    That said, I want to point out that I never saw that survey — the one you referenced as 90/10 in favor of auto-activation. I’m assuming the angry newspaper editor didn’t participate either. There’s bound to be a pretty huge “selection bias” with something like that, isn’t there?

    Plugin Author AITpro


    @conorbrace – We do all of our user feedback/information gathering stuff with BPS Pro folks since we have contact info for them. One of these days we plan on creating some kind of online website based form thing where people can add feedback/ideas/suggestions/requests and of course complaints. We did attempt to do something like that a long time ago, but it did not work out very well because if you cannot verify someone is actually a BPS user and is genuinely interested in saying something productive then typically you will get a lot of obvious random verbal attacks, slander junk, useless, etc. feedback.

    The general rule with WP is that you do not automatically do something without telling the user what is going to be done. So it’s a catch 22 situation with the new JTC-Lite feature since it is now considered a standard BPS feature and not something extra or additional. ie since JTC-Lite is considered a standard feature/functionality then logically it should be turned On by default. On the other hand, for folks who already had BPS installed and JTC-Lite is a new feature that was automatically setup and turned On during the BPS upgrade then I believe where we dropped the ball was by not notifying folks of the new JTC-Lite feature. Doing that also generates complaints from folks since we have done that in the past with other new BPS features. ie “why am I all of sudden a Notice about something – just make it go and do not show me any dumb messages”.

    In my experience the reality of creating anything new comes with a transition period where someone is not going to be happy with whatever the new thing is. So we were expecting a fair amount of complaints since that is the norm that should settle down naturally after a month or so. It would be great if it were possible to make all of the people happy all of the time, but that is being idealistic and not realistic. ??

    From a Developer perspective you try to achieve the highest possible satisfaction percentage you can achieve and then just expect some complaints no matter what you do. It is important to remind myself that typically when folks are happy about something I will never hear any feedback from them. Another important thing that I remind myself is to be detached when being attacked or dealing with someone who is upset or angry. I feel bad that they feel that way, but I do my best not to allow myself to get sucked into that negative state of mind because it is a non-productive/non-conducive state of mind. No one’s perfect, but the good news for me is I am getting better at not being reactive since that ends up making me feel negative too. ??

    • This reply was modified 7 years, 1 month ago by AITpro.
    • This reply was modified 7 years, 1 month ago by AITpro.
    • This reply was modified 7 years, 1 month ago by AITpro.
    • This reply was modified 7 years, 1 month ago by AITpro.

    The customer says hes having issues and your rebuttal is “well it works on 50,000 other websites” Are you serious? You need to get some training in customer service.

    First I am an MCSA. This issue is not cause by a VPN or browser issue. This issue is caused by a conflict within the BPS Security Plugin. Plain and simple. Whether or not this is a feature of BPS (JTC-lite) that is causing this issue it is still caused by the BPS PLUGIN and can be resolved by uninstalling or disabling the BPS plugin. PERIOD.

    AIT one thing you have to keep in mind is people are not attacking you personally they are commenting on a plugin that is published by you. They are upset because the plugin altered their login pages. Do not take things so personal. If you come off as arrogant you will probably get “attacked” (this is life, ie treat others how you want to be treated). In the future I would recommend not altering the login pages of your customers automatically without notification. You will have less headaches.

    Plugin Author AITpro


    @webmaster1234 – I’m sorry you feel that way. We did actually fully address Pattaya’s concerns and did a full assessment of why this problem occurred on his/her website. In Pattaya’s case the JTC-Lite problem was caused by a mistake on his/her custom login page.

    We addressed your concerns in your other forum posts:

    Actually we spent 2 weeks trying to decide how to handle the new standard JTC-Lite feature inclusion. I now think we made a mistake for existing BPS plugin upgraders and that is we did not notify existing BPS plugin users via email about that this new standard BPS plugin feature would be automatically setup and turned on on BPS plugin upgrade. For new BPS plugin users this is not an issue because JTC-Lite is a standard BPS plugin feature and is automatically setup and turned on by default just like all other standard BPS plugin features.

    The decision has been made to release a new BPS plugin version that will notify existing BPS plugin users via email about the new standard BPS plugin JTC-Lite feature.

    • This reply was modified 7 years, 1 month ago by AITpro.
Viewing 9 replies - 16 through 24 (of 24 total)
  • The topic ‘JTC-lite enabled by default: 2 thumbs down’ is closed to new replies.