Latest update of Local means I’m able to push/pull via local WITHOUT being logged in to Local HUB, via signin/2FA confirmation - -

How vulnerable is my Local installation after update?
How concerned should I be?
Why, after not being able to access my sites in Local to push/pull UNLESS I log into Local (via login/2FA) can I, after update - pull a site down from production Flywheel site whether I’m securely logged in or not? Please explain it to me like I’m a 5 year old/idiot thanks -

This is factor this morning, AGAIN, is very concerning to me - so, I’m doing my best to try to help myself and my clients, even while, so many other factors (listed below in info/tools used to explain to me what alerts/things I should notice/pay attention to EVEN while I cannot replicate the knowledge or expertise DRIVING those alerts)

Screen shot attached of local installation of local/one website, that was pulled from production this morning sans me logging in via 2fa Local Hub login (see disclaimer at end of message to explain why I am behind on Local/etc.)

  • Local Version: 7.1.0+6396

  • Operating System (OS) and OS version: macOS Monterey v 12.6.58 with Malwarebytes installed, on secured local internet connection, hardwired ‘not wi-fi’ for internet and and scans say I’m clean/not compromised other than an email address put in the wild by medical provider/credit bureau over 8 years ago NO reused/simple passwords/use password manager - also secured by 2fa by separate device, set to NOT auto connect to any (free/secured/not) internet service if I’m not at home - sigh -

Hi @tank13 - happy to help!

Local is not capable of pushing to or pulling from Flywheel without being properly authenticated with Flywheel inside the app. You can rest assured that your sites (and your clients and their info) are secure on Flywheel.

Your Local account (log in by visiting Local Hub, and your Flywheel hosting account are not the same. This is definitely a confusing workflow, and not the first time we have heard users have questions about it.

Logging into Local Hub unlocks development features like Live Links and Cloud Backups where we need to associate a user and their site to their Local app. This ensures your backups are only shown to you, your Live Links URLs are unique to you, etc.

Logging into Flywheel, a separate account, is done in the Local Connect window. See my screenshot below. If you visit the Connect tab in Local, you will see that you can remain authenticated with Flywheel even if you are not logged into Local. Hopefully this makes sense and eases your concerns, but I am happy to answer any questions you have.

Thank you Austin - appreciate it! I just in the past wasn’t able to push/pull when I wasn’t logged into my hub account - so when I started to pull an account - yet not logged into the Hub account - freaked me out! Been a while since I pushed/pulled so wasn’t sure which update - etc., but was pulling site while try troubleshoot some other thing - and guess I was on high alert something was compromised!

Thanks so much for your kind, helpful and prompt reply.


