Edit(because I'm incapable of not commenting on this seriously, apparently): In all fairness, sharing your real life details in a public place(like this forum) often enough can allow a would-be attacker to form a complete picture of the real you. Things like your age, country or city of residence, birth month+day, first or last name, what kind of car you drive, your email address, mailing address, family members' names, phone number, etc.
All of this could be gathered either over a period of many months, or by scraping various websites where someone has found a linked identity. Personally, I am not worried as much about the corporate as much as I am the individual possibilities. Because things like "swatting" are real, and although I'm not particularly at risk for such things because I happen to live in a small town where all the police know either me or my wife, I'm still very careful about sharing such things in a public forum. In PM or private channels, the risk is greatly reduced, simply because of the fact that a limited number of people have access, and sometimes also because of the transient nature of the communication medium.
I'm not saying you should be worried, just that it's usually better to err on the side of caution
Giving Torn admin these pieces of information is a personal choice, and any given player should base that choice on how valuable their Torn account is to them. Mostly I'm speaking in terms of sentimental value, but realistically, we can calculate the approximate value of any given Torn account simply by dividing it's networth by the current market value of a Donator Pack, and then multiplying that out by the current cost of the most cost-effective DP set purchase. Of course, to proceed any further, we delve into the realm of things a person might discuss if they were contemplating selling their account, which is against the terms of use, and so I won't go there.
In any case though, you have nothing worse to worry about by giving Torn admin this information than you have by giving it to any other company.
Okay, so how does staff look into mails and chat reports? And bug reports where they need to login using our account to check stuff? what's stopping them to go to settings and look at our details?
If I'm misinformed I'm sorry but it isn't exactly stated anywhere what staff can do and how they do it, and what they can't do and their roles for an average player..
So we simple folks think they have all the authority and control from reversing transaction to sending money or removing money from our account or look at our email address to verify accounts and do interviews and whatnot..
You're not giving your name, mailing address, family names, car, etc. You're giving the DOB for verification and your phone number which is optional (it uses your email otherwise).
I prefer token OTP via an authenticator app myself but not using this because you're worried about giving your DOB is just silly. It's a great start towards protecting the account that you spend years of your time in.
Okay so they can go there, Now, highly unlikely but what if they
Change email ---> Reset Password ---> Security settings (Not sure if you need password to change email, but it looks like it doesn't.)
I'm not saying they are going to do it but there are ways...
Also you may not care about your age but some people do care about it.... I certainly don't want them knowing my age, or any of the secret question; they are all too personal...
P.S. I'd rather get hacked and lose some pixel money rather than give away my info to a snotty face geek..
It's an image proxy written in Crystal that proxies unsecure images. If you're not into these newfangled languages the above is a rewrite of this repo:
I was commenting more on the fact that you posted your date of birth on a public forum, in answer to your rhetorical question about what people can do with it... I personally would not be concerned at all with giving Torn admin my DoB.
I think it would be awesome if they made or contracted with a third party authentication service. I would totally use that, just because it's damn near unhackable. As an added bonus, those usually work with no network connection, so assuming you only had access to a connection on a third party device, and your phone was offline, in airplane mode or something, you'd still be able to use the two factor authentication application... when your phone would not necessarily be able to receive text messages. It's almost better to simply use the email option.