I get a new code probably once a day. Using wi-fi, always same home location using MacBookPro laptop. IOS is fully updated and safari is browser. BT home hub 5.
Too frequent codes?
Started by ianstewart [660616] on in Bugs & Issues.
About this thread
Posts archived: 17 / 17 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Counted by TornLife from the archived posts.
- Archived posts
- 17
- Discussion span
- →
- People posting
- 7
- Likes on archived posts
- 5
- Posts by staff, officers and moderators
- 2
- Authority score
- 60 / 100
- Historical score
- 35 / 100
- Story score
- 43 / 100
- Engagement score
- 59 / 100
Most-liked replies
- JimmyJames [581165]
· 2 likes ·
Why not use non-expiring cookies, like facebook does? Then as long as I'm on my laptop or phone or whatever device, it doesn't matter what network I'm on. I've never understood why Torn's cookie expires and you have to constantly …
I get a new code probably once a day. Using wi-fi, always same home location using MacBookPro laptop. IOS is fully updated and safari is browser. BT home hub 5.
Your router probably restarts itself once a day. I know mine does, and some of mine friends as well, so that is probably the cause. Everytime it resets you get a new IP address - so code is sent again.
You can check this on your security panel as well, I've got many IP addresses:
[image: i.imgur.com]
As far as I am aware address is constant.
I can only wish you good luck with your bug then!
what code are you referring to?
Torn verification code being sent my mobile as part of authentication to login.
Are you using a VPN? Otherwise I expect they should slow down once all the ranges are covered.
Not using VPN.
I fear this is something out of our control - something to do with your ISP or connection. I'll pass to Dmitryz to take a look regardless though.
Thank you
Why not use non-expiring cookies, like facebook does? Then as long as I'm on my laptop or phone or whatever device, it doesn't matter what network I'm on.
I've never understood why Torn's cookie expires and you have to constantly log in, would it be so hard to just keep people logged in? Especially if you're planning on making mobile apps, are we gonna have to constantly log in to them too?
It might be something about account security. If so it isn't a bad thing. I know my retirement program from work requires verification for each new network I'm connected to. And that is on top of the normal login and password. But a game vs my login that had thousands of dollars of my hard earned money would have different standards. Course a responsible owner of a game would try for as secure as the users would tolerate. And seems like the general direction the game is going he's focusing on security to try to keep his users safe.
My banks I get logged out for inactivity rather quickly, which is understandable for a bank... But Torn doesn't need to be more secure than my email or social media accounts. I never have to log in to gmail, facebook, twitter, etc...
Someone who is clever with session stealing/ injection can get access to your Facebook Twitter and Gmail accounts. I don't claim to be a security expert for PC's but I do have a knack for being able be to bypass a lot of security features that say a photograph would use instead of encrypting their online photos. I've taken a try at a relative's to see what kind of setup she has. Needless to say I managed to access the photos but family ties prevented me from taking advantage. Have I tried the same for torn? No.
The point is though for every shortcut you get a risk. And one thing I can praise Chedburn for is that he seems to be aware most people use the same password for everything. So by extension he's protecting your bank password and email password. The game itself no there isn't a big risk. But for most users it's the same password protecting your bank and email. And if someone finds your email password they probably could get your bank login information.
Sorry for any typos I'm using my cell phone.
You can't get a password from the cookie.
But you can bypass the verification process. And furthermore if a cookie is setup wrong you could. Some sites do put the password into the cookie. Granted not as many as when the web was new but still there are sites with that bad of security. Stealing a session can bypass the need for a password. And guess what? That can be done via cookie.
You get a new code only when your IP is changed. I can't find any issues related to your account. You have as many delivered codes as the amount of your approved IPs. I also see that you don't get a code once a day. Furthermore, the last code was sent to you 10 days ago. Closed.