why is it not a thing for torn in 2020? everything has it nowadays, please i would feel a lot safer with it.
2 factor authentication?
Started by bIgfatone [2094425] on in Suggestions.
About this thread
Posts archived: 14 / 14 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Counted by TornLife from the archived posts.
- Archived posts
- 14
- Discussion span
- →
- People posting
- 6
- Likes on archived posts
- 3
- Authority score
- 27 / 100
- Historical score
- 18 / 100
- Story score
- 37 / 100
- Engagement score
- 49 / 100
bump
so there is such a thing, can you plaster it in peoples faces until they turn it on. that would be very good.
havent seen/heard of people being hacked in torn. but it's a good option to add security just in case
So it exists and you want it, but now you demand it be plastered in everyone else's face until they use it too? I don't like 2-factor for sites like this, so should I demand no one can use it? Let everyone choose the path they want and live with the consequences of those decisions.
its usually plastered in everyones faces in every other game because passwords can be cracked quite easily.
https://www.torn.com/preferences.php#tab=security
Here you go :) It's a preference. Protect yourself as you see fit and let others take care of themselves as well.
Love, deca <3
Here you go :) It's a preference. Protect yourself as you see fit and let others take care of themselves as well.
Love, deca <3
Just because it's done elsewhere doesn't mean it's a good idea. I stop playing any game that requires 2-factor because that's a lot more personal information than I'm willing to give them. No, they don't need my cell number or whatever form their system wishes to use. Passwords can be cracked, and that's why you should be using a unique password on this site compared to others to limit your exposure. See how I said 'should' and not 'do things as I demand'? Play how you want, but don't ask others to be forced to play your way.
This makes absolutely no sense!
2FA does not require any personal information. It is literally just a rotating number every 30 seconds based on a time and math and is provided by third party apps like Google Auth, there is no personal information used.
Passwords can be cracked yes but most passwords if done correctly are salted and secured on the server.
2FA does not require any personal information. It is literally just a rotating number every 30 seconds based on a time and math and is provided by third party apps like Google Auth, there is no personal information used.
Passwords can be cracked yes but most passwords if done correctly are salted and secured on the server.
Most 2FA that sites try to cram down my throat deliver this number via text, or another service that does require additional personal information. I don't need it, and I don't want it. I've been a victim of identity theft because these sites wanted too much personal information and they're unable to properly secure it. Each site I use has unique login and unique password. Yes, this makes managing the information more difficult but adds a much better security set than anything else. I would never ask other users to be forced to do this, let everyone live their life with the level of risk they're comfortable with.
Just so you are aware; Torn uses TOTP which means Time based One Time Password. This is a code that is only valid for 30 - 60 seconds and then it is no longer good. They use apps that provide the code and nothing more. They don't store any personal information. Also they do not use SMS for this which is even better they use Authenticator apps like Google Auth, Authy, and I believe Lastpass Authenticator. These applications provide you the TOTP code without using any of your personal information.
I agree SMS codes are one a pain in the ass and they are not as secure. TOTP 2 Factor is the most secure you can use without moving to something like a Yubico key (whole different story). If you have been a victim of Identify theft (which I think everyone has been I know I have) then yes using different passwords for each site is good, adding 2FA on top of that is even better. If the site is weak and they lose your password they can't lose the TOTP code because they can't even access it; so that makes it even harder for the attacker. That is why banks are supporting 2FA. I use Authy for Torn, my bank, and many other accounts.
Here is the problem we see in the security world and we saw this with Ring (camera app). People were getting hacked into and they blamed Ring for not using 2FA as an extra layer, but they were not using it. The problem is they didn't force it. So Ring had a PR nightmare because they didn't lead people to do the right thing. It's a damned if you do; damned if you don't situation.
Here are some links for you:
https://authy.com/
https://mashable.com/2017/10/29/how-to-set-up-google-authenticator/
I agree SMS codes are one a pain in the ass and they are not as secure. TOTP 2 Factor is the most secure you can use without moving to something like a Yubico key (whole different story). If you have been a victim of Identify theft (which I think everyone has been I know I have) then yes using different passwords for each site is good, adding 2FA on top of that is even better. If the site is weak and they lose your password they can't lose the TOTP code because they can't even access it; so that makes it even harder for the attacker. That is why banks are supporting 2FA. I use Authy for Torn, my bank, and many other accounts.
Here is the problem we see in the security world and we saw this with Ring (camera app). People were getting hacked into and they blamed Ring for not using 2FA as an extra layer, but they were not using it. The problem is they didn't force it. So Ring had a PR nightmare because they didn't lead people to do the right thing. It's a damned if you do; damned if you don't situation.
Here are some links for you:
https://authy.com/
https://mashable.com/2017/10/29/how-to-set-up-google-authenticator/
They dont have to be forced, just have it at the top of the torn screen, because i bet alot of people dont have it on because they dont know about it. Not because theyre scared of some random number generation app stealing your data and identity.
Who is afraid of the generator stealing your identity? That's just absurd. The more sites you place information on, the more chances you have of information being stolen. 2FA is wholely unnecessary if you limit the information given to sites and choose to not use services that force the sharing of personal information. Comparing a security service such as Ring to a text based game is literally comparing apples to oranges. People have a greater expectation of security from Ring (they shouldn't) because it bills itself as a security service. Torn is a game, and one I place little faith in the security of as we all should. I'm a donator using single use credit card numbers and no real information. This is the best way to handle a site like this. Should a banner be placed at the top of every screen advertising this method because it's by far the best? No.
2FA is already and option and is encouraged. Users with access to sensitive information are also required to have it.