Skip to content
TORNLIFE More

2 factor authentication?

Started by bIgfatone [2094425] on in Suggestions.

13 replies · 86 views · thread synced · 10 days ago · View on torn.com
About this thread

Posts archived: 14 / 14 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
14
Discussion span
→
People posting
6
Likes on archived posts
3
Authority score
27 / 100
Historical score
18 / 100
Story score
37 / 100
Engagement score
49 / 100
bIgfatone [2094425]
why is it not a thing for torn in 2020? everything has it nowadays, please i would feel a lot safer with it.
Fishbum [2009144]
So it exists and you want it, but now you demand it be plastered in everyone else's face until they use it too? I don't like 2-factor for sites like this, so should I demand no one can use it? Let everyone choose the path they want and live with the consequences of those decisions.
Fishbum [2009144]
Just because it's done elsewhere doesn't mean it's a good idea. I stop playing any game that requires 2-factor because that's a lot more personal information than I'm willing to give them. No, they don't need my cell number or whatever form their system wishes to use. Passwords can be cracked, and that's why you should be using a unique password on this site compared to others to limit your exposure. See how I said 'should' and not 'do things as I demand'? Play how you want, but don't ask others to be forced to play your way.
MisterM [2154120]
This makes absolutely no sense!

2FA does not require any personal information. It is literally just a rotating number every 30 seconds based on a time and math and is provided by third party apps like Google Auth, there is no personal information used.

Passwords can be cracked yes but most passwords if done correctly are salted and secured on the server.
Fishbum [2009144]
Most 2FA that sites try to cram down my throat deliver this number via text, or another service that does require additional personal information. I don't need it, and I don't want it. I've been a victim of identity theft because these sites wanted too much personal information and they're unable to properly secure it. Each site I use has unique login and unique password. Yes, this makes managing the information more difficult but adds a much better security set than anything else. I would never ask other users to be forced to do this, let everyone live their life with the level of risk they're comfortable with.
MisterM [2154120]
Just so you are aware; Torn uses TOTP which means Time based One Time Password. This is a code that is only valid for 30 - 60 seconds and then it is no longer good. They use apps that provide the code and nothing more. They don't store any personal information. Also they do not use SMS for this which is even better they use Authenticator apps like Google Auth, Authy, and I believe Lastpass Authenticator. These applications provide you the TOTP code without using any of your personal information.

I agree SMS codes are one a pain in the ass and they are not as secure. TOTP 2 Factor is the most secure you can use without moving to something like a Yubico key (whole different story). If you have been a victim of Identify theft (which I think everyone has been I know I have) then yes using different passwords for each site is good, adding 2FA on top of that is even better. If the site is weak and they lose your password they can't lose the TOTP code because they can't even access it; so that makes it even harder for the attacker. That is why banks are supporting 2FA. I use Authy for Torn, my bank, and many other accounts.

Here is the problem we see in the security world and we saw this with Ring (camera app). People were getting hacked into and they blamed Ring for not using 2FA as an extra layer, but they were not using it. The problem is they didn't force it. So Ring had a PR nightmare because they didn't lead people to do the right thing. It's a damned if you do; damned if you don't situation.

Here are some links for you:
https://authy.com/
https://mashable.com/2017/10/29/how-to-set-up-google-authenticator/
bIgfatone [2094425]
They dont have to be forced, just have it at the top of the torn screen, because i bet alot of people dont have it on because they dont know about it. Not because theyre scared of some random number generation app stealing your data and identity.
Fishbum [2009144]
Who is afraid of the generator stealing your identity? That's just absurd. The more sites you place information on, the more chances you have of information being stolen. 2FA is wholely unnecessary if you limit the information given to sites and choose to not use services that force the sharing of personal information. Comparing a security service such as Ring to a text based game is literally comparing apples to oranges. People have a greater expectation of security from Ring (they shouldn't) because it bills itself as a security service. Torn is a game, and one I place little faith in the security of as we all should. I'm a donator using single use credit card numbers and no real information. This is the best way to handle a site like this. Should a banner be placed at the top of every screen advertising this method because it's by far the best? No.
Hornz [2220919]
2FA is already and option and is encouraged. Users with access to sensitive information are also required to have it.