Skip to content
TORNLIFE More

Disabling two-step authenticator

Started by N0BLE [2693523] on in General Discussion.

120 replies · 4.04k views · thread synced · 3 days ago · View on torn.com
About this thread

Posts archived: 121 / 121 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
121
Discussion span
→
Authority score
62 / 100
Historical score
41 / 100
Story score
67 / 100
Engagement score
83 / 100

People posting, likes and official posts are not counted for this thread yet: on threads longer than one page they come from a periodic pass over the archive, which has not covered it.

Most-liked replies

Mentioned in this thread

Duke [4] ×1 Leslie [15] ×1 KneedDrugs [2613284] ×1

N0BLE [2693523]
Better leave it on for security purpose, but for those who could care less about losing your torn account,

Go to settings -> Security settings -> Enter your password -> Two Factor Authentication -> Off

Use more complex passwords tho!
IndyCision [2597200]
Just remember that Ched is reimbursing/restoring all the hacked accounts currently. He will *not* reimburse anyone who is hacked in future if they turn it off.
bogie [148747] Admin Staff
For real. If you actively disable 2FA at this point and your account gets accessed, situation depending, I am extremely unlikely to reimburse any losses.

I will reimburse most times when an account is accessed through seemingly no fault of the user, but this kind of action is more heavily leaning towards it being a player's fault by actively removing protections we put in place. Illegal goods will be removed from those they were sent to either way.
Vargur [94977]
I've NEVER been asked for 2FA and today I was, it's been enabled since they implemented it, it's not worth leaving it on if asking for it becomes the norm from now on. It can't be a coincidence and neither is this thread.
Pops [1025410]
thanks OP, i often come to general discussion for my daily dose of what NOT to do

[image: gyazo.com]

I use a program called WinAuth and make sure to back that up (you can auto sync / encrypt it with 3rd party storage places like google drive / dropbox)

I wish Torn would do more though and support things like YubiKey, i've used and asked for YubiKey integration over a decade ago - its probably only a 5 - 15 minute job to integrate as the SDK is very comprehensive and easy to add in.

If people are concerned about security, using a yubikey alongside a password manager is the ultimate form of protection imo
Marijuana [2400689]
Just stop using the same passwords. Send out a force password reset on login to every account too and make the password requirements more strict.



edit: dont get the downvotes. im not saying to not use 2fa im saying they should force everyone to reset their passwords aswell.
24kGoldn [1614113]
I’m pretty sure I always had 2FA on and I’ve never been asked to do it more than once on my devices. I can’t remember the last time I had a code sent. It should remember your details unless you’re like logging out every time. I never log out of my accounts so maybe that’s why
Jamey112 [2509842]
I disable 2fa because I find it inconvenient... Also my password has been the same for everything for nearly a decade now. Come at me hackers kek
Shoop [1326199]
So do I get to keep the points of those accounts this time?

Edit: I appeared to have a stroke mid sentence and it made no sense.
Taxxon [882264]
People dont just use a random password generator? I can't even hack myself because I don't know my own password! Fool-proof!
Ohadik [424017] Wiki Contributor
Pretty close minded approach. Especially since you know the reason that I disabled 2FA in the first place.

I have a unique password for all my games. So the odds of me getting hacked are pretty low. Not saying impossible, but improbable. I don't think forcing 2FA on people is a good idea.
bogie [148747] Admin Staff
You're welcome to call it closed minded, but actively weakening your account security is empty headed.

You may well have a unique password but I'd say the majority of people do not.
Wenno [2757277]
Trust me, you'll massively regret it if you don't use 2fa and your account gets accessed.

Source: -1 company a few days ago.
Catarchy [2632824]
i have different random high entropy passwords for each single site or service i've ever used, but i kept 2fa with authenticator anyway because i don't want to be a retard like OP.
CoolguyRuler [2183404]
2FA authentication saved my google account and since my google account is tied to literally everything, it pretty much saved my internet life.

I wake up in the morning to see my phone has text messages showing me logon codes, and log into my secondary email to see more of the same(I'd assume the hacker also tried the authenticator app and keys I have set up). Needless to say, I promptly changed the password I had not changed in 11 years since account creation. In that case it was that the password was [password removed] old and hackers had a lot of time to break it.

But 2FA makes an account unbreakable even if the hacker should(however slim) guess the correct password.
Ohadik [424017] Wiki Contributor
No, you using the same password for everything is the problem. Has nothing to do with 2FA.
Ohadik [424017] Wiki Contributor
2FA does no such thing. If you use the same password for everything. You can still get hacked with or without 2FA.

All they have to do is know is to log into the 2nd account with the same password, and BOOM... They are in. 2FA doesn't actually protect anyone, because if they found your password on one thing and accessed your torn, they'll get it on the other method, most likely the same password.

For 2FA to work, it relies on you having different passwords for all your crap. The people getting hacked have the same password for everything. If you only use 1 password, 2FA is useless.