Skip to content
TORNLIFE More

Random One-time authorization code emails.

Started by Reverend [2269743] on in Bugs & Issues.

4 replies · 60 views · thread synced · 7 days ago · View on torn.com
About this thread

Posts archived: 5 / 5 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
5
Discussion span
→
People posting
4
Likes on archived posts
1
Posts by staff, officers and moderators
1
Authority score
55 / 100
Historical score
29 / 100
Story score
33 / 100
Engagement score
41 / 100

Most-liked replies

Reverend [2269743]
Greetings,

This in the second random TWO-FACTOR AUTHENTICATION YOUR ONE TIME PASSWORD email received from TC. It is when I'm already logged in and playing. Is someone trying to recover my account information, or a glitch in the TC matrix?
python [1009878]
Best change your password on email and torn just to be sure would usually only be triggered by the recovery or attempt of logging in,
Not sure if the logs show attempted logins
CloudJumper [1636201]Staff
You can check the logs here which also tell you the IP address, it is all being requested from your normal IP address.

If you clear the site cookies or use Incognito mode/new device/browser, then you will have to validate the new configuration which is what the Emails are for.

You can switch 2FA method to Authenticator, it is more secure and does not create email/SMS spam like this.

Thanks!
Borg1of1 [2283190]
@admins,

Have you all considered a move away from passwords all together? Perhaps using OTP from an app like the Google or MS Authenticator might improve the security of player accounts since there would no longer be a password to steal. An attacker would have to spoof the output from an OTP provider. I think you all have the plumbing in place now since you send OTPs to email. Email is not ideal as it can also be compromised and many users reuse passwords. Using an app would strengthen the protection of accounts.
python [1009878]
Email is just the default authentication apps are already in use and recommended to switch to can be done in the security settings