I appreciate updated security on account, especially with all the data hacks we keep hearing about these days, however I do not see anywhere that indicates Ched or any TC staff will not take the information provided and give it or sell it to a third party under the guise of "Two-factor authentication & Additional security".
There are a wide range of people including minors all the way up to seniors that do not deserve to have their personal information distributed by Ched or any other person associated with TC without their permission.
Please provide assurance that our personal information will not be given, sold or used without explicit consent.
Yeah and stuff
Your mobile phone number/Details/Secret question is encrypted with 256-bit and will not be shared with third parties...
It states that on the page, so there's some kind of assurance..
But I'm sceptical and don't really trust torn staff so I decided not to put my details there..
Have to agreed.
If I recall there was an incident earlier this year regarding 'staff' and personal info. So call me Mr Cynical if I don't really want to give out my personal details.
Especially as you now have my email - with my DOB, phone number, password and a secret question?
Not a chance.
Knowing Torn staff, i would probably get phone calls from Icey cos everyone knows he loves me.
"It's not discrimination if it's true" - IceBlueFire
Words to live by.
Figures your name is cynic. Being drug free and all.
FFS, don't pick that scab and have 'em all shout at me for spurting puss at them.
I'm not drug free... I'M A SSL USER.
They're collecting personal info then will sell it later
[image: s-media-cache-ak0.pinimg.com]
No staff have access to any of that stuff. They can't see passwords, mobile phone number, date of birth or secret question answer. Even though they have proved their trust over many years of service, it's just bad practice to make any information like that available when it's not essential.
I can't even view that stuff without going to an off-site page allowed only for my IP, entering my Torn account password, and then yubikey authentication.
Even after all that, I also really don't care about having access to your date of birth, mobile phone number, or knowing who your first kiss was. It's literally there for your own security, or to confirm that you are the official owner of the account in the event that it is lost.
As long as we don't have a torn style adobe leak i'm sure we'll be all good, i believe that's more what OP is worried about.
If i give you my number will you ring me up?
Would adding additional forms of 2-factor be considered? Things like Google Authenticator work wonders for things like this, and I already secure lastpass, dropbox, evernote, etc with it...
Then people can stop being weird about their cell numbers being stored.
Data "hacks" are typically someone that has been loose with their password. I don't think sessions are stolen all that often, though, it does happen.
Yes, additional authenticators are planned. I felt at least initially, they might confuse the 2FA process for non tech-savy players - and it's essential that we get everyone on-board asap.
I don't care that you know. It's your game/business after all.
But I do care that some arsehead who DOES have a vested interesting in wanting to know has access to this rather valuable source of info, especially as this as been an issue in the past... Pretty sure you can understand where our mistrust comes from.
That said, with what you have said, I am sure it has alleviated some of this 'mistrust'.
Why not go for the 'road in between' and enable us to see the last 10 IP's (or more) that logged into our account?
As in
Login History - suggestion Thanks for replying personally btw, this is important.
Mentions:
Login history? --> 100 upvotes, staff contacted
Only late at night
(when he needs your love)
Another thing to mention, when I am on the Preferences page I see that https is not working and the security info says:
"Further, this page includes other resources which are not secure. These resources can be viewed by others while in transit, and can be modified by an attacker to change the look of the page."
That'd be elements inside your profile signature causing that I imagine. We are working on the ability to force https:// so this won't be any concern in the near future.
With no irony intended whatsoever I don't understand: what is being said about all this security and giving away my details scares me so thank you but no thank you.
I don't think anyone wants to hack some noob called 'cathead' in an online game.