What is the benefit of two factor identification? I apparently forgot my security answer and it seems like a lot of hoops to jump through and potentially risky (getting locked out or something). I emailed Bodie and he said it wouldn't lock me out, but didn't explain the benefit or risk of not doing anything? Thanks for the explanation. I don't intend to do anything until i hear some reasons why as i don't want other issues to arise after clicking the account recovery button.
two factor identification
Started by ApexOscar81_9 [2098801] on in Questions & Answers.
About this thread
Posts archived: 6 / 6 posts (100%) · the total is Torn's reply count + the opening post at the last fetch
Counted by TornLife from the archived posts.
- Archived posts
- 6
- Discussion span
- →
- People posting
- 5
- Likes on archived posts
- 10
- Authority score
- 43 / 100
- Historical score
- 16 / 100
- Story score
- 30 / 100
- Engagement score
- 50 / 100
Most-liked replies
- Beerstein [1322136]
· 5 likes ·
Many sites, even major trusted ones get hacked almost inevitably. It's not the user-end that your concern should be focused at if you're cautious, it's company end. If you use the same password multiple places, it's a massive risk to …
Multifactor authentication raises account security, because even if someone obtains your password, they can't login to your account without also physically accessing your phone for the 2FA.
https://www.avg.com/en/signal/what-is-two-factor-authentication#:~:text=Two-factor%20authentication%20(or%20two,to%20break%20into%20your%20accounts.
This link explains *a lot* about 2FA, mainly the security aspect.
Using this, means that you have to log in with both your password and another factor (code from sms or authentication app, or email. I'd recommend an authentication app, as it's the most secure).
It will also make recovery easier, as they can use it to more easily verify that you are who you say you are, but I'd say that the main advantage is security.
I can rant for ages about how insecure "security" questions are, same for date of birth verification, but I'll save that for another day.
If you use 2FA, you can still use a combination of password, and an email code to get into your account, depending on security settings.
This link explains *a lot* about 2FA, mainly the security aspect.
Using this, means that you have to log in with both your password and another factor (code from sms or authentication app, or email. I'd recommend an authentication app, as it's the most secure).
It will also make recovery easier, as they can use it to more easily verify that you are who you say you are, but I'd say that the main advantage is security.
I can rant for ages about how insecure "security" questions are, same for date of birth verification, but I'll save that for another day.
If you use 2FA, you can still use a combination of password, and an email code to get into your account, depending on security settings.
Sounds critically important for bank and financial sites. Not sure if Torn falls into that category for me. Thanks again.
Many sites, even major trusted ones get hacked almost inevitably. It's not the user-end that your concern should be focused at if you're cautious, it's company end. If you use the same password multiple places, it's a massive risk to ALL sites you use. If you don't, there's still a risk to that one if it is compromised. Using authenticator almost completely removes this risk if your password is compromised.
By that, I mean working on the other end of this I've seen more people than I can count "hacked" and exactly 0 with authenticator hacked.
Google plans to default gmail etc. to using authenticator, so it may be something you just want to jump on board with now. It's almost a basic security level in my opinion that patches the fact that passwords are so frequently compromised via bad policies, weak systems, social engineering hacks etc. that they seem not just a risk but practically an inevitable weak point in security across the multitude of websites people use logins for.
As an additional note: It's mandatory for Torn staff/committee
By that, I mean working on the other end of this I've seen more people than I can count "hacked" and exactly 0 with authenticator hacked.
Google plans to default gmail etc. to using authenticator, so it may be something you just want to jump on board with now. It's almost a basic security level in my opinion that patches the fact that passwords are so frequently compromised via bad policies, weak systems, social engineering hacks etc. that they seem not just a risk but practically an inevitable weak point in security across the multitude of websites people use logins for.
As an additional note: It's mandatory for Torn staff/committee
Back in the old days of Torn you logged in with your game name, not your email. So it was a common scam for people to pretend they are staff and ask you for your password. Then log in as you and wipe our your account and your faction if you had permissions.
Those accounts were banned, but they didn't return the items that were taken do to "user error"
More recently a list of emails an passwords got leaked onto the dark web. So if you use the same password here as you do on other sites someone could log in that way if you don't have 2FA on. (Staff had a very busy week that week because it happened to multiple people)
I highly recommend 2FA to keep your account safe.
Those accounts were banned, but they didn't return the items that were taken do to "user error"
More recently a list of emails an passwords got leaked onto the dark web. So if you use the same password here as you do on other sites someone could log in that way if you don't have 2FA on. (Staff had a very busy week that week because it happened to multiple people)
I highly recommend 2FA to keep your account safe.