Skip to content
TORNLIFE More

Passwordless login

Started by DarthSwiftie [3226223] on in Suggestions.

6 replies · 67 views · thread synced · 3 days ago · View on torn.com
About this thread

Posts archived: 7 / 7 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
7
Discussion span
→
People posting
5
Likes on archived posts
8
Authority score
26 / 100
Historical score
22 / 100
Story score
37 / 100
Engagement score
44 / 100
DarthSwiftie [3226223]

Not sure if this is the right place or not, but wouldn't it be nice to login with a physical device (such as a Yubikey) or for mobile users a fingerprint or face? I'm sure quite a few Torn players are a bit more security conscious.

JustAndrey [2527016]

I doesn't really feel like it's necessary. You're logging into a game, not a secret service archive or whatever. I do understand the convenience of not having to type the password and instead using your face or fingerprint. but since you've specified security, I will concentrate on that.

 

Torn wants you to have 2FA. If you care about security you can very easily stack the security measures on top of each other. First you have a normal password, then you have 2FA that turns on when you're logging on from unaproved device (and sometimes even from approved one), you can lock the mail behind the yubikey on pc and biometrics on phone.

 

Even in the case of someone stealing your phone and breaking through biometrics they would still need to get through your password. By that point you will have enough time to remove that phone from approved devices and block the mail, so now on top of the password, they will have to do 2FA, secret question, date of birth and possibly another authenticator.

 

Yubikeys are for lead devs that are actual reasonable targets for hacking. You have 500m nw. You're not even worth brute forcing attempt but you still have options to improve your security far beyond any reasonable measures.

DarthSwiftie [3226223]

Yes, I'm not a target. But I'm sure you know that most attacks aren't "targeted". I just think it would be nice to have as an option. I understand that passwordless logins are relatively new, but they're not just for super secret databases. Amazon and even BestBuy offers this, yet quite a few banks still don't. 

JustAndrey [2527016]

But you already have that option. 2FA pretty much makes your account as secure as is your password + as secure as is your email, to which you can add all sorts of protection as explained second and third paragraph.

 

But I'm sure you know that most attacks aren't "targeted".

Yes but I assume since you care about security you know how non-targetted attacks work which would mean you know that they are mostly targetted towards people technologically illiterate to fall for phishing, click a shady link or use a very easy and popular password, and those who care about security generally don't have to worry about these kinds of attacks, but if you still do, then having a basic email or SMS verification is more then enough to protect against those.

 

but they're not just for super secret databases

Yeah but it's generally good to adjust the security to the threat level. Security conscience is not about throwing as many defenses as possible on everything. It's about actually assesing what even is the threat, the ways it can penetrate the defenses and how to prevent it.

Accountant [3171310]

It is always a good thing to be security conscious, but as mentioned above the Yubikey may be a bit much. 

 

You got to put things into perspective. What is a Torn account worth? Probably not enough to deploy state of the art tools such as Pegasus. So you have very little to worry about. 

 

Just make sure 2FA is on and you don't re-use passwords and avoid sharing devices. And hit that 'log out of all devices' button often when logging out (yes, actually log out if you don't intend to stay logged in on said device!). 

Apate [2348539]

If you are truly this paranoid about your Torn account or distrusting of 2FA alone, why not just use 2FA with a Proton Mail account and use YubiKey for that?