• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Sony rolling out two-factor authentication: AUS+NZL tomorrow, other regions to follow

JP

Member
There we go, finally. :)

Please don't rely on it as being enough though, it's just one step of many that people should be taking to protect all their online accounts. Unfortunately, I don't think we'll get any fewer "My PSN got hacked" threads than we do now.
 

Mr Git

Member
Christ on a fucking bendy bus. About time.

I'd say maybe they saw the ridiculous frequency of threads about it recently, but then that's been happening for years.
 

grimmiq

Member
Stupid question about 2FA..

Is it similar to security tokens for MMOs? Every time I login on my console I need to get out my phone and input the code? Or is it once per location as in "You are attempting to log in from an unknown location, do you want to verify this location?"..I'm assuming it will be required for all transactions regardless of where you are.
 

5taquitos

Member
Stupid question about 2FA..

Is it similar to security tokens for MMOs? Every time I login on my console I need to get out my phone and input the code? Or is it once per location as in "You are attempting to log in from an unknown location, do you want to verify this location?"..I'm assuming it will be required for all transactions regardless of where you are.

Going by the OP's post, it sounds like it will only be for first logins on new devices. Once you enter the code for your home PS4, you won't need to enter one again. if someone tries to login with your account on another PS4, they'll be prompted for the SMS code.
 
Ok but what happens if youre already hacked and someone beats you to the punch in setting up a number?

Also, what if your primary account is on a friend or family members ps4?
 

RootCause

Member
Oh crap! I thought this day would never come. It's nice to see Sony do something, even if they made us wait years for it.
 

Raw bars

Banned
A blessing for play station owner's for sure. Glad to hear. Now people with Verizon should still be a little worried. Apparently they give out info with out confirming that you are really you( the account holder).

Context: boogie2988 was recently hacked, someone was able to get access to his Verizon account by calling customer service. Once they had his info they where able to get into his YouTube account and some social media and they deleted his youtube channel.
 

Rellik

Member
There we go, finally. :)

Please don't rely on it as being enough though, it's just one step of many that people should be taking to protect all their online accounts. Unfortunately, I don't think we'll get any fewer "My PSN got hacked" threads than we do now.

Then why don't we see "My Xbox/Steam account got hacked" threads every other day like we're getting PSN hijacks recently? Maybe because they have 2FA?

If people actually use it, there will definitely be a big reduction in cases.
 

JP

Member
Then why don't we see "My Xbox/Steam account got hacked" threads every other day like we're getting PSN hijacks recently? Maybe because they have 2FA?

If people actually use it, there will definitely be a big reduction in cases.
Why don't you see these threads? No idea.
 
This is long overdue, but I'm glad that Sony is finally getting their priorities straight and stepping up their security. I'd love if there was an option to have to approve of all purchases via SMS, but first time login works well too.
 
This is a good start, but I was hoping they'd implement it so you could use it with google authenticator/Authy. Or just put it in their app like Battlenet or Steam. Maybe there'll be more in the announcement. Fingers crossed.
 

Atomski

Member
Embarrassed to have taken their time with it sure but even Microsoft didn't have 2FA until 2013. 2FA in 2006 would have been way ahead of its time.

Im sure hes talking about the beginning of ps4..

Anyways good on them.. its a bit late but at least they have finally got to it.
 
Now people won't have an excuse when they are irresponsible with their logins. Always had a issue with people screaming that they've been hacked but in reality it's social engineering or using same passwords on other services.
 
D

Deleted member 325805

Unconfirmed Member
tumblr_myz4pvk1nF1schu5jo1_500.gif
 

STEaMkb

Member
Then why don't we see "My Xbox/Steam account got hacked" threads every other day like we're getting PSN hijacks recently? Maybe because they have 2FA?

We still see a small number of posts on Reddit:

Code:
25 Dec https://www.reddit.com/r/xboxone/comments/3y7p64/so_someone_just_spent_hundreds_of_dollars_on/
29 Dec https://www.reddit.com/r/xboxone/comments/3ynjbg/my_xbox_live_profile_was_hacked_but_i_got_it_back/
07 Jan https://www.reddit.com/r/xboxone/comments/3zxynj/somebody_logged_into_my_password_protected_profile/
11 Jan https://www.reddit.com/r/xboxone/comments/40i8rd/my_microsoft_account_was_hacked_and_i_cant_get_it/
13 Jan https://www.reddit.com/r/xboxone/comments/40qldf/wtf_i_think_i_just_got_hacked200_never_winter_zen/
15 Jan https://www.reddit.com/r/xboxone/comments/410omj/problem_with_xbox_account/
20 Jan https://www.reddit.com/r/xboxone/comments/41v8vm/escalating_account_issue_with_microsoft/
23 Jan https://www.reddit.com/r/xboxone/comments/42ape2/tech_account_hacked_xbox_live_no_longer/
28 Jan https://www.reddit.com/r/xbox/comments/431sbn/help_somebody_hacked_my_account_and_is_making/
02 Feb https://www.reddit.com/r/xboxone/comments/43rxhi/techsupport_question_from_a_new_user/
04 Feb https://www.reddit.com/r/xboxone/comments/4440mg/did_my_email_get_compromised_or_my_xbl/
13 Feb https://www.reddit.com/r/xbox/comments/45kk4m/account_was_hacked_last_night/
22 Feb https://www.reddit.com/r/xboxone/comments/473smj/xbox_live_account_compromised_support_being/
15 Mar https://www.reddit.com/r/xboxone/comments/4akkz4/psa_turn_on_2_step_verification_or_lose_your/
21 Mar https://www.reddit.com/r/xboxone/comments/4bd1x5/has_anyone_ever_had_trouble_recovering_a_hacked/
09 May https://www.reddit.com/r/xboxone/comments/4ihdy5/am_i_fucked_my_account_was_hacked_and_i_have/
24 May https://www.reddit.com/r/xboxone/comments/4ktuyb/microsoft_saved_my_bank_account/
26 Apr https://www.reddit.com/r/xboxone/comments/4ggh2i/someone_hacked_my_microsoft_account/
15 Jun https://www.reddit.com/r/xboxone/comments/4o5rz8/just_a_reminder_to_get_twostep_verification_on/
19 Jun https://www.reddit.com/r/xboxone/comments/4ovcqu/just_got_an_email_saying_that_my_account_had_been/
22 Jun https://www.reddit.com/r/xboxone/comments/4p9z20/someone_hacked_and_stole_my_xbox_handle_how_do_i/
25 Jun https://www.reddit.com/r/xbox/comments/4pr08x/did_i_just_lose_my_account_for_good/
26 Jun https://www.reddit.com/r/xboxone/comments/4pv7ev/another_reminder_to_enable_two_factor_verification/
02 Jul https://www.reddit.com/r/xbox/comments/4qykar/got_my_account_back_then_i_found_out_im/
31 Jul https://www.reddit.com/r/xboxone/comments/4vi80c/microsoft_temporarily_disabled_my_account_because/
04 Aug https://www.reddit.com/r/xboxone/comments/4w44mk/tech_cant_login_to_my_account_after_activating/

If people actually use it, there will definitely be a big reduction in cases.

I wonder what percentage will enable it.
 

Vex_

Banned
Looks like our threads worked, gaf!!!


Now the question is: would they have bothered to get it out as quick as they did without us drawing attention to it?
usure.png
 

EmiPrime

Member
Looks like our threads worked, gaf!!!


Now the question is: would they have bothered to get it out as quick as they did without us drawing attention to it?
usure.png

"As quick as they did"?

The GAF threads didn't do anything. It has been on the cards since Sony announced it in April.
 

STEaMkb

Member
Edit: Fuck. On haveibeenpwned.com says that my e-mail was disclosed on FUCKING SIX different data breach.

Now I know how my Origin account was hacked at the end of 2014.

Kill that email address with fire! lol

Still not putting any financial data on their systems.

Are you willing to put your information on a Microsoft system? The only reason I ask is, Microsoft was hacked in a pretty epic fashion 2011-2013. It was only because the hackers were ardent Xbox fanboys they decided not to go after user data.
 

Slaythe

Member
We still see a small number of posts on Reddit:

Code:
25 Dec https://www.reddit.com/r/xboxone/comments/3y7p64/so_someone_just_spent_hundreds_of_dollars_on/
29 Dec https://www.reddit.com/r/xboxone/comments/3ynjbg/my_xbox_live_profile_was_hacked_but_i_got_it_back/
07 Jan https://www.reddit.com/r/xboxone/comments/3zxynj/somebody_logged_into_my_password_protected_profile/
11 Jan https://www.reddit.com/r/xboxone/comments/40i8rd/my_microsoft_account_was_hacked_and_i_cant_get_it/
13 Jan https://www.reddit.com/r/xboxone/comments/40qldf/wtf_i_think_i_just_got_hacked200_never_winter_zen/
15 Jan https://www.reddit.com/r/xboxone/comments/410omj/problem_with_xbox_account/
20 Jan https://www.reddit.com/r/xboxone/comments/41v8vm/escalating_account_issue_with_microsoft/
23 Jan https://www.reddit.com/r/xboxone/comments/42ape2/tech_account_hacked_xbox_live_no_longer/
28 Jan https://www.reddit.com/r/xbox/comments/431sbn/help_somebody_hacked_my_account_and_is_making/
02 Feb https://www.reddit.com/r/xboxone/comments/43rxhi/techsupport_question_from_a_new_user/
04 Feb https://www.reddit.com/r/xboxone/comments/4440mg/did_my_email_get_compromised_or_my_xbl/
13 Feb https://www.reddit.com/r/xbox/comments/45kk4m/account_was_hacked_last_night/
22 Feb https://www.reddit.com/r/xboxone/comments/473smj/xbox_live_account_compromised_support_being/
15 Mar https://www.reddit.com/r/xboxone/comments/4akkz4/psa_turn_on_2_step_verification_or_lose_your/
21 Mar https://www.reddit.com/r/xboxone/comments/4bd1x5/has_anyone_ever_had_trouble_recovering_a_hacked/
09 May https://www.reddit.com/r/xboxone/comments/4ihdy5/am_i_fucked_my_account_was_hacked_and_i_have/
24 May https://www.reddit.com/r/xboxone/comments/4ktuyb/microsoft_saved_my_bank_account/
26 Apr https://www.reddit.com/r/xboxone/comments/4ggh2i/someone_hacked_my_microsoft_account/
15 Jun https://www.reddit.com/r/xboxone/comments/4o5rz8/just_a_reminder_to_get_twostep_verification_on/
19 Jun https://www.reddit.com/r/xboxone/comments/4ovcqu/just_got_an_email_saying_that_my_account_had_been/
22 Jun https://www.reddit.com/r/xboxone/comments/4p9z20/someone_hacked_and_stole_my_xbox_handle_how_do_i/
25 Jun https://www.reddit.com/r/xbox/comments/4pr08x/did_i_just_lose_my_account_for_good/
26 Jun https://www.reddit.com/r/xboxone/comments/4pv7ev/another_reminder_to_enable_two_factor_verification/
02 Jul https://www.reddit.com/r/xbox/comments/4qykar/got_my_account_back_then_i_found_out_im/
31 Jul https://www.reddit.com/r/xboxone/comments/4vi80c/microsoft_temporarily_disabled_my_account_because/
04 Aug https://www.reddit.com/r/xboxone/comments/4w44mk/tech_cant_login_to_my_account_after_activating/



I wonder what percentage will enable it.

MANY people have alt accounts for the other regional stores.

I'm in EU and I have a US and JP store.

In no way is this solution helping me.
 
This is very nice, but I'm hoping for Authenticator/Authy support too!

SMS is much better than nothing though and I'll gladly take it! Hope they enable it by default.
 

hwy_61

Banned
Do not save your payment information on PSN.

IDGAF if it's 10 factor authorization don't save your payment information.
 

EmiPrime

Member
This is very nice, but I'm hoping for Authenticator/Authy support too!

SMS is much better than nothing though and I'll gladly take it! Hope they enable it by default.

They won't. They'd be inundated with phone calls and support tickets asking them how to turn it off.
 
No major service enables 2-factor by default

Maybe I meant more of a "strongly encourage you to turn it on" like Google does when you don't have 2FA enabled. Basically, I don't want Sony to just say "hey it exists!" and then keep relatively mum on it for the masses.
 

Mithos

Member
I hope is 2-step using app, and not just text sms (as it sounds on the picture from the PS3), coz they ain't getting my numba!
 
Top Bottom