Corronchilejano
Member
I need this. I actually store all important passwords in my private messages and generate new ones from subscribed thread titles.
I for one, can't wait until gaf implements penis scan authentication.
I need this. I actually store all important passwords in my private messages and generate new ones from subscribed thread titles.
2 Step authentication is the future of securing our precious accounts. Would you guys like to see NeoGAF incorporate the Google app into their login process? Yes, there will be quite a bit of extra development, but will secure our accounts tenfold.
over the top. It's just a forum. Mods don't do this, it's uneeded.
Gaf has greater security issues, mostly related around the email restrictions and needing to contact someone to change your email.
Email restrictions make it so that if your email address was ever compromised and you didn't have another "private" email address, you're unable to prevent the spread of the compromise without finding a person to do it for you and hoping they take care of it in time. The only good thing is that passwords aren't sent to an email, instead it uses password reset links. It's a restriction that has no upside and only downside for users. I don't really know what the methodology behind it is for the site either.
Two factor really only exists in the consumer market because people are so lazy and mindless about what passwords they use. Education on decent password creation and management would be better than 2 factor in almost all consumer cases.
Waste of resources just to keep your forum account safe.
That's not true at all; I don't think you know what you're talking about. Do you think most passwords are cracked by random guessing? That's not the case. Systems get compromised and passwords are leaked. 2 step exists to make sure that even if a password is leaked, the secondary passcode will still be required for login.
Two factor really only exists in the consumer market because people are so lazy and mindless about what passwords they use. Education on decent password creation and management would be better than 2 factor in almost all consumer cases.
Passwords can be bruteforced offline.
Proper use of 2 factor (in that you don't give someone the second factor) is not, not only because it requires physical possession but also because the 2nd factor is (usually) time sensitive.
It's one of the better security practices, and will probably eventually be near standard in the future, but as it is the threat potential for a forum isn't high enough for it.
This isn't really true, sorry. Sites with poor user security tend to not store financial and personal data. The ones that do, use expensive and responsive services to deal with the fallout, ie target, etc.
The problem comes from unsecure sites being hacked and releasing passwords. Then those passwords being used across multiple services, such as banking, retirement accounts, etc.
If my MySpace password from 2005 got leaked to the world, I wouldn't be thankful two factor secured my account on that service. I would be fucked if that password was used across multiple services. That's the real culprit.
The day I have to pull out some app just to log in to NeoGAF any given day is going to be a terrible one.
I probably log in to this damn site over 20 times a day out of habit. I have a strong password, i'm not worried.
Optional 2FA has been looked into as part of overall security updates. The main concern I've noted, though, isn't that NeoGAF accounts tend to actually be compromised, as they're not high value targets in terms in terms of facilitating identity theft or fraud etc. like your bank account login or primary email login etc. might be, but that members in some cases end up losing access to their accounts eventually: if their isp/academic/work registration email dies wiithout their knowledge and they subsequently lose their NeoGAF password, they're then unable to recover their account without admin intervention. So, while full optional 2FA may or may not be overkill realistically, an account recovery option at least (like an SMS or backup permanent email address associated with your account) is on the to-do list if feasible and I've been looking into possible solutions there.
Expect many updates and improvements rolling out throughout 2016. There's a lot on the agenda.
Very excited to see an updated site, thanks EviLore.Optional 2FA has been looked into as part of overall security updates. The main concern I've noted, though, isn't that NeoGAF accounts tend to actually be compromised, as they're not high value targets in terms in terms of facilitating identity theft or fraud etc. like your bank account login or primary email login etc. might be, but that members in some cases end up losing access to their accounts eventually: if their isp/academic/work registration email dies wiithout their knowledge and they subsequently lose their NeoGAF password, they're then unable to recover their account without admin intervention. So, while full optional 2FA may or may not be overkill realistically, an account recovery option at least (like an SMS or backup permanent email address associated with your account) is on the to-do list if feasible and I've been looking into possible solutions there.
Expect many updates and improvements rolling out throughout 2016. There's a lot on the agenda.
Usurping EviLore starts somewhere.What value is there in stealing a NeoGAF account?
Optional 2FA has been looked into as part of overall security updates. The main concern I've noted, though, isn't that NeoGAF accounts tend to actually be compromised, as they're not high value targets in terms in terms of facilitating identity theft or fraud etc. like your bank account login or primary email login etc. might be, but that members in some cases end up losing access to their accounts eventually: if their isp/academic/work registration email dies wiithout their knowledge and they subsequently lose their NeoGAF password, they're then unable to recover their account without admin intervention. So, while full optional 2FA may or may not be overkill realistically, an account recovery option at least (like an SMS or backup permanent email address associated with your account) is on the to-do list if feasible and I've been looking into possible solutions there.
Expect many updates and improvements rolling out throughout 2016. There's a lot on the agenda.
LOL Precious accounts and GAF in the same sentence.
I like this site and its a decent time waster. But its not email or banking.
So, while full optional 2FA may or may not be overkill realistically, an account recovery option at least (like an SMS or backup permanent email address associated with your account) is on the to-do list if feasible and I've been looking into possible solutions there.
Expect many updates and improvements rolling out throughout 2016. There's a lot on the agenda.
That would probably be the best option for now.
Usurping EviLore starts somewhere.
It'll be available on Mobile too i'm sure. No worries.
I wonder what his version of NeoGAF looks like.
It'll be available on Mobile too i'm sure. No worries.