Or you could just, you know, use 2FA.
I do. Still paranoid.
Or you could just, you know, use 2FA.
The 2fa is a little flawed on psn...it needs some direct link like ms do with their ms account app where it asks you to approve a log in or requests from a different location .
The issue with sonys 2fa is that it does not always ask you for a code when logging in from different locations...if you have the password you can still login and have access to the account holders name...the purchase history and other basic stuff that is asked in the webchats or phone calls
My account was hacked just recently and i was suprised at how basic it was to get control of the account again through webchat.
reading this thread made me finally stop "beating around the bush" and finally enabled my 2FA
Jeez... there's a thread like this every day... wtf Sony. :|
Looks like the specific site for 2FA is currently down. Can you enable 2FA through the ps4?? thanks
Whenever I need input my password I need get a new code from 2FA too. Your post seems completely wrong.
From a known device you wouldn't. However you should get a 2FA request from a new device.Not sure if its a setting but i dont always get the 2fa pop up when logging in
Only when i request a password change
Or you could just, you know, use 2FA.
Looks like the specific site for 2FA is currently down. Can you enable 2FA through the ps4?? thanks
Why would you click a link in an unsolicited email?
Apologies for bumping this thread, but I don't know where else to post this. I had a text at midnight giving me a verification code (I have 2FA enabled), I have heard this has been a bug before, as a couple friends and people online had texts through even though know one was trying to access their account.
I tried logging this morning and couldn't, so I immediately went to change my password. I logged into my email, and saw that an email came through at midnight from PlayStation stating that my password had been reset (knowing full well I hadn't changed it at that time, I assumed somebody was trying to compromise my account), luckily for me I followed my password reset link, and have managed to sort it.
My question is, how the fuck can someone change my password without access to the code i received through text?
This is worrying.
Exactly.
Just a quick update. I've found out that they managed to access my EA account, 10 minutes prior to accessing my PSN account. I now have access to both and have reset my password.
I hadn't touched my EA account in perhaps 1-2 years, and it didn't have 2FA enabled. It now does. I'm assuming they gained access to my PSN through my EA account somehow? (Both are linked)
It seems the password wasn't changed, but that Sony reset it because of suspicious activity.
Did you have the same email and password for both?
I'm not convinced they actually got into your psn account. Surely they would have changed the email straight away. Especially since this happened overnight?
You should make a new thread. Someone here on gaf said before that even 2FA can have issues, but didn't explain more. Scary.
You should make a new thread. Someone here on gaf said before that even 2FA can have issues, but didn't explain more. Scary.
I'm glad 2FA is around, but I find it highly annoying and will never use it again. I use great passwords instead and change them now and then. I have never had any problems, and I hope I never do.
Are they unique to that account or not?
Apologies for bumping this thread, but I don't know where else to post this. I had a text at midnight giving me a verification code (I have 2FA enabled), I have heard this has been a bug before, as a couple friends and people online had texts through even though know one was trying to access their account.
I'm curious how did you and your friends determine that a received code was a bug in the 2FA system and not an adversary trying to access your accounts?
I'm curious how did you and your friends determine that a received code was a bug in the 2FA system and not an adversary trying to access your accounts?
I got a text last night for the 2FA code. It makes me feel creeped out.
There is this one guy that keeps saying it in every topic without ever giving detail when he is challenged.
There initially was a bug where you could potentially be bombarded with codes.
ItÂ’s a completely different scenario. So yes make a new thread for it. Bumping old threads is rather confusing.I was going too but didn't know whether this warranted another thread.
My question is still how was it determined to be a bug and not adversarial behavior?
Woah, is that the only situation that would trigger it? Damn. Time to change the password.It should. It means someone has your password.
Aside from 2FA, folks should add aliases to email addresses if you use Gmail using +alias
youremail at gmail dot com
to
youremail+whateveryoutypehere at gmail
Anything that's "+whatever" will get sent to your main address. Not only is it an extra layer of protection but you can have different extensions for different sites.
It's also good to see which asshole company gives your email address out to their friends.
Speed of texts, and it stopping when turning 2FA on/off again. You expect it to continue.
Woah, is that the only situation that would trigger it? Damn. Time to change the password.
Sorry not sure I understand. You can add random shit onto your email address and it'll still deliver?
I assume the point here is you'll still get the email, but that email address won't be valid to actually log into PSN?
Sorry not sure I understand. You can add random shit onto your email address and it'll still deliver?
I assume the point here is you'll still get the email, but that email address won't be valid to actually log into PSN?
I'd like to use 2FA, but as far as I can tell, it's a mess to setup for PS3... Even the official tutorial from Sony points toward a 404 page, and the things they say are in menus definitively aren't.So people if you care about your account use 2FA. Use unique email address and password for your psn account. This way you can be sure this wont happen.
Woah, is that the only situation that would trigger it? Damn. Time to change the password.
Im gonna explain these Stolen account procedures so people know what they are dealing with
Everyday people's email addresses and passwords are stolen from legit websites without them knowing or they signup in shady sites that are collecting these information purposefully and Many people use exact same email and password for everything they sign up for.
These stolen email addresses and password form lists and with using some hacking programs, simple scripts and multiple vpn servers everybody can bombard sony's servers to find accounts with matching emails and passwords. When the account owner doesn't use 2FA, they can access the account easily. Then they dump name of games purchased via that account and make shortlists of various accounts they've got access to.
These accounts are sold in boundles very cheap.
What happens next is someone that buys these Boundles use Playstation app to check that account owner is not online and using it. Then they access the account via psn website and use deactivate ps4 systems and then they activate as primary the account on their own ps4. they go through that library and download whatever game the account has and logout from the account. They don't change password or change email address. By doing this they make it harder for accounts owners to find out about their accounts and even proving it to sony that their account is actually stolen. And so many times account owner never finds out about this.
And if the account owner actually finds out about it and can prove the matter, the stealing party only loses those games and rarely theire ps4 gets banned from psn.
Its outright disgusting people are stealing peoples accounts and sony must be held responsible for their weak security. One simple solution would be needing an email confirmation for deactivating the account. Because there is a chance that email itself use different password. Making 2FA mandatory is another solution.
So people if you care about your account use 2FA. Use unique email address and password for your psn account. This way you can be sure this wont happen.
I hope i dont get in to trouble for sheding some light on This matter.
I'd like to use 2FA, but as far as I can tell, it's a mess to setup for PS3... Even the official tutorial from Sony points toward a 404 page, and the things they say are in menus definitively aren't.
(Though I still don't understand how they would get access to a PSN account if you use unique decent password)
I'd like to use 2FA, but as far as I can tell, it's a mess to setup for PS3... Even the official tutorial from Sony points toward a 404 page, and the things they say are in menus definitively aren't.
(Though I still don't understand how they would get access to a PSN account if you use unique decent password)
Was your PSN, EA accounts passwords the same? PSN password should always be unique meaning you never made that password before or currently no other account of yours have that passwordExactly.
Just a quick update. I've found out that they managed to access my EA account, 10 minutes prior to accessing my PSN account. I now have access to both and have reset my password.
I hadn't touched my EA account in perhaps 1-2 years, and it didn't have 2FA enabled. It now does. I'm assuming they gained access to my PSN through my EA account somehow? (Both are linked)
If for example you used danthefan+neogaf@gmail.com, that would be your login username but all emails would get delivered to danthefan@gmail.com. It's good because like what the other poster said you can pinpoint which service may be compromised should that happen and it'd also an easy way to have multiple separate emails for sign ups without having to make different ones each time.
Edit: beaten!
Yes, using Gmail you can use the + sign to add an alias to your email address and you will still receive the mail (or you can just add many . as you want).
It is still a valid email address to log into PSN, if you specified it in your account settings. You can use different aliases for different accounts, though.
Like name+psn@gmail.com or name+origin@gmail.com and so on.
Not heard about 2FA but obviously will switch on if/when it's sorted.
Through now...wish me luck