d2jsp
Log InRegister
d2jsp Forums > d2jsp > General Help > Site Suggestions >
Poll > Two Factor Authentication
12Next
Closed New Topic New Poll
  Guests cannot view or vote in polls. Please register or login.
Member
Posts: 924
Joined: Aug 1 2006
Gold: 15,320.00
Nov 25 2018 05:30am
TOTP and/or U2F support would be fantastic, and a great way to improve security.

Right now, all that's needed to compromise an account is access to the owner's email address.

This post was edited by xXZyZXx on Nov 25 2018 05:33am
Retired Moderator
Posts: 26,153
Joined: Nov 6 2006
Gold: 77.33
Trader: Trusted
Nov 25 2018 05:55am
Yes, if one of the commonly used methods/standards could be implemented.
Member
Posts: 13,136
Joined: Dec 26 2006
Gold: 44.69
Nov 25 2018 07:28am
Google authenticor would be good to use for this
Definitely see use considering some people have enough fg to buy a car
Member
Posts: 924
Joined: Aug 1 2006
Gold: 15,320.00
Dec 5 2018 01:35am
Quote (Qry @ Nov 25 2018 04:55am)
Yes, if one of the commonly used methods/standards could be implemented.


Yeah, that's what TOTP is. Authy, Google Authenticator, etc. all use this.

This post was edited by xXZyZXx on Dec 5 2018 01:36am
Member
Posts: 122,803
Joined: May 2 2009
Gold: 20,232.06
Dec 5 2018 01:42am
is that how you got this account? :rofl:
Member
Posts: 15,294
Joined: Feb 7 2008
Gold: 12,289.00
Dec 5 2018 02:48am
Yes, Google auth instead of required gold password. Ty.
Member
Posts: 3,719
Joined: Feb 8 2014
Gold: 0.00
Dec 5 2018 07:23am
Quote (Cfwx @ 5 Dec 2018 01:48)
Yes, Google auth instead of required gold password. Ty.


Gold passwords aren't leaving for a long, long, LONG time.
Member
Posts: 6,143
Joined: Mar 22 2016
Gold: 1,000.00
Trader: Trusted
Dec 5 2018 07:54am
Gold password is a million times better, in my books.

2 FA is lame and time consuming... People will have problems when they change emails & phone numbers, etc. I also don't like to rely on google to not charge for this service in the future...

Big and firm No - I don't like to rely on external technique .
Member
Posts: 15,294
Joined: Feb 7 2008
Gold: 12,289.00
Dec 5 2018 08:01am
Quote (bvanharjr @ 5 Dec 2018 14:23)
Gold passwords aren't leaving for a long, long, LONG time.


That’s fine. Just remove the requirement of having one if you have 2FA enabled.

Quote (ium @ 5 Dec 2018 14:54)
Gold password is a million times better, in my books.

2 FA is lame and time consuming... People will have problems when they change emails & phone numbers, etc. I also don't like to rely on google to not charge for this service in the future...

Big and firm No - I don't like to rely on external technique .


You have no idea what you’re talking about lmfao. Gold pw is a static password, if someone knows it you’re f’ed. 2FA changes every 30sec which makes it a million times more safe.

This post was edited by Cfwx on Dec 5 2018 08:03am
Member
Posts: 6,143
Joined: Mar 22 2016
Gold: 1,000.00
Trader: Trusted
Dec 5 2018 08:10am
Quote (Cfwx @ Dec 5 2018 03:01pm)
That’s fine. Just remove the requirement of having one if you have 2FA enabled.



You have no idea what you’re talking about lmfao. Gold pw is a static password, if someone knows it you’re f’ed. 2FA changes every 30sec which makes it a million times more safe.


That is very true! Just as much as if someone got access to your email (which is protected by only one password) they can verify your 2 FA. If you use 2FA on the cellphone you are absolutely protected, but once you lose your
phone number
, then you can just imagine the procedure to verify that you are the rightful owner of your d2jsp account.

How are people going to guess two passwords without your computer being compromised? And if your computer is compromised, then they can steal your web-session and use your account without a password. Which means
a 2FA is useless unless you have a gold password combined OR require it every time you send FG.


Does Google 2-step verification protect user from session hijacking?
- Short answer: Yes, the attacker can use session hijacking.

source: https://security.stackexchange.com/questions/56555/does-google-2-step-verification-protect-user-from-session-hijacking
Go Back To Site Suggestions Topic List
12Next
Closed New Topic New Poll