Loading...

Top
PFQ Banner

This is PokéFarm Q, a free online Pokémon collectables game.

Already a user? New to PFQ?

Single post in Account Breach incident

Forum Index > Core > Announcements > News Archive > Account Breach incident >

selocon's Avatarselocon
selocon's Avatar
elite.pngc.png

QUOTE originally posted by Lovino

QUOTE originally posted by selocon

For those who use Chrome: A recent update gave you the ability to have it auto-gen you a strong password and for it to auto-remember it (not good if you're using a public computer!!) this password has all the positives about a strong password: it's long (I think at least 16 characters), has a mix of upper and lowercase letters, numbers, and symbols.. Also: pins are...for lack of a better word, dumb. The less numbers in a pin the easier it is to crack, and thhose randomly generated "ensure you aren't a bot, and answer this stupid math question" thing really only works for sign ups. If I have to go get a pin everytime I log in from a new location/device I'd have to stop playing PFQ. I have so many different IPs I cross through while at work, it's no longer funny. Now assume I log in from 12 of those (2 stable) that's 12 pins on day one and 10 pins every other time until I finally log in enough that it's rarer to get a pin. Now imagine how frustrating that would be to have to get a new pin everytime you log in? Most 2 step verifications don't require you have to go back and forth--it's usually something right there. Plus, security questions aren't all that secure. Let's say we need to add three questions, and my three are as follows: "What's your pet's name? What's your mother's maiden name? What city were you born in?" Anyone who knows me well enough (or has found my online family tree, which is semi-public), can have the answers to those in about 5 minutes. They only really work to ensure that you utterly give up, especially if you answered different to that first question than you would now. I'm all for 2FA but please, for the love of Sally, do not use pins or security questions, it's just too much hassle..
theres no win for anyone with multi 2fa. i have multiple gmails with multiple step verifications just to get on to my account it goes from the system im on, hving to get a text putting in that text going into my email searching through whcih folder the confirmation would be in then clicking it then logging out of my gmail. so it would be a pain for everyone. my school when i was in it had to memorize a few 12 digit numbers to get in most got it after a month so pins arent that hard to memorize but i do see your point with the question part
Thing is, how secure would a static pin be? I guarentee you there are sophisticated enough RNGs out there that can generate hundreds--if not thousands--of random 12 digit coombinations which a user could then just paste into the box. Even with the waiting, they could go do something else until the time is up--like watch a music video on YT. Pins are only secure if they're generated every time. Like Yahoo. If I forget my password, in order to chain it, I have to get a code they send me and enter all 8 alpha-numeric characters into the box. But it's not static. And having to get a new code every X amoutn of time is about as memorable as sites that require you to use an entirely new password every 30 days, you finally just resort to storing them somewhere and trying all of them.
Avatar by the best lizard ever, Bananalizard #standwithEMS #ELM
Score: 0
© PokéFarm 2009-2024 (Full details)Contact | Rules | Privacy | Reviews 4.6★Get shortlink for this page