Any Plans on Two-Step Authentication of Our Accounts?

evacynevacyn Posts: 975
edited February 2020 in The Commons
Like the title says - any chance of protecting our investment in Daz assets with 2FA? I understand a lot of it falls to the user and not choosing '12345' as a password, but the added security for our purchases would be appreciated and peace of mind.
Post edited by evacyn on
«1

Comments

  • That's a question/suggestion for Daz - https://www.daz3d.com/help/help-contact-us

  • evacynevacyn Posts: 975
    Done! Thanks :)
  • AtiAti Posts: 9,139

    If someone breaks into your account, how are your past purchases in any jeopardy? They can't "unbuy" them. They can't delete them. What am I not seeing?

  • evacynevacyn Posts: 975
    Off the top of my head, I'm guessing download the content manually, gain control of the account or buy a GC if I stored a credit card.
  • AtiAti Posts: 9,139
    evacyn said:
    Off the top of my head, I'm guessing download the content manually, gain control of the account or buy a GC if I stored a credit card.

    If you store the credit card info on the site, that could indeed be an issue. Although most payments these days require 2FA at the bank's level anyway, so they wouldn't be able to do anything with your card data without your phone, or your other means of authentication.

  • maybe someone is getting a divorce and fighting over their shared DAZ assets cheeky

  • evacynevacyn Posts: 975
    Ati said:
    evacyn said:
    Off the top of my head, I'm guessing download the content manually, gain control of the account or buy a GC if I stored a credit card.

    If you store the credit card info on the site, that could indeed be an issue. Although most payments these days require 2FA at the bank's level anyway, so they wouldn't be able to do anything with your card data without your phone, or your other means of authentication.

    That's a good point. I guess in the end, I just like the peace of mind of having the 2FA option for my online accounts. 

     

    maybe someone is getting a divorce and fighting over their shared DAZ assets cheeky

    lol... that's another scenario :P

  • AtiAti Posts: 9,139

    maybe someone is getting a divorce and fighting over their shared DAZ assets cheeky

    It's a personal, non-transferable license. :D

  • Ati said:

    maybe someone is getting a divorce and fighting over their shared DAZ assets cheeky

    It's a personal, non-transferable license. :D

    same household no longer and each claiming to be customer 

    the acount could be Victoria Micheal Oursurname

  • FSMCDesignsFSMCDesigns Posts: 12,775

    Please no!!! I already have way to many places i have to jump thru extra hoops at to log in and view my account info, don't want DAZ to be another!

  • memcneil70memcneil70 Posts: 4,290

    I recently found out how to block text numbers and went happy clearing out everyone I had no idea who they were, including one that liked to add a cartoon to their texts. Last week, I tried to log in to Social Security/Medicare and found that two-step system, waited, waited, and waited for the text message. Went back to the text messages I had blocked, and unblocked the cartoon, and what do you know, it was a .gov text message! Got into my account finally.

    My flat mate has an old cell phone he loves, pre-smart phone, it takes him two hours to get a text message for that confirmation for his website so he can update it. 

    Me, I never leave financial data on Daz or other stores. And my financial accounts and government accounts get the most awful complex, unable to remember passwords that are changed every 60 days. Drives me nuts, but... better than someone clearing out accounts. 

    And when I cleared my cache so Ati's add-on would work again, I got to go through the challenge response all over again for everyone. Sigh. Please, not another one.

  • Personally, I find the idea of "everything" being turned over to online transactions & such to be rather stupid in an age where pretty much all computers are connected to the same internet, globally. heh, on the one hand, some would sacrifice freedom for security, while on the other, they would sacrifice security for convenience. Is this not some sort of paradox?

  • MelanieLMelanieL Posts: 7,467

    Please no!!! I already have way to many places i have to jump thru extra hoops at to log in and view my account info, don't want DAZ to be another!

    +1 to that! I already have two-step when I use a card to buy a GC, I'd hate to have to fiddle about to then spend it.

  • jakibluejakiblue Posts: 7,281

    I'm guessing you're aussie? :) I hate that mygov site. ATO will ONLY accept you receiving a text message on your mobile to be able to log in, which I didn't know - and because I hate using my mobile I changed it all to secret question instead of text message..only to discover I could no longer link my ATO to it. GUH. Had to switch it back and ring ATO and go through everything AGAIN to link it. The only reason I own a mobile phone is because of that stuff - and having to receive a code via text from our banks when we transfer money etc. Oh and also cos our landline phone died in January and I'm STILL WAITING for the phone I ordered from Telstra (cos there are no phone shops at all where I live) to arrive, so everyone has to ring me on the mobile and I have a bad habit of swiping the wrong way when answering it and disconnecting the call. Ugh. I want to go back to when I never had a mobile!!!!!! 

    I recently found out how to block text numbers and went happy clearing out everyone I had no idea who they were, including one that liked to add a cartoon to their texts. Last week, I tried to log in to Social Security/Medicare and found that two-step system, waited, waited, and waited for the text message. Went back to the text messages I had blocked, and unblocked the cartoon, and what do you know, it was a .gov text message! Got into my account finally.

     

  • 2FA is not the be all and end all of security. Hackers have many ways of beating it.

  • TaozTaoz Posts: 9,973
    evacyn said:
    Off the top of my head, I'm guessing download the content manually, gain control of the account or buy a GC if I stored a credit card.

    You can't check out with a stored card without entering the card verification number.

  • WendyLuvsCatzWendyLuvsCatz Posts: 38,531
    edited February 2020
    jakiblue said:

    I'm guessing you're aussie? :) I hate that mygov site. ATO will ONLY accept you receiving a text message on your mobile to be able to log in, which I didn't know - and because I hate using my mobile I changed it all to secret question instead of text message..only to discover I could no longer link my ATO to it. GUH. Had to switch it back and ring ATO and go through everything AGAIN to link it. The only reason I own a mobile phone is because of that stuff - and having to receive a code via text from our banks when we transfer money etc. Oh and also cos our landline phone died in January and I'm STILL WAITING for the phone I ordered from Telstra (cos there are no phone shops at all where I live) to arrive, so everyone has to ring me on the mobile and I have a bad habit of swiping the wrong way when answering it and disconnecting the call. Ugh. I want to go back to when I never had a mobile!!!!!! 

    I recently found out how to block text numbers and went happy clearing out everyone I had no idea who they were, including one that liked to add a cartoon to their texts. Last week, I tried to log in to Social Security/Medicare and found that two-step system, waited, waited, and waited for the text message. Went back to the text messages I had blocked, and unblocked the cartoon, and what do you know, it was a .gov text message! Got into my account finally.

     

    I was laughed at on facebook by people when I said I was surprised Coles service desk don't have a phonebook when I lost my Visa card early morning shopping when they were the only thing open and I needed my bank's number to use the public phone.

    I guess we just get OK Boomer said to us now.

    Post edited by WendyLuvsCatz on
  • jakibluejakiblue Posts: 7,281

    When we moved here 5 months ago, you imagine my absolute shock when we went to the post office to set up a post office box (cos there is NO mail delivery to houses in this town, which was another massive shock) when I saw not 1, but TWO public phonebooths there! And then a bit further down the road, there is actually ANOTHER ONE just across from the waterfront. Been a long time since I saw a public phonebooth in the wild. I didn't stop to see if they had phone books attached to them tho. LOL

    jakiblue said:

    I'm guessing you're aussie? :) I hate that mygov site. ATO will ONLY accept you receiving a text message on your mobile to be able to log in, which I didn't know - and because I hate using my mobile I changed it all to secret question instead of text message..only to discover I could no longer link my ATO to it. GUH. Had to switch it back and ring ATO and go through everything AGAIN to link it. The only reason I own a mobile phone is because of that stuff - and having to receive a code via text from our banks when we transfer money etc. Oh and also cos our landline phone died in January and I'm STILL WAITING for the phone I ordered from Telstra (cos there are no phone shops at all where I live) to arrive, so everyone has to ring me on the mobile and I have a bad habit of swiping the wrong way when answering it and disconnecting the call. Ugh. I want to go back to when I never had a mobile!!!!!! 

    I recently found out how to block text numbers and went happy clearing out everyone I had no idea who they were, including one that liked to add a cartoon to their texts. Last week, I tried to log in to Social Security/Medicare and found that two-step system, waited, waited, and waited for the text message. Went back to the text messages I had blocked, and unblocked the cartoon, and what do you know, it was a .gov text message! Got into my account finally.

     

    I was laughed at on facebook by people when I said I was surprised Coles service desk don't have a phonebook when I lost my Visa card early morning shopping when they were the only thing open and I needed my bank's number to use the public phone.

    I guess we just get OK Boomer said to us now.

     

  • AllenArtAllenArt Posts: 7,172

    It'll only confuse 'em ;)

    Laurie

  • ConnaticConnatic Posts: 282

    If someone hacks your account they can change the password and then you cannot access your own account. Hijacked!

  • AtiAti Posts: 9,139
    edited February 2020
    Connatic said:

    If someone hacks your account they can change the password and then you cannot access your own account. Hijacked!

    In that case, you ask for a new password, and you're in again. 5 seconds max.

    Post edited by Ati on
  • Ati said:
    Connatic said:

    If someone hacks your account they can change the password and then you cannot access your own account. Hijacked!

    In that case, you ask for a new password, and you're in again. 5 seconds max.

    Only incompetent hackers would leave it that easy. If they can change the PW they have access to your email already. So they can very easily change that PW or change the email of your DS account.

  • AtiAti Posts: 9,139
    Ati said:
    Connatic said:

    If someone hacks your account they can change the password and then you cannot access your own account. Hijacked!

    In that case, you ask for a new password, and you're in again. 5 seconds max.

    Only incompetent hackers would leave it that easy. If they can change the PW they have access to your email already. So they can very easily change that PW or change the email of your DS account.

    Your email already has 2FA, I hope. So that's not too likely to happen. But if it does, you reset your email password, and again: problem solved.

    Seriously though, if someone has already hacked your 2FA-protected email account, then another 2FA on the Daz site won't help. And all this to do what? Download your assets that they can get way more easily from elsewhere?

  • memcneil70memcneil70 Posts: 4,290
    jakiblue said:

    I'm guessing you're aussie? :) I hate that mygov site. ATO will ONLY accept you receiving a text message on your mobile to be able to log in, which I didn't know - and because I hate using my mobile I changed it all to secret question instead of text message..only to discover I could no longer link my ATO to it. GUH. Had to switch it back and ring ATO and go through everything AGAIN to link it. The only reason I own a mobile phone is because of that stuff - and having to receive a code via text from our banks when we transfer money etc. Oh and also cos our landline phone died in January and I'm STILL WAITING for the phone I ordered from Telstra (cos there are no phone shops at all where I live) to arrive, so everyone has to ring me on the mobile and I have a bad habit of swiping the wrong way when answering it and disconnecting the call. Ugh. I want to go back to when I never had a mobile!!!!!! 

    I recently found out how to block text numbers and went happy clearing out everyone I had no idea who they were, including one that liked to add a cartoon to their texts. Last week, I tried to log in to Social Security/Medicare and found that two-step system, waited, waited, and waited for the text message. Went back to the text messages I had blocked, and unblocked the cartoon, and what do you know, it was a .gov text message! Got into my account finally.

     

    Nope, American, live in Denver Colorado. Other side of the Rockies from DAZLand. Same time zone. I think all governments/agencies have an evilness to their access levels. It is inherent to the nature of the beast.

    My experiences in Europe and Asia are prior to the Internet, so can't say how bad or good they are, but I expect they can be as convuluted as any other system that is possible. 

  • it would be an excellent way of discouraging me by making me jump through hoops to buy stuff yes

    save me money

  • Ati said:
    Ati said:
    Connatic said:

    If someone hacks your account they can change the password and then you cannot access your own account. Hijacked!

    In that case, you ask for a new password, and you're in again. 5 seconds max.

    Only incompetent hackers would leave it that easy. If they can change the PW they have access to your email already. So they can very easily change that PW or change the email of your DS account.

    Your email already has 2FA, I hope. So that's not too likely to happen. But if it does, you reset your email password, and again: problem solved.

    Seriously though, if someone has already hacked your 2FA-protected email account, then another 2FA on the Daz site won't help. And all this to do what? Download your assets that they can get way more easily from elsewhere?

    2FA is pointless. I never said it wasn't.

  • TheKDTheKD Posts: 2,696

    I hope not, I ditched cellphones back when the blackberry were the big thing, and haven't gotten another one since lol.

  • McGyverMcGyver Posts: 7,066

    It's impossible to figure out my password, it's PASSWORD... it's so simple nobody would guess it.

  • TaozTaoz Posts: 9,973
    McGyver said:

    It's impossible to figure out my password, it's PASSWORD... it's so simple nobody would guess it.

    Unless the hacker is so stupid that he takes the sentence "Enter password" above the input field literal...

  • namffuaknamffuak Posts: 4,176
    McGyver said:

    It's impossible to figure out my password, it's PASSWORD... it's so simple nobody would guess it.

    I've been a fan of six * for throw-away passwords.

Sign In or Register to comment.