2FA via Authenticator - Now Fully Rolled Out!

This is a great step in the quest for better account security. Although I still have some concerns, as I wish the authenticator was more like Steam’s, where you have to confirm on the mobile app whenever you do something, and it sends a push whenever someone is trying to get into your account. The problem I see is that whenever someone gets into your account, it’s often too late to take any actions.

Another concern is the underlying issue with the customer support being social engineered into giving away access to people’s accounts, until these issues are fixed, I don’t know if I will ever be able to fully sleep at night with any items of value on my account. The sad part is, people with limited items are generally ignored when they are compromised.

2 Likes

Great work rolling this out rather quickly. :slight_smile:

4 Likes

Use a proper app to backup your 2FA codes.

Authy works also in desktop, though all apps from Authy look bad and don’t work the best.

I’m currently using 2FAS. Doesn’t have a desktop app but didn’t miss it.
You can move to it from GAuthenticator pretty nicely.

Microsoft Authenticator doesn’t backup your 2FA codes fyi.

Of course, there’s the backup codes, but realistically you should be using an app that does proper backing to your cloud service anyway so that isn’t an issue. (iCloud, Drive)

1 Like

You do know how authentication works with these, right? With this type of system you must have the code on your authentication app to log in all the time, even if you have a password. If you lose the authenticator app, then you can use the 10 backup codes given to you when you set it up. Usually you store these in a private place, so that no one can access them.

2 Likes

Thank you for this update!! Ever since like 2019 I’ve been wanting you guys to push out this update and you guys did! :smiley:

1 Like

Umm… what? Everyone I know has had this feature for as long as I can remember.

1 Like

Thank you for sharing the necessary information on the recent update, however, I have a question regarding this topic.

  • Is it safe to turn on both 2FA and 2SV?

Since Roblox told me a warning that I should not use 2SV while enabling 2FA, I was confused.

2 Likes

You should disable 2SV in favor of 2FA, as only 1 is required and 2SV is less secure than 2FA

3 Likes

Oh alright, thank you, however, why is 2SV less secure than 2FA?

If you don’t mind me asking.

1 Like

Amazing! This is definitely a huge upgrade in security. Thank you roblox for rolling out this amazing update.

3 Likes

Would be nice if this was also added to reselling limited items (we already have it when we spend a large sum on an item, don’t see an issue to have it for reselling as well)

Great finally more less hacks !!!

1 Like

Finally! It was about time! I’ m using andOTP for 2FA. It is free, open-source and works great.

1 Like

2FA is inherently better than 2SV as 2FA requires 2 separate factors of authentication instead of just one with an extra step (such as having your own phone’s auth app). If you have your email behind 2FA as well, I suppose 2SV could still be fine as in order to access the email you’ll need another factor anyways making 2SV really 2SV with 2FA on top of it.

I still hope at some point Roblox’s API switches to api keys and not cookie auth. As it stands if you get cookie logged somehow, even without logging into the account someone can still use the api and the cookie to do things without 2FA.

4 Likes

Thank you roblox, one of the best updates to the security system.

2 Likes

Nice! This is a much needed change.

3 Likes

This was MUCH appreciated, my account has been hacked about 3 times. Also just everyone’s vulnerability to being hacked is high as hell.

I really suggest the Microsoft Authenticator, I’ve had it for a while. It’s EXTREMELY simple to use, all you gotta do is sign in with an outlook or even anything line Gmail. Also you can sync your passwords and addresses for auto fill if you want…the app can ALSO be protected with Face ID, Fingerprints, ect with IPhones and maybe other phones aswell.

3 Likes

In my opinion, it is not clear that you can use integrated authentication in the iOS settings.

Maybe you have integrated authentication in your android device too.

2 Likes

image

Warning: 2 Step Verification via Email Codes is less secure than using an Authenticator App and will still be a choice during login. It is recommended that you turn off email verification if you will be using an Authenticator app.


I might disable the 2 Step Verification via Email for me.

1 Like

I prefer using Authy. Their interface works perfectly well on mobile and desktop and I’ve had no problem using it for the past 4 years.

2 Likes