At last, we have better security. I cannot imagine hackers getting through this system easily. Thanks a lot Roblox!
Thanks ROBLOX! ROBLOX continues to grow as a platform, thank you very much.
I am honestly glad with the reputation of Roblox. A lot has changed.
Wow!
This is such a great update Roblox is heavily needing!
One question?
What will happen to the security PIN verification?
We still need a way to stop session hijacking (or at least mitigate it)
no, thats not the point.
The point of the recovery codes are for if you lose your authenticator device.
The codes do indeed use characters other than numbers and are still more secure than the 2FA codes, so they wouldn’t cause any security issues.
Thank you for this update, it was much needed!
Looks awesome! Cant wait to see it in action!
Alright now let’s see how long it takes for Roblox to add the ability to use USB security keys to protect accounts.
If they do. I don’t see many sites using that honestly.
Any plans to support physical keys/authenticators in the future?
For some reason, it never works. I’m supposed to use Google or Microsoft Authenticator right? Every time I enter the number it gives, it never works and says that the code is invalid. I can’t scan the QR code either.
EDIT: WinAuth fixed it for me. For some reason, phone apps don’t work.
Such an awesome feature, everyone should have this enabled. There’s really no point in using 2-Step for email now, also it’s a lot faster than looking through your email for a code to login to your roblox account and more safe. I am looking forward to hearing many good outcomes of this feature. Thank you roblox!
Is this compatible with the LastPass authenticator? None of the current authenticators listed are helping me out so far.
It should be compatible with every authenticator.
If you are on iOS, just scan the QR-Code and it will be added to your system settings. Note: You have to be on iOS 15 or later to have this option.
Hello! I’ve thought of a suggestion for the feature, people can use tools to crack the keys sometimes, and because of that I feel this isn’t all that secure in some cases. However, if there could be a notification when somebody logs in through a different IP to the 2FA it could alert the user via their computer, email or just the website itself. This would be enough time to change your password and prevent a attacker possibly.
We need this, Discord already does it.
Also, just have a long password and you’re safe (and don’t tell anyone!!!)
That’s wrong! Cookie logging
I’m aware of that, but it targets that specific situation
Now days with everything going virtual, hackers have found numerous ways to dodge passwords, and is also the reason why so many companies including Roblox are recommending 2FA.
I wouldn’t be surprised if soon we were asked for 3FA.
Yeah, but probably after 2-6 years.