Allow groups to lock place editing behind a pin and 2FA

As the owner of a growing team of developers on Roblox, I find it currently that our games are subject to a 24/7 massive security flaw where if any of our developers gets compromised, all our games can be stolen with all their assets and scripts with no immediate way for us to avoid such a situation.

Improving account security is great, but resorting to just that is not enough. Getting into someone’s account on Roblox can be as easy as swapping a cookie, fully bypassing all the 2FA mechanisms put in place. This leads to a huge security risk where if a person with edit perms to places loses their account or gets hacked into, the whole studio’s secrets, assets and scripts can be leaked.

As such, I believe adding the ability to choose as a group or game setting (only changeable through
correct account pin and by the group / game owner) that edit perms require the correct pin to be used / require 2FA to access would massively reduce the risk of assets being stolen. This could be seen as a hassle to some which is why I propose this as an option, but increased security is a must specially as someone who takes Roblox at a professional level.

75 Likes

We just had a higher ranked member get their Roblox account compromised and the exploiter promoted himself to the Developer role.

Fortunately we caught it pretty quickly and that account only had access to the development game not the live one but it could have been really bad.

2 Likes

PIN is not a security feature, it is parental control feature and is ineffective as a security feature.

A 2FA code however should be required on certain sensitive account actions + cases like this when desired.

1 Like