As a Roblox developer, it is currently too hard to stay safe on Roblox’s website.
Roblox is a multi-millionaire company, that does not plan it’s security well enough.
Too many users get exploited by either being in-game, where someone exploits the place out, yes Roblox has tried to address issues thereby using FE (Filtering Enabled).
But website security has been the same ever since the website was made.
Roblox stores passwords encrypted in cookies, but the cookies OVERRIDE any extra layer of security you try to add.
Such as app authentication, e-mail authentication, the PIN you name it.
If you are unlucky and get hijacked, you are lost, until you figure out you lost EVERY limited and or R$.
Then if you have already gotten restored once, you are no longer lucky enough to be restored, even though, you have evidence of what users have done the issue.
Roblox keeps saying “this is a one-time thing”, and that they don’t have any restore tools.
The questions are
- How are R$ and other items restored if they don’t have a tool to restore them.
- Are they simply issuing new items and R$ to get them back.
Roblox should ensure that the passwords aren’t stored with a one-time cookie, where everyone can bypass ALL security options just by copying the cookie into another browser or computer.
I have suggested before that enabling pin on all sales and purchases helps somewhat.
But then again, some users will argue that it will be annoying to do mass trades and such.
The real question is, is security being taken seriously or is it just being kept as is, because users use the systems almost like a botnet and Roblox earns money?
If Roblox is able to address this issue, it would improve website security for users who might have had an issue, where they installed an extension by accident, and simply lost it all a second time.