Session Management & Security Email Notifications [Account Security]

:star::star::star::star::star:
Very helpful and important update!

2 Likes

I got this long ago on my account, though, it’s a really good update.

Also I would like to report a bug with it, if you play on Xbox it will show everytime you login as a new session, basically just launching Roblox on Xbox will add a new session there, it get filled up really quick.

4 Likes

Thank you! Finally extra extra security for our accounts!

2 Likes

Cool! Could we get a feature to lock down the IP addresses that our account can be accessed from? (Similar to OpenCloud API keys)

5 Likes

I noticed this change to occur on my account before the announcement came through, and all I want to say,

This is very good!

9.8/10

2 Likes

This is great, but I don’t think we need “Roblox Windows App” under the “Where you’re logged in” section. That will spam that section every time I join a game, which would make it difficult to see any unusual activity. Or perhaps some sort of search and/or filter options to weed out the ones I know are myself.

Actually, I’d rather see this under a new section called “Activity Log”, and then have the current section only be used to show devices that are logged in.

3 Likes

Should be useful for when you have sessions on devices you don’t use anymore.

1 Like

This is very good as well. but should using sessions devices has been sneaking your account, i guess they have warn from features is great!

2 Likes

Suggestion: When I log-out of my accounts on another device, it just lets me log out. Instead it should ask for my 2 Step Verification code because if for whatever reason my account got compromised they could just log me out and then I would not be able to get back my account.

2 Likes

Dude,

Yes, this is a great update…!

But it’s scary because 2-3 months ago I had a dream when I was sleeping about this feauture. To see different devices on your account. And then I woke up that day to nothing like that. But now it’s actually here…?

Spooky.

TL;DR
I had a dream about this update when I was sleeping, crazy to see it’s actually here.

4 Likes

This is an extremely good idea for security, but I have noticed that where it says the device is located is not totally accurate. For me, it said I was in a whole different state.

2 Likes

… LONG OVERDUE!!!

Thank you for keeping our accounts safe!

3 Likes

What if the user has a verified phone number but no email? Why can’t they be sent a SMS?

However, this is a great update and will improve the safety of the community from tricks like session stealing.

I can’t think of any cases where someone would have a phone number but not an email. Even then, I don’t believe SMS is a secure enough 2-step factor method to justify it being added in.

is there a way to stop this though, i tend to use incognito a lot which means i would have to log in everytime i start a new browsering session.
They’re all me.

4 Likes

That will occur regardless of incognito mode as I wrote here:

1 Like

Glad we finally got this. Discourse (this forum software) has had it for a long time. Compared to Discourse though, Roblox doesn’t know how to handle browsers on Linux:

while Discourse does:

Looking at some of the user agents my browsers send, I’m assuming a lookup is used to display the operating system. While Roblox doesn’t support Linux, I don’t see why an entry shouldn’t exist for someone browsing on Linux.

4 Likes

Hi seeing how Roblox is advancing into 2023 practices (finally), will we hopefully see some forced 2-step actions on important account security features?

We should get these email notifications for failed logins if the password was correct but the 2FA code was not, or expired. Would be a huge + to visibility if something is wrong.

Woohoo!
This update was amazing. Thanks, Roblox.
But… Uh…
1:

Sometimes, i get this reminder to change all my passwords. It will FORCE me to reset my passwords in 4 / 3 days. This also happened to my friend too.
While this update is amazing, i dont like some of the features because it FORCED us to change our passwords. when it was LITERALLY us.
One of my friend’s alt accounts were hacked, and all of my accounts got FORCED to change the password.

2:

Showing the IP Address could be an invasion of privacy. I recommend you shouldn’t show the IP Address as people can use that to track people down… and… stuff.