Thoughts on 2-Step Verification?

Of course SMS messages are insecure, they are sent in plaintext. Two-factor authentication is meant to prevent cases where merely obtaining the user’s password enables their account to be compromised. If you log into a website on a computer, a program on that computer might be logging your keystrokes or someone might be reading your password over your shoulder. If two-factor is enabled, an unsophisticated attacker cannot get into the account without also compromising the user’s phone.


I just hope we get google authenticator or something similar, that’s what I am looking forward to.

This really is needed now, as a lot of developers are getting hacked.

I would very much love it if we can verify with:

  1. Email
  2. SMS

(I rather email more than SMS but yea…)

Also, don’t open links on skype or accept contact requests from random people you don’t know.

What methods are they using? What should we look out for?

ToniToni tweeted about how it happened to him :

Ah, I see. I never share my skype contact information with anyone, so I should be safe at least there.

If you really want to be careful about your account, then:

Don’t use other computers than your personal computer and don’t allow others to use your computer to login their account.

Make sure the site you go on has a valid SSL

Don’t click links that you are not 100% certain to where they lead, ( ex: from people you do not know )

probably there is more but yea :stuck_out_tongue:

Don’t go on public wireless networks preferably

I use NoScript just in case I ever click on a bad link.

This is already as prioritized as it can be. The “Web team” is split into smaller teams that focus on different areas. 2FA is the next big thing one of the web teams will be working on.

Edit: I can’t give you a delivery date yet. My current estimation is a month or two for email 2FA. Other types to follow.


Just checking in on the progress of this because it’s been round-a-bout a month. Any updates or news? I don’t know also if you saw my suggestions but will they ever be a thing?

I care so much about my account security even more so than ever, considering our accounts can hold real world value of ££’s or even ££££££’s [because our accounts have real world value (at least in the UK) the Data Protection Act now comes into affect] and now I’m expecting the security to match that (or come considerably close) to that of a bank (pin sentry anyone?). HTTPS everywhere is a step in the right direction but we need to push further to help make our accounts as hard-as-nails.

The only thing that does is make a slight annoyance to anyone who hijacks an account. They could set up their account with thousands of purchasable assets for 999R$ and transfer all the account’s R$ without triggering the authentication (And maybe use a bot). This would also put a user at an even bigger disadvantage when purchasing the original limiteds to the sniping bots.

But how would they know what you set it for? It should be hidden by **** with a link at the side to change/see it but you’ll need your password.

If the hacker is using bots (if they got this far, they probably could), they could do it for a simple 10R$ at a time. If it’s already set below that, then they would be screwed, but then it would be inconvenient for any purchases the player.

Of course that won’t stop them fully the idea is to increase security as much as possible. It will slow down a lot of newbie hackers and reduce the amount of losing your items/stuff because if a 9 year old somehow gets my account his first thoughts are gonna be “IM GONNA GIVE ALL DIS MONEY TO MYSELF” and the struggle for an hour or few trying to figure out my password again and by that time hopefully, I would of gotten my account back with minimal damage.

It’s all about slowing them down and making it as hard as possible

Any word on how soon™ 2FA will be arriving at this point?



I now regret saying soon in the first place. There is progress, and it’s still a top priority. It’s slow going.


