Add additional options for 2FA

Status

1337

ash is our purest form
Supreme
Feedback score
159
Posts
1,541
Reactions
1,523
Resources
0
Hello,

Just a small suggestion that should be fairly easy to implement. I believe that U2f and Yubikey are both very important protocols and very easy ways to substantially increase user account security. There is already a xenforo extension made available to implement these, which can be found here: https://xenforo.com/community/resources/th-two-step-authentication-essentials.4987/.

Don't really see any downsides to this happening, but feel free to leave your opinions down below.
 
Type
Suggestion
Status
Denied
PebbleHost
High performance, consistent uptime and fast support. Minecraft hosting that just works.

Ajdin

I used to be a big deal on here but now irrelevant
Supreme
Feedback score
12
Posts
2,419
Reactions
3,404
Resources
0
I think these are excessive. Regular 2FA should do just fine. I doubt many members have heard of these authentication methods.

Why they shouldn't add it? It's another thing to maintain and keep updated while it isn't actually needed.
 

1337

ash is our purest form
Supreme
Feedback score
159
Posts
1,541
Reactions
1,523
Resources
0
I think these are excessive. Regular 2FA should do just fine. I doubt many members have heard of these authentication methods.

Why they shouldn't add it? It's another thing to maintain and keep updated while it isn't actually needed.
It isn't exactly too much maintenance to drag & drop an addon..
 

Landon

wow!
Supreme
Feedback score
111
Posts
1,590
Reactions
2,040
Resources
7
I don't know what you mentioned are, but I do see the addon has SMS verification which I really have wanted for a while now.
 

Jack

Retired Moderator
Supreme
Feedback score
11
Posts
1,210
Reactions
1,462
Resources
0
It isn't exactly too much maintenance to drag & drop an addon..
That's what we'd all say, but seeing as you have been on MC-Market for just over 2 years now, you should know by now how much effort installing a 'drag and drop' addon is for the MC-Market administration (or rather, how much time it would take) Kappa
 

Landon

wow!
Supreme
Feedback score
111
Posts
1,590
Reactions
2,040
Resources
7
That's what we'd all say, but seeing as you have been on MC-Market for just over 2 years now, you should know by now how much effort installing a 'drag and drop' addon is for the MC-Market administration (or rather, how much time it would take) Kappa
Two weeks for the image proxy!!
4 months later
 

1337

ash is our purest form
Supreme
Feedback score
159
Posts
1,541
Reactions
1,523
Resources
0

Jack

Retired Moderator
Supreme
Feedback score
11
Posts
1,210
Reactions
1,462
Resources
0
Shout out to Brent W, the non-admin sys admin
v5R6f0l.png

CtJ4qpi.png


Image proxy works now :whistle:
On-topic: Maybe we will see 2FA in the April update.
CAZmLwY.png
 
Last edited:

Sloth

Feed Me
Supreme
Feedback score
6
Posts
4,370
Reactions
2,660
Resources
0
I’d be more surprised if this suggestion was implemented before next year.

Everyone talks about how support tickets and resource requests are backed up but nobody talks about how neglected the suggestions section has become. It takes months/years for suggestions to even be decided on and then it takes another few months for it to be implemented.
 

Kelsey

Pokémon GO Master
Supreme
Feedback score
150
Posts
1,762
Reactions
2,676
Resources
0
I’d be more surprised if this suggestion was implemented before next year.

Everyone talks about how support tickets and resource requests are backed up but nobody talks about how neglected the suggestions section has become. It takes months/years for suggestions to even be decided on and then it takes another few months for it to be implemented.
My suggestion has been pending for more than 2 years now.
 

LA Confidential

Feedback score
1
Posts
32
Reactions
5
Resources
0
Hello,

Just a small suggestion that should be fairly easy to implement. I believe that U2f and Yubikey are both very important protocols and very easy ways to substantially increase user account security. There is already a xenforo extension made available to implement these, which can be found here: https://xenforo.com/community/resources/th-two-step-authentication-essentials.4987/.

Don't really see any downsides to this happening, but feel free to leave your opinions down below.
do you know anyone personally that their mcm account got jacked/hacked? nothings wrong with being too cautious. Unless you're giving your password out freely or mcm has a database breach it's not needed. if you're a over secure weirdo stick with 2fa only devs at mcm have access to that type of information.
 

Sloth

Feed Me
Supreme
Feedback score
6
Posts
4,370
Reactions
2,660
Resources
0
do you know anyone personally that their mcm account got jacked/hacked? nothings wrong with being too cautious. Unless you're giving your password out freely or mcm has a database breach it's not needed. if you're a over secure weirdo stick with 2fa only devs at mcm have access to that type of information.
People get their accounts compromised all the time unfortunately.
 

LA Confidential

Feedback score
1
Posts
32
Reactions
5
Resources
0
There was a database breach on a competitor site and certain users thought it was a good idea to have the same password on both sites.
completely irrelevant to this post. theres no need for additional security. nobody should have to tell you to not have the same password. only a idiot that mindlessly cares about security would use the same password for everything. thats equal to wiping your ass with already used toilet paper to a hat (White/Black/Grey).
 

jxhdvn

The Visionary
Supreme
Feedback score
30
Posts
2,480
Reactions
1,282
Resources
0
I think these are excessive. Regular 2FA should do just fine. I doubt many members have heard of these authentication methods.

Why they shouldn't add it? It's another thing to maintain and keep updated while it isn't actually needed.
They're way better than standard email 2FA which a lot use
 

1337

ash is our purest form
Supreme
Feedback score
159
Posts
1,541
Reactions
1,523
Resources
0
do you know anyone personally that their mcm account got jacked/hacked? nothings wrong with being too cautious. Unless you're giving your password out freely or mcm has a database breach it's not needed. if you're a over secure weirdo stick with 2fa only devs at mcm have access to that type of information.
There's plenty of people who have had their accounts compromised on MCM and thousands of data breaches occur constantly, having a yubikey doesn't make someone "an oversecure weirdo", it makes them either legitimately concerned about the privacy of their data, or someone that's required to be compliant with certain regulations. Additionally, MCM admins do not have access to our passwords, they're stored as hashes/salts within a database and they couldn't decrypt them if they tried.
You look like Edward Snowden

ax0WBf6.jpg
*reacts optimistic*
They're way better than standard email 2FA which a lot use
E-Mail and SMS 2fa are long out of date and unfortunately too many people believe they're still secure. While better than having nothing, simply getting SIM swapped would completely eliminate the layer of protection 2fa-SMS gives you and via E-Mail, it could also be compromised. TOTP, U2F, and FIDO2 are pretty much the only truly secure/reliable means of multifactor authentication.
 

jxhdvn

The Visionary
Supreme
Feedback score
30
Posts
2,480
Reactions
1,282
Resources
0
There's plenty of people who have had their accounts compromised on MCM and thousands of data breaches occur constantly, having a yubikey doesn't make someone "an oversecure weirdo", it makes them either legitimately concerned about the privacy of their data, or someone that's required to be compliant with certain regulations. Additionally, MCM admins do not have access to our passwords, they're stored as hashes/salts within a database and they couldn't decrypt them if they tried.

*reacts optimistic*

E-Mail and SMS 2fa are long out of date and unfortunately too many people believe they're still secure. While better than having nothing, simply getting SIM swapped would completely eliminate the layer of protection 2fa-SMS gives you and via E-Mail, it could also be compromised. TOTP, U2F, and FIDO2 are pretty much the only truly secure/reliable means of multifactor authentication.
What about an Authenticator app?
 
Status
Top