I don't use Google Authenticator, so this strictly applies to the e-mail confirmation login.
Though, I'll add to why GAuth is bad practice as well.
It was only around December when we were required to add 2FA to our accounts. Due to the negative reaction in the community, this requirement was revoked, though ultimately, e-mail verification isn't even safe on MCM.
Why, you may ask?
Well, ultimately, MCM leaks the e-mail address that your 2FA code goes to. Which not only makes you more vulnerable, but if a SQL injection attack happened on another site with possibly stricter password requirements were in place, or someone had access to a list of databases(*cough* Ew *cough*), they could cross-reference the e-mail address and your most commonly-used passwords to login to your e-mail, and grab the 2FA code.
Now, in lamen's terms, this is really just poor security. Requiring 2FA is one thing, and to be honest, it wasn't that big of a deal. But literally providing the e-mail that you use(say even at a personal level), makes it not only easier to get into that personal e-mail, but taking over the account wouldn't even be that hard, especially if they aren't intelligent enough to use different passwords on different sites.
My suggestion: don't provide the e-mail your 2FA code was sent to. You should know what e-mail you signed up with.
Now, Gauth/Google Authenticator.
Ultimately, there is no way to stop members from using this, but it is definitely good practice to only recommend Authy. Strangely enough, when your phone is reset or you get a new phone, you've just lost any 2FA accounts attached to that. And realistically, bigger companies that require 2FA via an application such as Authy or Google Authenticator, won't remove the 2FA without extraneous amounts of verification you are who you say you are.
But that's just from personal experience and opinion, I wouldn't recommend GAuth to members. Authy is nice as it's attached to a phone # or e-mail address, also comes with a Chrome extension and the ability to have seperate passwords just to display the 2FA code for a certain account(and in general a better application IMHO).
Thanks.
Though, I'll add to why GAuth is bad practice as well.
It was only around December when we were required to add 2FA to our accounts. Due to the negative reaction in the community, this requirement was revoked, though ultimately, e-mail verification isn't even safe on MCM.
Why, you may ask?
Well, ultimately, MCM leaks the e-mail address that your 2FA code goes to. Which not only makes you more vulnerable, but if a SQL injection attack happened on another site with possibly stricter password requirements were in place, or someone had access to a list of databases(*cough* Ew *cough*), they could cross-reference the e-mail address and your most commonly-used passwords to login to your e-mail, and grab the 2FA code.
Now, in lamen's terms, this is really just poor security. Requiring 2FA is one thing, and to be honest, it wasn't that big of a deal. But literally providing the e-mail that you use(say even at a personal level), makes it not only easier to get into that personal e-mail, but taking over the account wouldn't even be that hard, especially if they aren't intelligent enough to use different passwords on different sites.
My suggestion: don't provide the e-mail your 2FA code was sent to. You should know what e-mail you signed up with.
Now, Gauth/Google Authenticator.
Ultimately, there is no way to stop members from using this, but it is definitely good practice to only recommend Authy. Strangely enough, when your phone is reset or you get a new phone, you've just lost any 2FA accounts attached to that. And realistically, bigger companies that require 2FA via an application such as Authy or Google Authenticator, won't remove the 2FA without extraneous amounts of verification you are who you say you are.
But that's just from personal experience and opinion, I wouldn't recommend GAuth to members. Authy is nice as it's attached to a phone # or e-mail address, also comes with a Chrome extension and the ability to have seperate passwords just to display the 2FA code for a certain account(and in general a better application IMHO).
Thanks.
- Type
- Suggestion
- Status
- Denied
Banned forever. Reason: Scamming (https://www.mc-market.org/conversations/659455/)
