Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

Retardo? Feature request: option to disable login by username (email-only)

Luke Skinwalker

*teleports inside you*
Patron
Undisputed Queen of Faggotry Village Idiot
Joined
Aug 20, 2021
Messages
16,097
Location
Neversex
Usernames are publicly visible to all. Emails are private, none can see anyone else's email but the user and admins (can regular mods, a.k.a. Crispy see them? I sure hope not. Fuck off, you old turd! STOP LOOKING AT MY EMAIL ADDRESS!)

There's not much of a chance of someone managing to HAXXXORZZ someone's account just by knowing their username, but nonetheless, I would like an option to disable login by username, and make it by email+password+2FA+3FA+IP address+five secret questions+magic ritual+solving Fermat's theorem only.

If it's too hard to make this a global setting, then allow for each account to decide that for xirselves in our account settings.

Thanks,
Sherry
This post is pending Infintroon's approval
 

ds

Arcane
Patron
Joined
Jul 17, 2013
Messages
3,265
Location
here
Login should be reduced to a single button without any input fields. When you click it our friendly mossad agent will decide in real time if you are allowed to log in and which account belongs to you.
 

DarkUnderlord

Professional Throne Sitter
Staff Member
Joined
Jun 18, 2002
Messages
28,675
There's a mod that does this. But I'd need huge numbers of people wanting it before I considered it, as it does become a global setting. It also becomes another mod we have to carry around every-time there's an update, so if it's not updated, it's back to default.
 

InD_ImaginE

Arcane
Patron
Joined
Aug 23, 2015
Messages
6,436
Pathfinder: Wrath
There's a mod that does this. But I'd need huge numbers of people wanting it before I considered it, as it does become a global setting. It also becomes another mod we have to carry around every-time there's an update, so if it's not updated, it's back to default.

Use email and disable 2FA?

After all can't bruteforce if you don't know the email.

2 problems are solved this way
 

Twiglard

Poland Strong
Patron
Staff Member
Joined
Aug 6, 2014
Messages
7,596
Location
Poland
Strap Yourselves In Codex Year of the Donut
I'm not convinced that people with these leaked password databases don't have the email as well.
 

Luke Skinwalker

*teleports inside you*
Patron
Undisputed Queen of Faggotry Village Idiot
Joined
Aug 20, 2021
Messages
16,097
Location
Neversex
I still don't know why this is needed.
It's one extra thing for someone to guess, right now the site asks for "your username or email" and your password.
What extra thing, you don't need BOTH the username AND the email, just one of them. The usernames are all public, so a potential hacker already has all of them.
 

InD_ImaginE

Arcane
Patron
Joined
Aug 23, 2015
Messages
6,436
Pathfinder: Wrath
Use email and disable 2FA?

After all can't bruteforce if you don't know the email.

2 problems are solved this way
Nah, if they have your password, they also have your email address.

I mean yeah if they got it from a leak there is nothing you can do anyway

But the mass delete in ukraine thread iirc was because of brute force? O r was it due to leak? Because that was what causing mods went full gay with 2FA right?
 

Haba

Harbinger of Decline
Patron
Joined
Dec 24, 2008
Messages
1,872,362
Location
Land of Rape & Honey ❤️
Codex 2012 MCA Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2
Use email and disable 2FA?

After all can't bruteforce if you don't know the email.

2 problems are solved this way
Nah, if they have your password, they also have your email address.

I mean yeah if they got it from a leak there is nothing you can do anyway

But the mass delete in ukraine thread iirc was because of brute force? O r was it due to leak? Because that was what causing mods went full gay with 2FA right?
Not brute force. People use the same username/password combo on multiple sites, site gets hacked, data gets leaked.
 

Semiurge

Arcane
Joined
Apr 11, 2020
Messages
8,326
Location
Faery glade
Does it still take decades to brute force a strong password with dozens of letters - both upper and lower case, numbers and misc. characters? I imagine brute forcing is simply not worth it anymore as there are easier ways to obtain passwords and other session tokens.
 

Cohesion

Arcane
Patron
Joined
May 14, 2015
Messages
1,732
Location
Moscow, Russia
Codex+ Now Streaming!

muckguppy

Magister
Joined
Jan 1, 2011
Messages
218
login by sticking my dick in your ass
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom