Putting the 'role' back in role-playing games since 2002.
Donate to Codex
Good Old Games
  • Welcome to rpgcodex.net, a site dedicated to discussing computer based role-playing games in a free and open fashion. We're less strict than other forums, but please refer to the rules.

    "This message is awaiting moderator approval": All new users must pass through our moderation queue before they will be able to post normally. Until your account has "passed" your posts will only be visible to yourself (and moderators) until they are approved. Give us a week to get around to approving / deleting / ignoring your mundane opinion on crap before hassling us about it. Once you have passed the moderation period (think of it as a test), you will be able to post normally, just like all the other retards.

PUBLIC SERVICE ANNOUNCEMENT: 2FA NOW MANDATORY - YOU DON'T NEED A PHONE NUMBER FFS

Skinwalker

*meows in an empty room*
Patron
Village Idiot
Joined
Aug 20, 2021
Messages
12,601
Location
Yessex
Remove the delete button, problem solved.

Doing this 2FA routine every 30 days on every device is ridiculous bullshit for a discussion forum.
Remove yourself, and you won't have to do this every 30 days. Problem solved.
 

LarryTyphoid

Scholar
Joined
Sep 16, 2021
Messages
2,233
This is the first time the Russia-Ukraine war has affected ME personally, and it was caused by a vatnik. I hope Russia gets carpetbombed for this inconvenience to me. At least until a Ukrainefag does something worse.
 

Atlantico

unida e indivisible
Patron
Joined
Sep 7, 2015
Messages
17,120
Location
Midgard
Make the Codex Great Again!
Atlantico - Pwned in 1 data breach
I looked up my username on that website and it came up as being part of a databreach at Gawker

I've never even used that website, let alone created an account

There are other "Atlantico" accounts out there you know and when search by my email, Gawker does not show up

This isn't that easy
 

Haba

Harbinger of Decline
Patron
Joined
Dec 24, 2008
Messages
1,872,089
Location
Land of Rape & Honey ❤️
Codex 2012 MCA Divinity: Original Sin Project: Eternity Torment: Tides of Numenera Wasteland 2
Atlantico - Pwned in 1 data breach
I looked up my username on that website and it came up as being part of a databreach at Gawker

I've never even used that website, let alone created an account

There are other "Atlantico" accounts out there you know and when search by my email, Gawker does not show up

This isn't that easy
Nah, The Brazilian Slaughter, for example baffles me. I can't find his nick on any obvious breaches. Adminos could tell us if there are repeated login attempts (dictionary attack?) or are they getting in with a handful of tries.

And would be interesting to hear which users have had password fails (before the MFA requirement).
 

LarryTyphoid

Scholar
Joined
Sep 16, 2021
Messages
2,233
You fags don't use password managers? That's all I need. I don't even have my real email attached to this account, it's a burner from tempmail. And I keep the password to the password manager on a card in my wallet. It's easy.
 

ind33d

Learned
Joined
Jun 23, 2020
Messages
1,798
last thing i need is for someone to pwn my account and start posting retarded shit like "Bioshock Infinite was good"
 

NecroLord

Dumbfuck!
Dumbfuck
Joined
Sep 6, 2022
Messages
14,638
Atlantico - Pwned in 1 data breach
I looked up my username on that website and it came up as being part of a databreach at Gawker

I've never even used that website, let alone created an account

There are other "Atlantico" accounts out there you know and when search by my email, Gawker does not show up

This isn't that easy
Nah, The Brazilian Slaughter, for example baffles me. I can't find his nick on any obvious breaches. Adminos could tell us if there are repeated login attempts (dictionary attack?) or are they getting in with a handful of tries.

And would be interesting to hear which users have had password fails (before the MFA requirement).
But how did they get to those accounts? Password guessing?
 

Tacgnol

Shitlord
Patron
Joined
Oct 12, 2010
Messages
1,871,883
Codex 2016 - The Age of Grimoire Grab the Codex by the pussy RPG Wokedex Strap Yourselves In Codex Year of the Donut Shadorwun: Hong Kong Divinity: Original Sin 2 Steve gets a Kidney but I don't even get a tag. Pathfinder: Wrath I helped put crap in Monomyth
Now I have to use my phone to use a website that doesn't even have rusty? wtf
Reminder that rpghq does not require 2fa and also has all the rusty you could want

Rusty actually advocates the use of 2FA:
1685726599458.png
 

Tacgnol

Shitlord
Patron
Joined
Oct 12, 2010
Messages
1,871,883
Codex 2016 - The Age of Grimoire Grab the Codex by the pussy RPG Wokedex Strap Yourselves In Codex Year of the Donut Shadorwun: Hong Kong Divinity: Original Sin 2 Steve gets a Kidney but I don't even get a tag. Pathfinder: Wrath I helped put crap in Monomyth
Now I have to use my phone to use a website that doesn't even have rusty? wtf
Reminder that rpghq does not require 2fa and also has all the rusty you could want

Rusty actually advocates the use of 2FA:
View attachment 36858
But it's not required and he doesn't advocate for the shitty phone kind.
You can do the Codex one without a phone as well though, so I don't see the issue.
 

Atlantico

unida e indivisible
Patron
Joined
Sep 7, 2015
Messages
17,120
Location
Midgard
Make the Codex Great Again!
Nah, The Brazilian Slaughter, for example baffles me. I can't find his nick on any obvious breaches.
There are many false-positives and others marked "unverified" on the HIBP website

I have only ever used this nickname here and on Rusty's place, nor do I use the same password between these two sites, so anyone wanting to steal my account would have to guess the password

Not super likely to happen
 

Skinwalker

*meows in an empty room*
Patron
Village Idiot
Joined
Aug 20, 2021
Messages
12,601
Location
Yessex
A very obvious solution to this problem would be disabling login by username. Everyone can see your username. Match it up with a password, and voile.

However, if the RPGCodex allowed login only by email address, it would be a lot harder, as your email is private to everyone but admins.

Now the potential hacker would have to match up three pieces of information, two of which are supposed to be private. This would prevent most of these hacks, and no need to abuse your userbase with 2FA.
 

As an Amazon Associate, rpgcodex.net earns from qualifying purchases.
Back
Top Bottom