sign in security (2fa)

Suggest new features or changes to Chicken Smoothie.

Re: sign in security (2fa)

Postby Lacuna » Tue Jul 04, 2023 7:06 pm

    Just to be clear, I have no power to make sitewide announcements. I just wanted to put that info here as a PSA as the thread was getting off-topic. I have been posting where I can to the best of my abilities since I have been available (I personally was away at a work conference when this started). I apologize, I should have requested the thread to get back on topic in my post, but I am doing so now.
User avatar
Lacuna
Admin Assistant
 
Posts: 11760
Joined: Sat Apr 09, 2011 6:50 pm
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby lovely! » Wed Jul 05, 2023 8:02 am

10000% support

_________________________________________________________________[/size]
My life goal is to be a living meme
Image

Thanos snap me out of my mistakes
User avatar
lovely!
 
Posts: 2391
Joined: Tue Dec 19, 2017 6:14 am
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby Darni » Wed Jul 05, 2023 8:42 am

Lacuna wrote:
    I don't know if it was said on this thread, but CS's security was not compromised. User data was breached from another site in the past, which allowed bad actors to get into some CS accounts where users had not updated their passwords or used unique passwords. If you follow proper password protocol you are likely not in danger (can't say never, because some CS "hacks" come from literally inside your house, for example) and there is no reason to take a break from the site or anything similar. Please do not spread misinformation about data from CS being compromised, as this is not true.


Gonna snip this little part because when this first started happening I was told ChickenSmoothie's security was breached and then told it was other sites like Neopets / other that got breached and the hackers were trying accounts here with same names using same password as the other site and getting in. I know you can't answer everything so I'm not expecting a long answer, but were all the users hacked so far sharing the password with other forum games/ pet collected / same type of sites? Again if you can't confirm or answer that's totally okay too!
Image

"Please do not trade with me to add to major hoards"
User avatar
Darni
 
Posts: 823
Joined: Wed Feb 22, 2023 10:19 am
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

sign in security (2fa)

Postby lyney » Sun Jul 16, 2023 12:38 pm

still going to bump this up! while cs itself has not been compromised, and the hackings themselves have stopped (as far as i'm aware), i still feel that 2fa would be super helpful. we've made brilliant steps in the right direction, but 2fa can help prevent issues like this from occurring in the first place.
Image
─-────────────────────────────
【 → cross • he/they • biromantic • sagittarius • adult 】
tired college student
─-────────────────────────────
User avatar
lyney
 
Posts: 3011
Joined: Sun May 22, 2016 6:59 am
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby ARACHNOPHOBI4 » Sun Jul 16, 2023 5:59 pm

Support! For safetyyy!!! * riots but in a friendly way *
Image

Let's have a party
There's a full moon in the sky
It's the hour of the wolf
and I don't want to die
Image
Image
Link
Link
credit
User avatar
ARACHNOPHOBI4
 
Posts: 1996
Joined: Wed Aug 05, 2020 7:57 am
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby Adamented » Tue Jul 18, 2023 12:07 pm

Support!

I think the people expecting one Mod to have the power to inform the entire userbase without necessarily being fully informed themselves have unrealistic expectations. The answer to not knowing and not having information is not to assume and spread misinformation, it's to ask for a comment from the staff and be patient while they- working as hard as they can to keep the site you love functional- do their best to handle the situation and deliver the information clearly and completely without misinformation.

We need to remember CS Staff are human too! They need time to do their jobs correctly, there's much more on the line for them if they accidentally perpetuate bad info. Unlike the users using ignorance as an excuse to spread hearsay.


[ ABOUT ]

Ada
AdamAddie
he / she / they

✦ ✦ ✦
Image
Image
[ MY STUFF ]
the gladewood
CLs / buzzies / wermz

Image
[ LINKS ]
ImageImage @adamented

Art T.o.S.
Image

[ SUPPORT SELECT BY RARITY ]
thread
Image
Image
User avatar
Adamented
 
Posts: 2714
Joined: Sun Sep 28, 2014 2:40 am
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby devourers.of.god » Sun Jul 30, 2023 3:32 pm

support

Image
♥ x ♥
|| acheron || him/his ||
x
|| " you didn't look away. " ||
♥ x ♥
Image
Image
pfp credit
User avatar
devourers.of.god
 
Posts: 1257
Joined: Sat Jul 23, 2022 3:16 pm
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby conarcoin » Fri Aug 04, 2023 12:23 pm

i would really appreciate the ability to link my cs account to authy - i prefer it over all other 2fa (email, phone) as it doesn't require me to put personal information into a site and also doesn't rely on me being able to access my email account in the offchance that my email is compromised or i can't access it for some other reason. instead, i just open the authy app on my phone and grab the code and go, and i have everything in one place, and i can rest assured that even if authy were to be compromised they would not have access to my accounts through it.
Image

connor, he/any, adult
talk to me about smplive
trades - collections

User avatar
conarcoin
 
Posts: 1991
Joined: Sat May 01, 2021 12:57 pm
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby larn » Sun Aug 13, 2023 7:21 pm

Support! My accounts on other websites have been saved so many times because of 2fa and I would hate to lose my CS account through hacking.
User avatar
larn
 
Posts: 1382
Joined: Fri Dec 12, 2014 4:14 pm
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Re: sign in security (2fa)

Postby Simon » Tue Aug 15, 2023 2:56 am

    Thank you for the thoughtful suggestion. We have discussed this and came the the conclusion that we have to decline this suggestion for the following reasons:

      -Implementing a third-party sign-on solution comes with a big technical cost for a security benefit that isn't any better than using a unique password on every website

      -Many users would get locked from their accounts if they lose their phones or something similar, which will create a lot of administrative problems for our staff. The recovery pathway for lost 2-factor on websites is based on reconfirming ownership of your email account, and we will be using that same reverification of email account in our own login security features instead, without causing drama when trading in for a new phone.
User avatar
Simon
Admin
 
Posts: 11216
Joined: Sat Sep 07, 2013 3:39 pm
My pets
My items
My wishlist
My gallery
My scenes
My dressups
Trade with me

Who is online

Users browsing this forum: No registered users and 0 guests