Google Authentication (2-Step Verification) Account Support

Discussion forum related to Nostalrius Begins in general.

Google Authentication (2-Step Verification) Account Support

by lockpower » Thu Mar 24, 2016 11:43 pm

With the news of the recent account banning spree (which is a great thing!) and the news that the staff is going to spend 1-2 weeks sorting out the hacked from the created gold spamming accounts, I think it would be not only in the players best interest but also the staff's to implement some sort of 2-Step Verification onto your account.

If you have 2-Step Verification (Google Authentication, Authy, Etc...) even if someone were to hack your account with an old password (which you should not use in the first place, but come on, people are human....) they would be unable to change the password and thus lock the person out of their account.

It would be awesome if there was authentication on the login server itself, but not sure how you could EASILY get that accomplished without making some sort of dedicated client, but that's not my field of expertise so maybe it is easier than I think.

Anyway, Devs/GM's, is the 2-Step Verification process something you would/are considering adding?
User avatar
lockpower
Grunt
Grunt
 

Re: Google Authentication (2-Step Verification) Account Supp

by leetdemon » Fri Mar 25, 2016 12:11 am

I support this suggestion! Its a great idea
leetdemon
Grunt
Grunt
 

Re: Google Authentication (2-Step Verification) Account Supp

by devildog4355 » Fri Mar 25, 2016 12:28 am

I believe with the current client this is not possible since 2 step was not even thought of back in 2005. although a good idea i think this would be hard to implement since they are limited from a client side standpoint.
devildog4355
Sergeant
Sergeant
 

Re: Google Authentication (2-Step Verification) Account Supp

by Athene » Fri Mar 25, 2016 7:41 am

You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.
<Genesis>
youtube.com/GenesisGuilde

MSBT [Continued] landed on Nostalrius, check it here: forum.nostalrius.org/viewtopic.php?f=63&t=1721
User avatar
Athene
Senior Sergeant
Senior Sergeant
 

Re: Google Authentication (2-Step Verification) Account Supp

by leetdemon » Fri Mar 25, 2016 3:25 pm

Athene wrote:You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.



Exactly this....ive saw many websites using google authenticator.
leetdemon
Grunt
Grunt
 

Re: Google Authentication (2-Step Verification) Account Supp

by lockpower » Fri Mar 25, 2016 7:42 pm

Athene wrote:You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.


Yes, this is what I had in mind and would be perfect. It should also be very easy to do setup.
User avatar
lockpower
Grunt
Grunt
 

Re: Google Authentication (2-Step Verification) Account Supp

by devildog4355 » Fri Mar 25, 2016 8:51 pm

would have to agree, website 2 step would be helpful.
devildog4355
Sergeant
Sergeant
 


Return to General discussion