Page 1 of 1

Google Authentication (2-Step Verification) Account Support

PostPosted: Thu Mar 24, 2016 11:43 pm
by lockpower
With the news of the recent account banning spree (which is a great thing!) and the news that the staff is going to spend 1-2 weeks sorting out the hacked from the created gold spamming accounts, I think it would be not only in the players best interest but also the staff's to implement some sort of 2-Step Verification onto your account.

If you have 2-Step Verification (Google Authentication, Authy, Etc...) even if someone were to hack your account with an old password (which you should not use in the first place, but come on, people are human....) they would be unable to change the password and thus lock the person out of their account.

It would be awesome if there was authentication on the login server itself, but not sure how you could EASILY get that accomplished without making some sort of dedicated client, but that's not my field of expertise so maybe it is easier than I think.

Anyway, Devs/GM's, is the 2-Step Verification process something you would/are considering adding?

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 12:11 am
by leetdemon
I support this suggestion! Its a great idea

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 12:28 am
by devildog4355
I believe with the current client this is not possible since 2 step was not even thought of back in 2005. although a good idea i think this would be hard to implement since they are limited from a client side standpoint.

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 7:41 am
by Athene
You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 3:25 pm
by leetdemon
Athene wrote:You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.



Exactly this....ive saw many websites using google authenticator.

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 7:42 pm
by lockpower
Athene wrote:You don't need that on the client, we just need to be able to login on the website using Google auth and from there manage our whitelisted IP's and other account security settings. If only the withelisted IP's can connect on the client and the website use Google auth I'll feel safe.


Yes, this is what I had in mind and would be perfect. It should also be very easy to do setup.

Re: Google Authentication (2-Step Verification) Account Supp

PostPosted: Fri Mar 25, 2016 8:51 pm
by devildog4355
would have to agree, website 2 step would be helpful.