@ultrilliam while the login system is great. I think QuestionCove could benefit from the option of enabling 2FA on your account. While the chances of QC being hacked are low, it's not impossible.
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
JusJeyk:
I use an Authenticator App for nearly everything I have online, and I'd like to be able to have one for QuestionCove as well. It would add an extra layer of website security.
xXAikoXx:
I think that'd be highly useful tbh
DUXK:
yes very useful and I agree with all of it
MaxTon:
I dont agree with that what so ever a 2FA would make account recovery almsot impossible if you got locked out some how
Spectrum:
@maxton wrote:
I dont agree with that what so ever a 2FA would make account recovery almsot impossible if you got locked out some how
So don't enable it? Simple as that.
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
Twaylor:
2FA is annoying, first off you have to know the users name and then use a password guesser for like 2 months
Twaylor:
Honestly y'all just need better passwords.
NaiNoah:
Gang js dont sign out when you're done using the site, or make your passwords more easier for yourself
Breathless:
you all should be remembering ur passwords anyway
Breathless:
it shouldn't be that hard unless ur using Google for passwords
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
curriful:
@twaylor wrote:
Honestly y'all just need better passwords.
I don't mean this in any sort of offensive way, but just having a 'better password' doesn't change the fact that you are still in risk of getting hacked if there isn't some sort of MFA (Multi-Factor Authentication) on your account.
Any sort of MFA in general would make it harder for accounts to be hacked, and even better, if you have an email on your account you can always just send something in like a "forgot password" report to get your password back.
Twaylor:
use a how strong is my password site
@curriful wrote:
@twaylor wrote:
Honestly y'all just need better passwords.
I don't mean this in any sort of offensive way, but just having a 'better password' doesn't change the fact that you are still in risk of getting hacked if there isn't some sort of MFA (Multi-Factor Authentication) on your account.
Any sort of MFA in general would make it harder for accounts to be hacked, and even better, if you have an email on your account you can always just send something in like a "forgot password" report to get your password back.
Breathless:
for starters, who would hack a acc on qc
Breathless:
what incriminating Data do you have on ur acc for it to be hacked
Twaylor:
mine takes 8 octillion years with the best brute force hacking method
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
NaiNoah:
Well most hackers on here mostly arent looking for incriminating info, js trolls tryna be funny or sum
Breathless:
this website is used to be helped with school related subjects, and socializing. not chat sites,
Ultrilliam:
@curriful wrote:
@twaylor wrote:
Honestly y'all just need better passwords.
I don't mean this in any sort of offensive way, but just having a 'better password' doesn't change the fact that you are still in risk of getting hacked if there isn't some sort of MFA (Multi-Factor Authentication) on your account.
Any sort of MFA in general would make it harder for accounts to be hacked, and even better, if you have an email on your account you can always just send something in like a "forgot password" report to get your password back.
And then all of that is meaningless in the event of session hijacking, which makes up 90% of online attacks right now.
curriful:
@ultrilliam wrote:
@curriful wrote:
@twaylor wrote:
Honestly y'all just need better passwords.
I don't mean this in any sort of offensive way, but just having a 'better password' doesn't change the fact that you are still in risk of getting hacked if there isn't some sort of MFA (Multi-Factor Authentication) on your account.
Any sort of MFA in general would make it harder for accounts to be hacked, and even better, if you have an email on your account you can always just send something in like a "forgot password" report to get your password back.
And then all of that is meaningless in the event of session hijacking, which makes up 90% of online attacks right now.
there's been hijacking?? i had no clue
Breathless:
@nainoah wrote:
Well most hackers on here mostly arent looking for incriminating info, js trolls tryna be funny or sum
I don't find that by any means bad. because most of the "hackers" I've seen on qc are ppl messing around
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
Ultrilliam:
I'm referring to all online attacks, not QC in particular. Session hijacking is when a user gains access to a users cookies, and steals the session tokens for a user. Since the user is already logged in according to those tokens, it bypasses all authentication
Twaylor:
phishing attempts are common
Breathless:
@ultrilliam wrote:
I'm referring to all online attacks, not QC in particular. Session hijacking is when a user gains access to a users cookies, and steals the session tokens for a user. Since the user is already logged in according to those tokens, it bypasses all authentication
what am getting at is don't share personal info
Ultrilliam:
1) Don't share personal info
2) Don't click on suspicious links (since they could potentially hijack your cookies)
3) Don't run random executables
The 3 basic rules of internet safety.
Either way, at this moment I don't plan to add MFA because I currently have no clue how to, and I feel there are better things I could improve on QC rather than researching how to add MFA. Perhaps in the future however
Twaylor:
@breathless wrote:
@ultrilliam wrote:
I'm referring to all online attacks, not QC in particular. Session hijacking is when a user gains access to a users cookies, and steals the session tokens for a user. Since the user is already logged in according to those tokens, it bypasses all authentication
what am getting at is don't share personal info
a TON of people on here struggle with that :sob:
Still Need Help?
Join the QuestionCove community and study together with friends!
Sign Up
Breathless:
for sure
Breathless:
if ur worried Abt being hacked or losing ur acc
Just don't be stupid and randomly give ur acc info to people, or in general
don't ragebait the mods</3