Check out all of the details of this month's Patch Notes, featuring the Mini-games + Quality of Life Update! https://mabinogi.nexon.net/news/91106/mini-games-quality-of-life-update-patch-notes-april-11th
[NEW MILLETIANS] Please note that all new forum users have to be approved before posting. This process can take up to 24 hours, and we appreciate your patience.
If this is your first visit, be sure to check out the Nexon Forums Code of Conduct. You have to register before you can post, so you can log in or create a forum name above to proceed. Thank you for your visit!

Adding two factor authentication

TechnixTechnix
Mabinogi Rep: 665
Posts: 20
Member
in Feedback and Suggestions
Is Nexon going to add 2FA or is it too expensive for them to implement?

Comments

  • ParadoxLostParadoxLost
    Mabinogi Rep: 1,575
    Posts: 108
    Member
    ..why would you want that?
    Greta
  • TechnixTechnix
    Mabinogi Rep: 665
    Posts: 20
    Member
    For security.
  • GretaGreta
    Mabinogi Rep: 51,805
    Posts: 6,975
    Member
    edited May 24, 2017
    Technix wrote: »
    For security.

    That's all? I think it's unnecessary since we already have secondary password in game, also it doesn't seem like our accounts are in such danger that it needs to be added here. Unless i'm wrong?
  • TechnixTechnix
    Mabinogi Rep: 665
    Posts: 20
    Member
    edited May 24, 2017
    If I manage to steal / hack your password, I can go waste whatever NX you have in credit or pre-paid buying junk. I could make purchases under your account then reverse transaction, then get you banned.
    Through a longer method, I can go ahead and attempt to change your current password as well.

    I didn't want to spell out the obvious to you. "That's all". But there it is. Some ideas for other people to try out who happen to share passwords with their 'friends'.

    If not that, then constantly resetting your secondary passwords.

    What kind of arguments are you making that you want LESS security?

    A lot of places have it optional and you can enabled it. If you don't care, then just don't use it.
    RaishiiYellowBin
  • GretaGreta
    Mabinogi Rep: 51,805
    Posts: 6,975
    Member
    edited May 24, 2017
    Well, when you make suggestion first off you must explain it in detail why you are suggesting it and why it would be useful to the game and such, because posting a single line like "can Nexon add..." will only make people feel confused and uninformed about why you want it to be added here and most likely it will go to incomplete/more details needed category which means it will be ignored/forgotten forever.
    TechnixYellowBin
  • PolicromaPolicroma
    Mabinogi Rep: 6,730
    Posts: 564
    Member
    Attaching your account to your phone number or something could add an extra layer of security.... Or it could just lock folks out of their accounts. I personally think it'd be more secure than the "second password" as both regular and secondary password can be reset via email.

    TechnixYellowBin
  • AeolysAeolys
    Mabinogi Rep: 5,115
    Posts: 469
    Member
    The good about more security is self explanatory, it would be harder to lose your account to someone malicious.
    We also have to accept the potential negatives with more security. If we lose the means to pass security (losing passwords, phone tagging, etc.), it is harder to get our accounts back. The recovery process would have more failure states if/when we lose even one of our email, phone, etc.
    Last point is that too much security would be a bear to go through every time we would want to play. Its like... this door.
    If you ask what my opinion on this is, I'm on the fence on more security; its good to have, but is can weigh you down and become easier potentially lock yourself out.
    ...
    Maybe make it optional?
  • TechnixTechnix
    Mabinogi Rep: 665
    Posts: 20
    Member
    edited May 24, 2017
    Greta wrote: »
    Well, when you make suggestion first off you must explain it in detail why you are suggesting it and why it would be useful to the game and such, because posting a single line like "can Nexon add..." will only make people feel confused and uninformed about why you want it to be added here and most likely it will go to incomplete/more details needed category which means it will be ignored/forgotten forever.

    Oh fair enough. I really did think it was self explanatory but I see what you're saying.

    Example of it being optional:
    f6XDmAS.png
  • ParadoxLostParadoxLost
    Mabinogi Rep: 1,575
    Posts: 108
    Member
    edited May 25, 2017
    I would never, ever, consider giving nexon my phone number. NTY. If they were gonna add 2FA they'd be losing at least one player.

    Edit: I just wanna be clear, Nexon has some pretty shady business practices as it is, not to Defame them or anything, but like adding 2FA is just asking for trouble. At the very most, like it was mentioned before, make it optional.
    Greta
  • GretaGreta
    Mabinogi Rep: 51,805
    Posts: 6,975
    Member
    edited May 25, 2017
    I would never, ever, consider giving nexon my phone number. NTY. If they were gonna add 2FA they'd be losing at least one player.

    Yeah, i'm not a fan of adding my phone number in social websites too. I always decline when Facebook, Google and so on asks for my phone number just because my account will be "safer". No thanks, it only makes me feel like i might get stalked or/and spammed with messages via my phone if i plan to give it out in every account i have. I know i sound paranoid, but it's 2017 already, everything is possible in this technology world. Geez, i even got locked out from my Twitter account and they demand my phone number to verify it, but i highly refuse to give out my phone number because after you verify it you can't remove it anymore, you are only able to change your number... At least that's what i heard. I don't want to give out my phone number randomly everywhere, especially in social medias. I hate this so much.
  • NamiriNamiri
    Mabinogi Rep: 1,700
    Posts: 112
    Member
    edited May 25, 2017
    Technix wrote: »
    If I manage to steal / hack your password, I can go waste whatever NX you have in credit or pre-paid buying junk. I could make purchases under your account then reverse transaction, then get you banned.
    Through a longer method, I can go ahead and attempt to change your current password as well.

    I didn't want to spell out the obvious to you. "That's all". But there it is. Some ideas for other people to try out who happen to share passwords with their 'friends'.

    If not that, then constantly resetting your secondary passwords.

    What kind of arguments are you making that you want LESS security?

    A lot of places have it optional and you can enabled it. If you don't care, then just don't use it.

    Except there's no such thing as people getting their accounts hacked in Mabinogi. It's just idiots who share their passwords with people who later stab them in the back or people looking to cheat who get keyloggers by trying to download stuff like hacks for the game. Honestly the secondary password is already an annoying feature added in just to protect those sort of idiots from losing their accounts. So I hardly think we need a 3rd additional security feature added on top of all that.

    Honestly what's needed isn't more additional security measure hassles. What's needed is for people to stop sharing their passwords with other people or trying to download things they really shouldn't be. Because honestly that's the best way for someone to protect their account.
  • TechnixTechnix
    Mabinogi Rep: 665
    Posts: 20
    Member
    edited May 26, 2017
    Greta wrote: »
    I would never, ever, consider giving nexon my phone number. NTY. If they were gonna add 2FA they'd be losing at least one player.

    Yeah, i'm not a fan of adding my phone number in social websites too. I always decline when Facebook, Google and so on asks for my phone number just because my account will be "safer". No thanks, it only makes me feel like i might get stalked or/and spammed with messages via my phone if i plan to give it out in every account i have. I know i sound paranoid, but it's 2017 already, everything is possible in this technology world. Geez, i even got locked out from my Twitter account and they demand my phone number to verify it, but i highly refuse to give out my phone number because after you verify it you can't remove it anymore, you are only able to change your number... At least that's what i heard. I don't want to give out my phone number randomly everywhere, especially in social medias. I hate this so much.

    >
    A lot of places have it optional and you can enabled it. If you don't care, then just don't use it.

    Also, a lot of places nowadays have cheap/free burner SIMs to use. Don't have to use your primary number.

    Some of the things you mentioned are true too, and I think it's better to be paranoid and safe than sorry. Even better than being willfully ignorant like some people.
    Namiri wrote: »

    Except there's no such thing as people getting their accounts hacked in Mabinogi. It's just idiots who share their passwords with people who later stab them in the back or people looking to cheat who get keyloggers by trying to download stuff like hacks for the game. Honestly the secondary password is already an annoying feature added in just to protect those sort of idiots from losing their accounts. So I hardly think we need a 3rd additional security feature added on top of all that.

    Honestly what's needed isn't more additional security measure hassles. What's needed is for people to stop sharing their passwords with other people or trying to download things they really shouldn't be. Because honestly that's the best way for someone to protect their account.

    There's people who make bad character judgements and there's people who get infected files from ignorant friends who happen to get their passwords stolen.
    Your suggestion then is that they should just deal with the loss when it could have prevented it in the first place?
    You know what's an even better way not to have your password stolen? Quit Mabi.

    You can tell them not to do it as often as you want but people will do it anyway, and having optional, like I said earlier, 2FA would at least stop unintended logins to your account.

    It's not uncommon for people to re-use the same passwords on other sites. And if those other sites use plain text and gets compromised, that entire list gets sold off.

    And I wouldn't even try that "there's no such thing as getting hacked" argument.
    There's zero weight behind it.
    Greta
  • NamiriNamiri
    Mabinogi Rep: 1,700
    Posts: 112
    Member
    edited May 26, 2017
    Technix wrote: »
    There's people who make bad character judgements and there's people who get infected files from ignorant friends who happen to get their passwords stolen.
    Your suggestion then is that they should just deal with the loss when it could have prevented it in the first place?
    You know what's an even better way not to have your password stolen? Quit Mabi.

    You can tell them not to do it as often as you want but people will do it anyway, and having optional, like I said earlier, 2FA would at least stop unintended logins to your account.

    It's not uncommon for people to re-use the same passwords on other sites. And if those other sites use plain text and gets compromised, that entire list gets sold off.

    And I wouldn't even try that "there's no such thing as getting hacked" argument.
    There's zero weight behind it.

    You're absolutely right! It could have been prevented in the first place. Prevented by not sharing your password with other people like the game repeatedly reminds players off every single day. As well as being prevented by not downloading things you shouldn't be or saving/downloading random files from friends. So yes, I say if people can't just do those two very simple common sense things then they very much so definitely should learn to deal with the loss. Folks with common sense don't need to be further inconvenienced just to protect idiots who think that it's someone else's job to keep them safe from all the bad people in the world. Eventually people need to grow up and learn to actually take responsibility for their own actions.

    Oh, and as for your "You know what's an even better way not to have your password stolen? Quit Mabi. " line. Well there's an even better way than that actually. It's called don't even bother using the internet at all if you can't use even extremely basic common sense to protect yourself.

    Also, no I'll still be standing by my statement of there being no such thing as people getting their NA Mabinogi account hacked. Because unlike the case in your link where 13.2 million KR Maple Story players got their accounts compromised, NA Mabinogi probably only has a current total playerbase of 10,000 or less. That and the game isn't even very well known anymore due to the age of the game and the overall lack of advertisement for it. So given a big time serious hacker would stand almost nothing to gain from such a thing the chances of it ever being hacked are beyond abysmally low. Which is why the only way anyone has ever gotten get their NA Mabinogi account "hacked" in the 9 years the game has been running is by sharing their account details with someone or by downloading things they shouldn't be. In short all things that could easily be prevented with common sense.
  • GretaGreta
    Mabinogi Rep: 51,805
    Posts: 6,975
    Member
    edited May 27, 2017
    I actually forgot to mention, but lately there was a guy in Facebook Mabinogi groups who would randomly pm anyone of group members while sending a suspicious files saying that they have "a list of stuff" in there which they are giving away or say that they want to buy something from you and they are offering items to trade for it. Of course it was a file with malicious virus and few victims fell for it. Few people i knew of was hacked and lost their items in Mabinogi because of that sick fake named guy there. That guy tried to contact me too, but good thing i was paranoid and i didn't download that random file. These accidents happened almost 2 weeks ago. That's probably the reason you brought this thread up in the first place right?
  • TechnixTechnix
    Mabinogi Rep: 665
    Posts: 20
    Member
    edited May 30, 2017
    Namiri wrote: »

    You're absolutely right! It could have been prevented in the first place. Prevented by not sharing your password with other people like the game repeatedly reminds players off every single day. As well as being prevented by not downloading things you shouldn't be or saving/downloading random files from friends. So yes, I say if people can't just do those two very simple common sense things then they very much so definitely should learn to deal with the loss. Folks with common sense don't need to be further inconvenienced just to protect idiots who think that it's someone else's job to keep them safe from all the bad people in the world. Eventually people need to grow up and learn to actually take responsibility for their own actions.

    Oh, and as for your "You know what's an even better way not to have your password stolen? Quit Mabi. " line. Well there's an even better way than that actually. It's called don't even bother using the internet at all if you can't use even extremely basic common sense to protect yourself.

    Also, no I'll still be standing by my statement of there being no such thing as people getting their NA Mabinogi account hacked. Because unlike the case in your link where 13.2 million KR Maple Story players got their accounts compromised, NA Mabinogi probably only has a current total playerbase of 10,000 or less. That and the game isn't even very well known anymore due to the age of the game and the overall lack of advertisement for it. So given a big time serious hacker would stand almost nothing to gain from such a thing the chances of it ever being hacked are beyond abysmally low. Which is why the only way anyone has ever gotten get their NA Mabinogi account "hacked" in the 9 years the game has been running is by sharing their account details with someone or by downloading things they shouldn't be. In short all things that could easily be prevented with common sense.

    mmk, well goodluck with your subjective opinions with no facts backing them up.
    It's called don't even bother using the internet at all if you can't use even extremely basic common sense to protect yourself.
    Think you completely missed the point of the rhetoric, and tried setting a standard of common sense on password security ontop of that lol. It's not a thing and never will be.

    Also, I guess you didn't read what I said earlier, multiple times, about making it optional.
    Fortunately, not every human playing this game is like you.
    And fortunately not everyone grew up like you did, but that includes people who aren't tech savvy and only want to enjoy Mabi.

    Security through obscurity is a really bad practice if you think that's a legitimate argument.
    That and the game isn't even very well known anymore
    lol

    I actually forgot to mention, but lately there was a guy in Facebook Mabinogi groups who would randomly pm anyone of group members while sending a suspicious files saying that they have "a list of stuff" in there which they are giving away or say that they want to buy something from you and they are offering items to trade for it. Of course it was a file with malicious virus and few victims fell for it. Few people i knew of was hacked and lost their items in Mabinogi because of that sick fake named guy there. That guy tried to contact me too, but good thing i was paranoid and i didn't download that random file. These accidents happened almost 2 weeks ago. That's probably the reason you brought this thread up in the first place right?

    Partly.
    I wanted to post this earlier after new accounts were forced to use their email as a login name instead of any username people came up with.
    Then Nexon forced everyone, including old players that used a non-email username to login, to use an email as a login username. I know you could still use an email but this change just made it REALLY obvious.
    People re-use passwords everywhere and it just adds an extra vector for getting hit.
    Finally got around to posting it after seeing people keep getting hit by these losers sending out infected files.