How to: use two-step verification (2fa)

I have found Google Authenticator a bit confusing most of the time (plus it involves switching back between using the desktop + mobile) .... Needs to use the system more to get a hang of it! But 2nd step verification via email seems fine.
 
Yeah, for those that aren't a fan of apps, the email option is really simple and means you can use your phone, computer, TV, toaster or whatever else is smart enough to receive emails.
The app is my choice, but we wanted to let users choose.
 
very inconvenience

I am an adult and I can take care of my password, Why should I do all these extra steps because some people cant keep their account secure?
It should be optional.
 
Since I am forced to choose I guess it will have to be email for me. I hate having to grab some other device to run an app just so I can login somewhere.
 
Since I am forced to choose I guess it will have to be email for me. I hate having to grab some other device to run an app just so I can login somewhere.

You are not forced to do anything you are not an upgraded member.

I suggested this as being mandatory for people abe to sell 2 or 3 years back, at the time it was rejected.

I guess having upgraded members accounts being hacked, then innocent members scammed via PM taking payments in crypto has meant this is a safer option.

There were too many Shitlists where people were scammed by a member, only for us to see that member wasn't online, but their account had been hacked, from an IP the other side of the globe.
 
Yes, but in the future I may become an upgraded member at which time this rule will apply to me. Thanks for explaining the history and your reasoning behind the change.
 
I mean if you don't clear your cache, you'll need to do this every 30 days - not every single time. This is 12 times a year to put some numbers into a field.

It's similar to "Why should I have to put CAPS and punctuation symbols in my password, it's my choice". We're doing it to protect you guys, not as a pnishment. This also reduces tickets/account recoveries etc. when password leaks happen/same passwords used across different websites :) .
 
I mean if you don't clear your cache, you'll need to do this every 30 days - not every single time. This is 12 times a year to put some numbers into a field.

It's similar to "Why should I have to put CAPS and punctuation symbols in my password, it's my choice". We're doing it to protect you guys, not as a pnishment. This also reduces tickets/account recoveries etc. when password leaks happen/same passwords used across different websites :) .
this is a punishment for people who upgraded their account because normal members doesnt need to bother and do these steps.
 
this is a punishment for people who upgraded their account because normal members doesnt need to bother and do these steps.
I get your side of it. We love feedback, so we'll take it on board - this is what BHW is about!
 
Gotta say i really dont like this. But hey its your forum.
It is their forum in terms of ownership, but it was supposed to be more a sharing experience between black hatters, thus acted more like a co-op. The site doesn't own the risks taken by buyers and sellers (to whom it should be shouldered), but has assumed a responsibility to mitigate them it didn't have to. From many past testimonies, BHW used to be primarily a community, with a marketplace. Now it's primarily a marketplace, with a community, and protecting that market is driving their changes. I did the 2FA, but if I had known this was coming before I reupped for JrVip, I probably wouldn't have.
 
Really hate the fact that it is mandatory.
What happens if 2FA isn't set up till 30th Jun?
 
Really hate the fact that it is mandatory.
What happens if 2FA isn't set up till 30th Jun?

Then you won't be able to log in until it is.
There are many options from email to desktop app to phone.
You only have to do it once a month - 12 times a year which keeps your account secure.

my acc is always logged in., do I still need to set up 2FA?
i hate 2FA tbh its time-wasting :(

curious to know the reason behind this 2FA mandatory decision?

If set up within the Authy desktop app or password apps like 1 password it's simply another click or you can do it via email which is slightly less secure but better than nothing.

We've decided to make it mandatory due to the increase in benefits for Jr. VIP's over the coming months and for the security of your account going forward it's important to ensure that it's kept secure. It's a couple of seconds for a lot of additional security and benefit.

Thank you for allowing to do this with email.

I hate them fucking apps :p

No problem.
 
I think it would help to know what methods hackers are using to hack in to BHW accounts. Is it through phishing methods or guessing non-complex passwords, or... I usually chose, what I would consider, impossible passwords to guess, but I also think the multiple authentication methods can be a hassle.
 
It is a nice idea to have an account fully authenticated but to further strengthen 2nd security layer , considering sending verification codes to phone number should also be accommodated rather than code-generating app such as Authy or Google Authenticator

I think it would help to know what methods hackers are using to hack in to BHW accounts. Is it through phishing methods or guessing non-complex passwords, or... I usually chose, what I would consider, impossible passwords to guess, but I also think the multiple authentication methods can be a hassle.
I do not believe or think there is such thing as "impossible passwords" to guess when it has to do with cybersecurity, the more complex you think a cybersecurity is the more it could be broken or penetrated by a very simple algorithm.
 
You can have a really difficult password, but if someone happens to enter it correctly by shear dumb luck, they get in, and your account is compromised anyway! ;-)
 
Back
Top