Discuss Scratch
- Discussion Forums
- » Suggestions
- » Read the OP, it's way too long to put on the title
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
You need to type your old/actual password to change it, right? But what if someone logged in on your account? It will know your password already, type it in the box and do bad things on your account.
But if this was implemented, this wouldn't happen!
I suggest that every time that you change a email/password, you receive a token in your email, to type in a box to confirm that YOU are changing the email/password.
Pros:
More security
Guarants that you are the one changing the password/deleting your account/changing your email
If someone gets into a account, would need your email password, Scratch password, and a token
Can be turned on-off by Contact Us
Cons:
Harder email changing for the actual one (email)
Impossible to change email if the first got deactivated Use Contact Us to turn this off, and change email/password without this
But if this was implemented, this wouldn't happen!
I suggest that every time that you change a email/password, you receive a token in your email, to type in a box to confirm that YOU are changing the email/password.
Pros:
More security
Guarants that you are the one changing the password/deleting your account/changing your email
If someone gets into a account, would need your email password, Scratch password, and a token
Can be turned on-off by Contact Us
Cons:
Harder email changing for the actual one (email)
Impossible to change email if the first got deactivated Use Contact Us to turn this off, and change email/password without this
Last edited by ScratchCatDoBem (Jan. 19, 2023 21:13:41)
- PenguinLover1123
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
First password, then email. Even more protection
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
First password, then email. Even more protectionHmm, maybe i will add this to the OP

- Yellowsheep43
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.Yep, that's why i suggested this-
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.
In Account Settings, if a hacker get into your account, they can see your email and delete/change the password. But to do that, a email will be sent to your email (the one you used to confirm your account) with a token like “Af12Cd” saying like “This is a email confirming you are deleting/changing your password. If you didn't request this token, delete or ignore this email. Overwise, copy and paste this token into the bar.”
- PenguinLover1123
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
First password, then email. Even more protectionMore!:
first password, then email to original (current, non-changed email) email saying "Here's your first stage confirmation url for username: url If you did not request this, ignore this email and contact us“, then after first email, to the changed email saying ”Here's your second stage confirmation url for username: url If you did not request this, please ignore this and contact us"
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Cool idea! But i already posted something similar to that here-First password, then email. Even more protectionMore!:
first password, then email to original (current, non-changed email) email saying "Here's your first stage confirmation url for username: url If you did not request this, ignore this email and contact us“, then after first email, to the changed email saying ”Here's your second stage confirmation url for username: url If you did not request this, please ignore this and contact us"
- PenguinLover1123
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Con:Title
Edit: Mistyped send
Pros:
More security
Guarants that you are the one changing the password/deleting your account
Cons:
Nothing i can think of
Harder email changing for real one (Barely a problem)
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Uhh i posted that accidently but thanksCon:Title
Edit: Mistyped send
Pros:
More security
Guarants that you are the one changing the password/deleting your account
Cons:
Nothing i can think of
Harder email changing for real one (Barely a problem)

- ItsMe-XTV-
-
Scratcher
100+ posts
Read the OP, it's way too long to put on the title
What if your first email got deactivated?
How would verification happen then?
How would verification happen then?
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
What if your first email got deactivated?Hmm… Adding this to the cons
How would verification happen then?
- 9cjames1
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.It has never happend. Scratch does not have “hackers” however some people try to brute force their way into someones account. That's not hacking.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Uhhh it does, but also…Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.It has never happend. Scratch does not have “hackers” however some people try to brute force their way into someones account. That's not hacking.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.
Even if Scratch had no hackers, there would be passguessers, etc.
- 9cjames1
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
I meant nobody has hacked before.Uhhh it does, but also…Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.It has never happend. Scratch does not have “hackers” however some people try to brute force their way into someones account. That's not hacking.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.Even if Scratch had no hackers, there would be passguessers, etc.
And passguessing is not hacking.
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Prevention is always needed.I meant nobody has hacked before.Uhhh it does, but also…Perfect. This will add extra protection against account “hackers”; Now they need to know both your email AND its password AND your scratch password.It has never happend. Scratch does not have “hackers” however some people try to brute force their way into someones account. That's not hacking.
And that's not happening unless somebody got into your email. And even then, in pretty much all scenarios they use it for things other than to “hack” your scratch account.Even if Scratch had no hackers, there would be passguessers, etc.
And passguessing is not hacking.
- Yellowsheep43
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
It has never happend. Scratch does not have “hackers” however some people try to brute force their way into someones account. That's not hacking.That's why I put “Hacker” in quotations. It's the easiest way to send a message without having to explain much. What if I used “Passguessers?” Not many people would know what those are.
I don't need another lecture on this type of thing. I know what I am doing.
- ScratchCatDoBem
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Moist bumppp 





- PenguinLover1123
-
Scratcher
1000+ posts
Read the OP, it's way too long to put on the title
Maybe turning this on/off? By contact-us-ing.
Last edited by PenguinLover1123 (Sept. 22, 2021 19:17:41)
- Discussion Forums
- » Suggestions
-
» Read the OP, it's way too long to put on the title





