Discuss Scratch
- Discussion Forums
- » Suggestions
- » 2-Factor Authentication
- CK-2
-
17 posts
2-Factor Authentication
Yah because people have been hacked and we need like an I am not a robot or I am not hacking anyone or something like that
- Dagriffpatchfan
-
1000+ posts
2-Factor Authentication
Support, I would like the extra security
- LadyNoir8022
-
27 posts
2-Factor Authentication
Support. Even I would like the extra security.
- Steve0Greatness
-
1000+ posts
2-Factor Authentication
This might not be possible, but it'd be nice if 2FA could work with rolling code apps like Microsoft Authenticator. Basically, the service and the authenticator agree on a seed, which is then used to change out a code after a set time-frame (usually a minute). I say this might not be possible because it could eat up server capacity very easily (it would be a constant source of CPU usage on the server).
- TariqjeMaakt
-
91 posts
2-Factor Authentication
That's not how 2fa works, t's a key generated based on the current unix time (together with some complicated encryption and math stuff) so it would barely eat up any processing power since most of it (except comparing the correct code to the inputted code) is done locally. This might not be possible, but it'd be nice if 2FA could work with rolling code apps like Microsoft Authenticator. Basically, the service and the authenticator agree on a seed, which is then used to change out a code after a set time-frame (usually a minute). I say this might not be possible because it could eat up server capacity very easily (it would be a constant source of CPU usage on the server).
- Steve0Greatness
-
1000+ posts
2-Factor Authentication
That actually makes sense. That's not how 2fa works, t's a key generated based on the current unix time (together with some complicated encryption and math stuff) so it would barely eat up any processing power since most of it (except comparing the correct code to the inputted code) is done locally.
- doggy_boi1
-
1000+ posts
2-Factor Authentication
semi support
scratch accounts aren't really “hacked” often so its not necessary. You can never have to much security, but at the same time most users would have this off anyways
scratch accounts aren't really “hacked” often so its not necessary. You can never have to much security, but at the same time most users would have this off anyways
- A-MARIO-PLAYER
-
1000+ posts
2-Factor Authentication
Support for reasons in OP. /j
Seriously though, this extra layer of security could help prevent hackers from stealing accounts. Also, FIDO2 has recently started to emerge and it makes login safer by only allowing to login on trusted devices.
Seriously though, this extra layer of security could help prevent hackers from stealing accounts. Also, FIDO2 has recently started to emerge and it makes login safer by only allowing to login on trusted devices.
- OnTheCode99
-
500+ posts
2-Factor Authentication
(#344)
This might not be possible, but it'd be nice if 2FA could work with rolling code apps like Microsoft Authenticator. Basically, the service and the authenticator agree on a seed, which is then used to change out a code after a set time-frame (usually a minute). I say this might not be possible because it could eat up server capacity very easily (it would be a constant source of CPU usage on the server).
Just send an automated email to the users email address. Why do we have to use Microsoft Authenticator?
- sonic__fan
-
1000+ posts
2-Factor Authentication
As stated in post #26, we can use multiple methods to send the code. We can use:(#344)Just send an automated email to the users email address. Why do we have to use Microsoft Authenticator?
This might not be possible, but it'd be nice if 2FA could work with rolling code apps like Microsoft Authenticator. Basically, the service and the authenticator agree on a seed, which is then used to change out a code after a set time-frame (usually a minute). I say this might not be possible because it could eat up server capacity very easily (it would be a constant source of CPU usage on the server).
- Email
- SMS
- Authentication Apps (Google Authenticate, Microsoft Authenticator)
- mumu245
-
1000+ posts
2-Factor Authentication
(#354)Email is fine, but I prefer token apps because it doesn't require any more resources to maintain, and it's the most secure since it requires physical access to the device with the app.As stated in post #26, we can use multiple methods to send the code. We can use:(#344)Just send an automated email to the users email address. Why do we have to use Microsoft Authenticator?
This might not be possible, but it'd be nice if 2FA could work with rolling code apps like Microsoft Authenticator. Basically, the service and the authenticator agree on a seed, which is then used to change out a code after a set time-frame (usually a minute). I say this might not be possible because it could eat up server capacity very easily (it would be a constant source of CPU usage on the server).Either the community can decide which one will be used, the Scratch Team can decide, or the user can choose for themself.
- SMS
- Authentication Apps (Google Authenticate, Microsoft Authenticator)
SMS is very expensive to send and bad for privacy.
- warriorcatsfreakalt
-
1000+ posts
2-Factor Authentication
Not sure a phone text would be the best idea, but for an email, this is a great idea. Some people would like some extra security, and those who don't can choose not to enable it.
- C2PasswordManager
-
91 posts
2-Factor Authentication
turkey3, I love the idea. Its just I hope if this becomes real, It can support my Yubico Security Keys.
- ThisIsTemp1
-
1000+ posts
2-Factor Authentication
I don't think anyone's Scratch account is gonna get hacked anytime soon (or ever), and what are the chances of that?yes I know this is from 2022
No support, I don't see why you would need it, and it would cause a lot of problems and the Scratch Team would be spammed with emails more and everything would be worse.
I think you misunderstood the suggestion. The Scratch Team is not going to get spammed with emails. And many Scratch accounts have been hacked, because a lot of passwords here are weak.