• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Two Factor Authentication

I'm sorry, but if you make two-factor authentication mandatory, you will lose me. Two-factor authentication is a freakin' pain in the arse, and since I know I'm cautious enough to protect myself as much as is necessary already, it's an additional (and onerous) additional level of protection I don't want and don't think I need. Two-factor authentication should be an option, not a mandate.

I suspect those members that have been harmed wouldn't have been spared by two-factor authentication.
 
Last edited:
TB has no way of knowing if a user is re-using the same login credentials for other online identities. Like say banking, Amazon, or whatever you can name. If TB is hacked and your credentials are stolen and used somewhere else and you are financially impacted or your identity is stolen, you could blame TB for having lax security. Entities *far* larger than TB get hacked every day. I guaranty you a significant percentage of TB users are sloppy about online security because hey who wants to keep track of 100 different passwords. I have over 100 online accounts.

Seems like a legal liability issue to me.

Better security is, well, always better for everyone, even with the minor inconvenience that comes with it.
 
Last edited:
  • Like
Reactions: PhillipHolbrook
Phooey! Back in the old days all we had was a secret knock! It wasn't creative and everyone knew it because it was shave and a haircut which was the national anthem at the time but that's the way it was and we liked it!

im-a-grumpy-old-man-grumpy.gif


It doesn't bother me. I deal with certain websites on a regular basis that require a code. I feel better about it since I've had accounts hacked before. The only thing I'd prefer is if I could get a text VS having to open an app. Having to hunt for an app just to login is annoying, especially since this app is from google but doesn't have Google in the name. I have to remember what it's called. But for the time I'll just use email since Paul clarified that it's just as safe.
 
  • Like
Reactions: DigMe
I use a different app for the code and it works fine. It doesn’t need an internet connection. I’m glad it works because a google app or a code in email isn’t super secure either. It does shift liability, which is good for TB.

all I ask is to allow us to continue to use a variety of authentication apps. Trusting our information to a company who makes money selling it is a little silly imho.
 
TB has no way of knowing if a user is re-using the same login credentials for other online identities. Like say banking, Amazon, or whatever you can name. If TB is hacked and your credentials are stolen and used somewhere else and you are financially impacted or your identity is stolen, you could blame TB for having lax security. Entities *far* larger than TB get hacked every day. I guaranty you a significant percentage of TB users are sloppy about online security because hey who wants to keep track of 100 different passwords. I have over 100 online accounts.

Seems like a legal liability issue to me.

Better security is, well, always better for everyone, even with the minor inconvenience that comes with it.

Not if you use a different password for every account.

In that case if TB got hacked, the only thing the hacker would have stolen that is of any value would be your email address.

Don't get me started on how bad using an email for your userID is.....
 
  • Like
Reactions: KohanMike
I'm sorry, but if you make two-factor authentication mandatory, you will lose me.
That's your choice

I suspect those members that have been harmed wouldn't have been spared by two-factor authentication.

Supporting and gold supporting members should be exempted from two-factor, if that is possible.

Actually, much of the scam attempts that happen are because old dormant accounts are hacked, the scammers purchase a monthly supporting membership, then post scam classified ads.
 
  • Like
Reactions: Andre678
Yes. Obviously one code a month is easier that a text every time you want to use the site. @paul please let us know if the email is OK, or if it is recommended to use text.
Mods have been using 2FA with an email code for a couple years now. It works fine.
 
I suspect it’s the thinking that “it’s only a bass forum” that has caused so many here to reuse passwords. Do you know how much time the staff here spends playing wack a mole with scammers? It looks like about 14 accounts were broken into TODAY. We have to be fast in banning them before they post classifieds. Some even buy a supporting membership to rip us off. IMO it’s a small price to pay to enter a 6 digit code once every 30 days.

One way to address this would be to enforce passwd complexity and, maybe, the changing of passwds every 90 days or so.
 
I suspect it’s the thinking that “it’s only a bass forum” that has caused so many here to reuse passwords. Do you know how much time the staff here spends playing wack a mole with scammers? It looks like about 14 accounts were broken into TODAY. We have to be fast in banning them before they post classifieds. Some even buy a supporting membership to rip us off. IMO it’s a small price to pay to enter a 6 digit code once every 30 days.

Wouldn’t that per device every 30 days?

I use many different devices depending on my location.