• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Two Factor Authentication

I'm sorry, but if you make two-factor authentication mandatory, you will lose me. Two-factor authentication is a freakin' pain in the arse, and since I know I'm cautious enough to protect myself as much as is necessary already, it's an additional (and onerous) additional level of protection I don't want and don't think I need. Two-factor authentication should be an option, not a mandate.

I suspect those members that have been harmed wouldn't have been spared by two-factor authentication.
 
Last edited:
People complaining about taking preventive steps remind me of when I was in tech support:
Customer: “My hard drive died.”
Tech Support: “After you get a new drive, you can restore from a backup.”
C: “I don’t have a backup. What am I going to do?”
TS: “So when did your data become important to you?” (Said in an empathetic way.)
 
Last edited:
  • Like
Reactions: PhillipHolbrook
We decided to hold off on requiring 2FA. There are too many people hitting errors when trying to use 2FA apps. I have some other methods that will hopefully slow the scammers for now.

So while it's not required, I would definitely suggest using 2FA if you can. Or at least use a password on TB that you use nowhere else :)
 
We decided to hold off on requiring 2FA. There are too many people hitting errors when trying to use 2FA apps. I have some other methods that will hopefully slow the scammers for now.

So while it's not required, I would definitely suggest using 2FA if you can. Or at least use a password on TB that you use nowhere else :)

@Mr_McBride you dont have to leave…
 
But if you wanna leave, take good care
Hope you make a lot of nice friends out there
But just remember there's a lot of bad and beware
Earworm......................
Nonplussed.gif

It's OK.I've had worse.
 
  • Like
Reactions: 5StringBlues
Password complexity and rotation were once considered good ideas, but we're beyond that now as the methods and tools used by hackers have become more sophisticated.
This isn't about someone sitting at a keyboard guessing your password anymore. Unfortunately a large number of folks practice poor 'cyber hygiene' in regard to password management. Thus we end up with compromised accounts and such.
Staying ahead of the hackers, and cleaning up after the ones who get in, is a full time job. The technologies to secure our data are always changing in an effort to stay ahead. As it evolves, it will impact all of us as end users.

-Mike
 
I suspect it’s the thinking that “it’s only a bass forum” that has caused so many here to reuse passwords. Do you know how much time the staff here spends playing wack a mole with scammers? It looks like about 14 accounts were broken into TODAY. We have to be fast in banning them before they post classifieds. Some even buy a supporting membership to rip us off. IMO it’s a small price to pay to enter a 6 digit code once every 30 days.

in 1996, i used to reuse one password for our business accounts. someone - and we'll never know who - who worked for or with one of our sponsors logged into another of our sponsors and changed our name and address, not to streal our money - just to do mischief. the sponsor sent out our check, and let us know when it returned to sender, no such address. luckily they called, as the email had also been changed to a nonsense account.

i must admit that i'm not a fan of mandatory 2fa, but if it's only once a month, i can live with it. hopefully it will make the mods' lives easier. i hope we don't lose too many posters, and i expect we're likely to lose new potential members behind this. i do wish for the best possible result.
 
I'm very diligent about my passwords, never reuse the same one. I also go so far as to use a different email address for each of the services for which I have to register, over 200 now (I pay for an internet service that has unlimited email addresses, storage and bandwidth). I'd rather not have to deal with two factor, but 'ya can't fight city hall' so I'll have to live with once a month.
 
2FA is really not that big a pain in the arse. If that's what ruins your day, your life is pretty damn stress-free.

I have to use 2FA every day for work, multiple times a day due to access time-outs. It's really not a pain point.

I have to open a door every time I use the restroom, and then I have to close it when I'm done! Goddamn the injustice of it all.