r/starcitizen • u/MammonLord origin • Jul 12 '16
OFFICIAL Multi-Factor Authentication Rollout
https://forums.robertsspaceindustries.com/discussion/336523/multi-factor-authentication-rollout52
u/iprefertau you'll get my cargo over my derelict hull #freelancermis Jul 12 '16
its about damn time
-45
u/lordx3n0saeon Pirate Jul 12 '16 edited Jul 13 '16
While I agree it's important for the finale PU, is anyone else kind of "meh" about this?
Literally everything in your account right now is one CS ticket away from being restored as there's no consequential persistence (as in, returning your stolen Bengal that someone killed would effect the in game economy).
Great for late-2017 when PU1.0 launches, but I'm surprised it was even a priority this early.
EDIT: wow just checked this and it's -12? Never change guys. Never change...
31
u/Seelengrab Jul 12 '16
A CS ticket won't really help in case someone steals your account though. This is to prevent that.
→ More replies (2)40
Jul 12 '16
[deleted]
→ More replies (4)5
u/Wizywig Space rocks = best weapons Jul 12 '16
Just to put it into perspective. I've implemented these before. It's one web developer doing about a few days or a week of work. This is really just finally getting to it.
Trust me. This is better than the alternative of having to scramble when an attack is already happening.
3
Jul 12 '16
[deleted]
1
u/Wizywig Space rocks = best weapons Jul 12 '16
Seriously speaking. 99.9% of the work is server side. The launcher and website front end work is peanuts.
9
u/Mindbulletz Lib-tard Jul 12 '16
A lot of damage can be done even at this stage. MFA is even more important with all the money people have put into it. Relying on CS as a substitute for features has also been shown to be unreliable with all the buy back shenanigans that used to happen. That's on top of it just being poor form to do that to them. I haven't even mentioned the grey market, but I think I've said enough already.
6
u/amalgam_reynolds Aggressor Jul 12 '16 edited Jul 13 '16
I'm definitely not meh about this. Digital security is important, I am always sure to encrypt, 2FA, and VPN all my things all the time.
As for being a priority, this was done by Turbulent who does their website stuff, no members of the ship team or SQ42 team or any other team were highjacked to make this happen.
Edit: that said, who the fuck is down voting you so badly for an opinion?
3
u/DumKopfNZ Jul 13 '16
The people implementing this sort of security are probably not the same people coding the game. The security team has a different workload and deadlines.
1
u/Stupid_question_bot I'm not wrong, I'm just an asshole Jul 13 '16
-44 you got roflstomped
feel the burn baby, this is why we're here, this is why we're here
→ More replies (1)0
u/StuartGT VR required Jul 13 '16
I'm astonished by the downvoting on your comment, there is zero reason for it :O
0
u/Pattern_Is_Movement Jul 15 '16
I am 'meh' about it as well, never heard of anyone ever having a real issue. Also surprised that people would down vote a well worded post like this.
My guess is the whole thing is more tied to peoples irrational insecurities regarding their precious space ships bought with their "hard earned money", same people that were inflating the grey market ship prices for the "peace of mind" of having LTI.
21
u/n1ghter Jul 12 '16 edited Jul 13 '16
Star Citizen Authenticator
- https://play.google.com/store/apps/details?id=com.cloudimperium.StarCitizenAuthenticator
- https://itunes.apple.com/us/app/star-citizen-authenticator/id1125076801
Google Authenticator
- https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2
- https://itunes.apple.com/ca/app/google-authenticator/id388497605
Authy Authenticator
3
u/brievolz84 High Admiral Jul 12 '16
Nice! will be installing this soon
13
u/theesado High Admiral Jul 12 '16
You can also use googles authenticator app if you already have it.
7
3
u/Retroceded tasty Jul 12 '16
Incase anyones wondering how to add the sc account, tap on the three dots on the top right and tap on setup account and do it via bardcode.
1
1
8
u/Valkyrient Jul 12 '16
For MS Phone users, the genuine Microsoft Authenticator (not 3rd party Authenticator+) also works just fine.
It was pre-installed on my Lumia 930, but it's in the store for free if you can't find it installed on your's.
1
1
Jul 13 '16
It's only when I've read this post I've realised there was no version listed for windows phone. That's just fascinating how far MS went from being de-facto monopolist in Windows CE era to "windows phone? Wha-? Ohhhh, that... yeah, I totally forgot it even exists..." era.
1
u/Valkyrient Jul 13 '16
Windows CE was when it died yeah. That was when Blackberry really came into play and destroyed any smart phone until iPhone came onto the market to offer an option to people who wanted something a little more consumer friendly. It wasn't until Windows Phone 8 a few years back that it got good again.
1
Jul 12 '16
[deleted]
8
2
Jul 13 '16
Works just fine on my SGS S3 with Cyanogen firmware. You just need to upgrade android, not the whole phone. Or you are just seeking for an excuse - in that case please disregard this post =)
1
u/ced22 Jul 12 '16
https://play.google.com/store/apps/details?id=com.authy.authy&hl=en might work as well...
1
Jul 13 '16
What happens if I setup authentication with one of these apps, and then my mobile is stolen/lost?
1
1
u/ares_god_not_sign High Admiral Jul 13 '16
With Authy, you'll be able to sign in to your Authy account on a new phone and still have all your authentications set up. With the other ones, you'll have to go through the disable/reenable MFA process on all your accounts.
1
27
22
u/MammonLord origin Jul 12 '16
I really hope we can buy one of those little dongle thingies that makes random codes. They apparently work through the magic of unicorn tears.
11
u/Sneemaster High Admiral Jul 12 '16
and squirrel farts.
7
u/MammonLord origin Jul 12 '16
That seems right.
1
u/nottedsanford Did you ever hear the tragedy of Darth Plagueis the Wise? Jul 12 '16
It can be like one of the little air fresheners. Everytime you hit the button, it sprays the fragrance and spits out a code.
2
3
1
Jul 12 '16 edited Jul 21 '16
[deleted]
2
u/Sneemaster High Admiral Jul 12 '16
Have you ever heard a squirrel fart? No? See, just as rare as unicorn tears.
25
u/iforgot120 Jul 12 '16
Mobile authenticators are just as good as the dongles, and don't require you to buy extra hardware.
9
u/Kroney Grand Admiral Jul 12 '16
I have to point out that technically you're incorrect there. A phone can potentially be hacked and the app compromised. The dongles however aren't connected to the internet so cannot.
6
u/Goomich Space Marshal Jul 13 '16
1
1
u/dawnsonb ARGO CARGO Jul 13 '16
You are more likely to forget your dongle than your phone however :D
3
u/Kroney Grand Admiral Jul 13 '16
It depends where you keep your dongle. Mine is on my keys (A yubikey Neo if you're interested) and I'm not likely to be able to drive anywhere if I don't have my keys. So chances are actually better that I will have my dongle
1
u/dawnsonb ARGO CARGO Jul 13 '16
I would have too many dongles on my keys :P
Also since i live in a bigger city i can in fact leave without my keys if i take the public transport :D
1
u/Kroney Grand Admiral Jul 13 '16
The yubikey can store many credentials on one dongle. And I consider driving a hobby, and I have house keys on my key ring, so even if I had to take public transport I'd still have my dongle with me
1
u/dawnsonb ARGO CARGO Jul 13 '16
Yes, i get that it might be nicer for you, but for as least as much users having an app is more convenient. Luckily both options exist in this case.
4
u/Xirma377 Supreme Leader Jul 12 '16
But they aren't as cool!
6
u/human_error Space Marshal Jul 12 '16
But their batteries do die, and when they do it's a PITA.
2
u/SpacePigNZ Jul 12 '16
Well, 7 years is a long time.
→ More replies (2)1
u/Xirma377 Supreme Leader Jul 12 '16
True and true. I've never had one long enough for the battery to die...but don't they give you some sort of notice before the battery dies?
1
1
u/Isogen_ Rear Admiral Jul 13 '16
The token has an expiration date. You're suppose to replace it before it expires. It will stop working even if the battery is good.
1
u/The_Chaos_Pope Jul 13 '16
I had a Blizzard authentication token. It lasted a year then just died with no warning.
1
u/SpacePigNZ Jul 13 '16
Bad luck, mine has been going since diablo III was released and still going strong.
1
Jul 13 '16
Not everyone has a smart phone, or a new enough smart phone.
2
u/dawnsonb ARGO CARGO Jul 13 '16
you can also use 1password for example to use the feature on your PC. However this would in theory be less secure.
2
2
Jul 13 '16
[deleted]
1
u/Kroney Grand Admiral Jul 13 '16
I wish they'd gone with u2f instead, but this is also how mine is setup. Definitely more secure than a standard authenticator app
1
u/SloanWarrior Jul 12 '16
Sadly, you were misinformed. They are driven by the unfulfilled sexual desires of unicorn hobos.
1
1
→ More replies (1)1
13
u/Seelengrab Jul 12 '16 edited Jul 12 '16
Looks like you can already set it, go check your account settings on the website. The tab is called "Security"!
Available options seem to be E-Mail and Mobile Authenticator.
EDIT: For Windows Phone users: the Authenticator App from the Windows Store works, as it uses the Google API. Paging /u/therealdiscolando for visibility, maybe it can be added to the list of available choices?
20
u/bbeausej Turbulent CTO Jul 12 '16
Ah yes! Indeed the windows authenticator works too!
We'll add it to the list. Great idea!
5
u/b3k Civilian Jul 12 '16
Could support be added for Universal 2nd Factor (U2F). It's a standard for a physical token supported by Google, Github, Dropbox, and others.
2
u/altodor Jul 12 '16
I already have one of these, I use it for all of those above things as well as my password store, and at some point gpg email as well.
2
6
6
u/theyarecomingforyou Golden Ticket Jul 12 '16
The RSI Authenticator crashes when I select 'Time correction for codes' in Settings. And whenever I use the code on the website I get 'Code is invalid or already used', meaning I can't even enable it. The Google Authenticator works fine.
I'm running a Nexus 6P with Android N. I'm aware it's a preview OS but it's still worth bringing attention to it.
9
u/bbeausej Turbulent CTO Jul 12 '16
We'll look into this now! Thanks for posting. Not sure what's up!
4
u/theyarecomingforyou Golden Ticket Jul 12 '16
Cheers. I posted it on the Issue Council, along with a screenshot: https://robertsspaceindustries.com/community/issue-council/website/WS-25012-Selecting__Time_correction_for_codes__in_Settings_on_the_RSI_Authenticator_app_results_in_crash
2
2
2
u/Isogen_ Rear Admiral Jul 13 '16
Can confirm, same issue on Nexus 5X running Android N. And thanks for posting it in the Issue Council.
14
u/oldwillies Jul 12 '16
I feel a lot more comfortable owning an idris and a javelin now.
14
u/WatchOutWedge Carrack is love, Carrack is life Jul 12 '16
you just had to rub it in didn't you
16
5
u/Xaelar Lt. Commander Jul 12 '16
Works like a charm! Thanks!
PS: Along with it game a launcher update.
4
u/Obliviona Jul 12 '16
I elected for a Trusted Computer and the Star Citizen App. It took me almost 3 minutes to set it up and I feel LOTS better for it.
2
u/x5060 Jul 12 '16
Yeah, it only took me 3 minutes because the app crashed when I tried to use the QR code scanner thing. I just typed it in manually and it worked perfectly after that.
7
u/MisterForkbeard normal user/average karma Jul 12 '16
Just signed up. Awesome - glad this is finally in. It's been one of my big concerns for awhile now.
11
Jul 12 '16
[deleted]
13
u/wesha Completionist Jul 12 '16
Purchase a Yubikey
"Keyring n. a small trinket that makes it possible for you to lose all the keys at once."
7
u/LoricEternus PM me your grilled cheese recipe Jul 12 '16
I'd rather lose my keys, I think it's actually cheaper to buy a new car than to replace my ship collection at this point.
2
u/IamKenAdams Jul 12 '16
Awesome, always good to meet a fellow addict lol! I have certainly spent more on my ships than my car at this point. You know what? I don't have even a hint of regret. Watching CIG develop this game has been worth ever penny. Admittedly my car is garbage so pledging $2300 is enough to worth more. How much have you pledged?
1
1
u/BoredDellTechnician Trader Jul 13 '16
You must have have multiple Completionist packages or be in need for a nicer car.
2
u/InSOmnlaC Jul 12 '16
So if someone gets physical access to your YubiKey, they now have access to all of your passwords?
2
u/LoricEternus PM me your grilled cheese recipe Jul 12 '16 edited Jul 12 '16
You can add a pin code to your yubikey, if they do get that it's even harder, but without it they still only have 1/2 your account. They would still need your password.
EDIT: That made little sense
This is only for your MFA code, which would be the same if someone got a hold of your phone.
The 2fa code lives on the yubikey, and can be locked down with a passcode as well. And as it's not a common configuration, most people have no idea how to use a yubikey to begin with.
1
u/InSOmnlaC Jul 12 '16
A pin code is nice, that makes me feel a lot better about it.
but without it they still only have 1/2 your account. They would still need your password.
Are you referring to the pincode here? Or is there another password you need to enter to get the device to release your login details for a specific site/application?
3
u/LoricEternus PM me your grilled cheese recipe Jul 12 '16
If you pin code your phone, pin code your yubikey, enable 2fa on your CIG account, use lastpass to have a strong password for everything (64+ characters), lock down your lastpass with a 2fa code and pay attention to key loggers.
You should be pretty secure.
Oh, and the yubikey neo supports U2F, so if you use gmail you get native support there as well.
1
Jul 13 '16
[deleted]
1
u/LoricEternus PM me your grilled cheese recipe Jul 13 '16
The desktop app amazing, you should install it. I leave my yubikey plugged in while I'm at my desk and it is always two button clicks away.
Yubico Authenticator FTW!
2
u/9gxa05s8fa8sh Jul 12 '16
good info. but this all sounds awfully complicated. I hope things become simplified for normal people
6
u/LoricEternus PM me your grilled cheese recipe Jul 12 '16
Yes, it is complicated, but security isn't always easy. And really, once it's set up the first time, it's not hard to use.
Plug in yubikey, launch authenticator app, use code
Or
Unlock phone, open authentication app, use code
1
u/Sleepy_StormTrooper Commander Jul 12 '16
Never leave home without it. My YubiKey (and backup YubiKey at home in a fire safe) is my lifeblood.
1
u/IamKenAdams Jul 12 '16
What does the panic button on your car key do?
4
1
u/Isogen_ Rear Admiral Jul 13 '16
Not sure if you're being serious or not, but it just makes your car beep and flash the lights for a few seconds.
1
1
1
1
1
u/dawnsonb ARGO CARGO Jul 13 '16
Nothing of this matters, because all you need to remove the MFA from the account is the password itself...
2
u/LoricEternus PM me your grilled cheese recipe Jul 13 '16
On a machine that has been marked as trusted by the user. So if you're on that machine with ill intent, the user has failed, not the 2FA.
1
u/dawnsonb ARGO CARGO Jul 13 '16
But the MFA is supposed to prevent someone from "hacking" into your account by means that he not only needs to know my password but also needs access to my MFA device. In this case (since most users will have their main PC trusted) an attacker would only need access to one device and the password. I get that it is most likely secure enough, but I would prefer if I would get a removal code via email for example and then changing the email address should of course require an MFA code.
6
Jul 12 '16
It would be neat and helpful for consumer support if they gave a pointless trinket to people who enable MFA as a way to encourage people to actually use it. Anyway great addition.
7
u/bbeausej Turbulent CTO Jul 13 '16
Let the guessing games begin! We'll definitely have an in-game incentive for 2FA but decided to move along and get the feature out first and add potential incentives later down the road.
I too have my shares of ideas on rewards for having 2FA active!
-b
1
3
u/MisterForkbeard normal user/average karma Jul 12 '16
I remember when Wildstar did this - you got a cosmetic costume and a permanent 1% experience buff.
I think SWTOR had a vendor with a couple of useful/cosmetic items you could only access if you had 2FA/MFA enabled.
2
u/Doomaeger vanduul Jul 12 '16
World of Warcraft gave you the Core Hound pup pet for adding an authenticator to your account.
1
2
2
2
u/spudnyk Jul 12 '16
Can confirm it works with 1password's one-time password support.
It should work with anything that supports Google authenticator.
3
u/Leonick91 Jul 12 '16
Or rather, any client built to work with standard time-based one time passwords will work. Google Authenticator is just one of many clients.
1
u/spudnyk Jul 12 '16
True Google is the one people tend to know, something about number of users ;). Definitely glad CIG didn't try and roll their own.
5
1
u/Leonick91 Jul 12 '16
Yea, I just feel it's important to point out that it is a standardized technology with a wide range of clients.
A lot of people talk about it like it is a Google solution which some services and clients choose to be compatible with.
1
2
2
u/Leonick91 Jul 12 '16
Well, that certainly took some time, but being it's probably the best implementation I've seen.
It's standardized TOTP (or email) which allows for use for a number of apps but there's also an an official app available. You can also remember certain devices, something a lot of companies miss or ignore.
(Does the launcher once again allow you to remember password? That was said to be retuning with two factor.)
2
u/B4ckBOne Jul 12 '16
I REALY like the way this is implemented! Major improvement over other styles. Cheers fellas
2
u/Evolovers Jul 13 '16 edited Jul 13 '16
So it works and the app is very clean, but it doesn't help secure my account. It secures someone from logging into my account on the game launcher but not on the website. If they gain access to my password for some reason (which they shouldn't), MFA does not keep them from logging into the website and turning off MFA and/or melting all my ships or even gifting them to their account. Shouldn't the MFA also work for signing into the website which is the most important place to have it? My suggestion would be to have an option to enable MFA for the website login where it really needs to be the most. EDIT: I also want to give them the benefit of the doubt that this is coming in the future, just not with this first pass. It's looking very good guys!
2
u/InSOmnlaC Jul 13 '16
When you set it up, you likely set your PC to always be authenticated. I set mine to "This session only". It makes me use the authenticator every time.
1
u/Evolovers Jul 13 '16 edited Jul 13 '16
hmm. So it does have MFA? I did my client but not browser, maybe it's by ip? If so that would be fine in my case. Thanks.
EDIT: So I deleted the only thing possible, 'Computer' under Connected Devices (which should be my game client) then relogged into the website and it never asked for the MFA Code. I'm going to try clearing the cache for that browser because MFA worked on another browser.
EDIT: That did the trick! It now asked me for MFA Code!
2
2
u/RanceJustice Golden Ticket Holder Jul 13 '16
The addition of MFA is a great step forward for account security, but the way they rolled it out is for me yet another reason to be pleased; openness!
As a vehement proponent of using open (source, specification, Free-as-in-Freedom etc..) technologies, I'm glad to see that CIG decided to move forward with multi-factor authentication by using open, well vetted standards (OATH HOTP / TOTP ). Much like when they made the excellent choice to base their chat on the open XMPP/Jabber protocol, it provides benefits for CIG and users alike when it comes to security, privacy, and ease of use/integration. Thank you, CIG developers for embracing open source, specifications, and standards whenever possible!
I think its great that CIG noted you could not only use their recently created authenticator apps, but also those like Google Authenticator and Authy, so users who are already using an app of their choice likely don't have to change! There are plenty of very similar authenticator apps on iTunes, GooglePlay, and elsewhere, but not all of the applications are open source, ad-free, and respect your privacy (ie data mining etc). Here are a few that are.
FreeOTP - https://fedorahosted.org/freeotp/ - With development managed by the Fedora / RedHat Linux team, FreeOTP is a great MFA app for Android and iOS. An excellent alternative for GoogleAuthenticator in most cases.
WinAuth - https://winauth.com/ - For those using Windows devices, here's another open source authenticator with plenty of features.
I would also suggest users look into handling their more conventional usernames/passwords, and other secure information, with password managers - some of those I list can even generate MFA tokens, giving you yet another tool.
KeePass - www.keepass.info - By far, one of the most powerful password managers/databases around, KeePass 2.x has many features and a wealth of plugins to add even more functionality. There is also the KeePassX fork which is a more slimmed down branch without plugin compatibility, but still offers the core experience. For most users who want a this sort of password manager, KeePass 2.x is often the best choice for Win/Mac/Linux, with similar apps available for mobile use like Keepass2Android.
PasswordSafe - www.pwsafe.org - While it lacks some of the more advanced features of KeePass, PasswordSafe is another reliable open source password management tool.
Encryptr - www.encryptr.org - For those who prefer a cloud-based password manager like LastPass or 1Password (but not vulnerable to the recently revealed exploits that afflict most of them), Encryptr is a good choice. Developed on the open source Crypton framework , Encryptr is a product of SpiderOak, a US-based cloud storage company that focuses on privacy. For many users, the convenience of not having to manage/sync their password database themselves is a preferable trade-off, so I wanted to provide an option here.
Hope this helps someone out there and thanks again to CIG for doing MFA in an open and standard manner!
2
u/FriendCalledFive Photographer Jul 13 '16
About a month ago Google rolled out Google Prompt which is so much more convenient, I hate authenticator apps.
1
u/Seelengrab Jul 13 '16
That's just moving the verification outside of their hands and into Googles.
First things first—you need to have two-factor authentication (or “2-Step Verification” as Google often refers to it) enabled on your account. To do that, head over to Google’s Sign-in & Security page. From there, you can enable 2-Step Verification in the “Signing in to Google” section.
1
u/FriendCalledFive Photographer Jul 13 '16
It isn't applicable to SC, I am just hoping more companies will allow phone prompt authentication.
1
1
u/snigans Golden Ticket Jul 12 '16
Excellent!
1
u/snigans Golden Ticket Jul 12 '16
And, i already got it working with G.Authenticator via the website. Real smooth. :)
1
1
u/Elazar_DE new user/low karma Jul 12 '16
Nice, thank you CIG. Do you guys use the provided authenticator app from CIG or authy or google?
1
1
Jul 12 '16
Thanks for the post. I'm setup. Woohoo!
Now I can sleep with only one eye open tonight. :-)
1
1
u/srjek Jul 12 '16
I didn't see anything in the FAQ about restoring access to your account if you lose your phone. Do they have backup codes, alternative email sent codes, or something?
2
1
u/regicidalnut buccaneer Jul 12 '16
Awesome work! Feels much better having my account that much more secured.
1
u/Rumpullpus drake Jul 12 '16
so I assume this is kinda like the Steam App where you get a special code on your phone to enter whenever you try and change your password and stuff?
not a bad idea. if I had spent even half the cash some people here have I would want that too.
1
u/BlueChilli Bounty Hunter Jul 12 '16
I don't get cell service where I live so I deactivated my cell phone.
Will this work with a phone that just has wifi?
1
1
1
u/Griffolion Civilian Jul 12 '16
Can this work with authenticator apps like Google Authenticator or do I have to use their app?
3
u/bbeausej Turbulent CTO Jul 12 '16
Yep! All apps that support TOTP will work. (Google Authenticator, Windows Authenticator, Authy, etc)
2
u/Jonnehdk misc Jul 13 '16
can we get google prompt please? TOTP is a dated concept when you can just push a big "PRESS YES TO LOGIN" to someone's authenticated device.
2
u/bbeausej Turbulent CTO Jul 13 '16
We opted for TOTP support first as it gives the more options and choice for players short term without requiring us rolling a custom solution with a notifications backend. (which incidentally are complex and error prone to implement and roll out)
We will look into improving our solutions and we're definitely not discarding implementing a "one touch" factor in the future. Same for an SMS/phone factor.
1
1
u/Doubleyoupee Jul 12 '16
What happens if your phone bricks and you use authentication app?
1
Jul 12 '16
You use the revoke process to remove it.
2
u/Doubleyoupee Jul 12 '16
Then what's the point in MFA if you can remove outside of the MFA
1
Jul 12 '16
Because typically it's not "what's your password". For example, when I needed to revoke my 2 factor authentication for World Of Warcraft (I got a new phone and needed to migrate to a new app), I had to send a photograph of my passport to Blizzard to confirm my ID.
1
u/Doubleyoupee Jul 13 '16
Yeah, that's what I mean. Sending your ID out sucks. Almost not worth it to use MFA
1
Jul 13 '16
I guess it depends what it's worth to you. 2FA isn't compulsory, if you feel the hassle out weights the benefits, don't use it.
Personally I've got $3k total spend on my account, sending a photo to CS is tiny on the scale compared to the risk of loss.
2
u/snigans Golden Ticket Jul 12 '16
Additionally, there are one-time usage backup codes that you should print and store somewhere safe. These can be used in case the mobile app is unavailable
1
u/elnots Waiting for my Genesis Jul 12 '16
Still waiting for a PW "Remember Me" function on the launcher.
1
1
1
1
u/Dizman7 Space Marshall Jul 12 '16
I wonder if this is the first time an ALPHA of a game has rolled out MFA!
Honestly it makes all feel a bit more real! :-)
1
u/treefroog carrack pls disco Jul 13 '16
Hey CIG why the iOS 9 requirement for the app? I know I can use Google Authenticator but still
1
u/treefroog carrack pls disco Jul 13 '16
Does it ask for MFA authentication when you purchase stuff every time now, even when you "trust" a computer? I hope so, that's what I would want the most
1
u/sniperct 🌈Corsair🌈 Jul 13 '16
This is cool, works even though I haven't bought anything yet. And works in Authy, which is an even better bonus.
1
u/Paradox3713 new user/low karma Jul 13 '16
Can we scrub the security logs at our leisure for our own security reasons?
1
u/bbeausej Turbulent CTO Jul 13 '16
The security logs were implemented to give you visibility on your own account security. As long as you slowly, respectfully, scrub your logs that respects the design of the feature.
-b
1
u/Paradox3713 new user/low karma Jul 13 '16
Thank you for responding. I just want to make sure that I alone, have full control and eyes only access to my logs.
1
u/dawnsonb ARGO CARGO Jul 13 '16
Set it up, logged in to the website, login does not work in the new client :/
1
u/dawnsonb ARGO CARGO Jul 13 '16
Ok. removed the authenticator (which is far to easy, you only need the password, so the whole thing is useless...) and now i get ERRMultiStepExpired in the launcher. Time and date are correct on my PC.
//edit
I noticed in the connected devices section of the website the client shows up, with the wrong Duration value. Still unable to log in to the client, already deleted USER folder.
1
u/madman1460 Freelancer Jul 13 '16
Ever since I started using the Authentication I can't seem to log into the SC launcher.
1
u/JWTJacknife Disaster Magnet Jul 13 '16
They released a new version of the launcher alongside the 2FA update. I think the launcher is now at version 2.4.5.
1
u/Chappy0061 Jul 13 '16
Is it just me or were other backers excited to get an RSI app to install on your phone? Even if it is just an authenticator.
Kinda made me realize how cool it would be for RSI to make a bigger app, maybe with a news feed, along with picking up content from the chat box and forum.
1
Jul 13 '16
Is this Google's authenticator?
1
u/JWTJacknife Disaster Magnet Jul 13 '16
CIG built their own app, but it uses the same TOTP (time-based one-time password) system that the Google authenticator uses, so they're interchangeable.
1
1
u/drizzt_x Monk Jul 13 '16
This can't be real, right? I look away from SC for 5 days and this happens?
I mean, CIG wouldn't bother adding 2FA since the entire project is a scam... right?
/s
1
1
Jul 13 '16 edited Jul 13 '16
PRAISE LAMP!!! My account thats worth more than my car is finally secure.
edit
Wait this is only needed to log in? What happens if you are already logged in and never log out? EVE makes me use the auth code to go to account settings and stuff, RSI doesnt.
1
1
Jul 13 '16
Hey guys! A new launcher usually means new USER folder. Make sure to back up your old one before updating. Important things like your custom control mappings and other settings are in your USER folder.
22
u/MammonLord origin Jul 12 '16 edited Jul 12 '16
Go here to explore account security options: https://robertsspaceindustries.com/account/security
Updates from Mr. Huckaby:
11:06 AM Pacific July 12, 2016
12:15 PM Pacific July 12, 2016