Forum Settings
Forums
New
Oct 30, 2017 6:54 PM
#1

Offline
Jun 2013
3
I wonder if it is possible for the site to implement two-factor authentication? Just a thought since the brute force attacks.


Mod Edit: Modified title for clarity and/or easier searching.
TenshoOct 9, 2020 10:21 PM
Pages (2) [1] 2 »
Mar 18, 2018 8:52 PM
#2

Offline
Jun 2014
250823
Allow us to have two factor authentication on the website. This can be implemented in the form of standard OTP or maybe some login verification on the mobile mal app. This would in turn help stop accounts getting hijacked.
Mar 19, 2018 5:46 AM
#3

Offline
Oct 2015
4124
I mean this site doesn't really need that imo, it's not like steam where you can have stuff you paid for hijacked. I don't think people would want to 'hack' accounts which only contains a list lol.

If there's a reasonable need for this, name it. As if the long ass password isn't enough
Mar 19, 2018 10:55 AM
#4
Offline
Oct 2017
1838
EGOIST said:
I mean this site doesn't really need that imo, it's not like steam where you can have stuff you paid for hijacked. I don't think people would want to 'hack' accounts which only contains a list lol.

If there's a reasonable need for this, name it. As if the long ass password isn't enough

OP is just paranoid his parents will see his hentai ratings and disagree with the shoujo ramune rating
Mar 19, 2018 11:20 AM
#5
Offline
Jul 2018
564612
EGOIST said:
I mean this site doesn't really need that imo, it's not like steam where you can have stuff you paid for hijacked. I don't think people would want to 'hack' accounts which only contains a list lol.

If there's a reasonable need for this, name it. As if the long ass password isn't enough


@KimJong-Un I agree with you. I don't think the users above are taking this seriously enough...

There's plenty of people who could and possibly will take control of accounts and just use them for trolling purposes. I use multiple online forums for various things and I can personally say that this kind of stuff does happen—even if there is no clear benefit for the "hacker".

Anyways, someone could gain access to another person's account and use it for malicious activity or trolling in general, such as purposely breaking rules are using the account as part of a spambot/raid. No one in their right mind would just take control of an account for their lists. There are also many users who have personal information saved on the MAL account, and therefore that is also at risk.

But probably the strongest argument for a 2FA is the security of accounts with credit card information saved. With the rise in MAL Supporters and the recent release of the Manga Store, I'm confident that hundreds of people have at least some of their card information saved on their account. If an account with card information is hacked, then it's going to be a problem for the user and will eventually be a problem for MAL. It's better to act before such things happen than waiting for them to happen.
removed-userMar 19, 2018 11:23 AM
May 15, 2018 3:08 PM
#6

Offline
May 2016
276
I agree with you @TentacleMaster and @changelog_ I believe that there needs to be a 2FA on this service for the same reason y Facebook has 2FA. This is a social media site and it would be much welcome. And now with credit card implication (even if it is not logged) that makes me want it even more. It could be very easy as well with Google's very own 2FA thing. Because rn I don't want to put my credit card on here because it doesn't have 2FA.
May 15, 2018 11:15 PM
#7

Offline
May 2016
276
EGOIST said:
I mean this site doesn't really need that imo, it's not like steam where you can have stuff you paid for hijacked. I don't think people would want to 'hack' accounts which only contains a list lol.

If there's a reasonable need for this, name it. As if the long ass password isn't enough

I get your point but this is a social media site. There is a reason y Facebook, Twitter, Discord, and Instagram have 2FA support. I would say a simple implication of Google 2FA would be great.
May 16, 2018 4:05 PM
#8
Offline
May 2018
1
I fully support this. This idea is a nice one and there isn't much wrong with it and it comes with more pros than cons so it's all good.
May 16, 2018 4:10 PM
#9

Offline
Jun 2014
250823
The only issue I could see if you forget your 2FA code but that could be solved wth backup codes.
May 16, 2018 4:15 PM

Offline
May 2016
276
true but Google Authenticator just generates codes after a certain amount of time so u just need to check it when u need to log in
May 16, 2018 6:06 PM

Offline
Jun 2014
250823
C01IN01-BakaVaca said:
true but Google Authenticator just generates codes after a certain amount of time so u just need to check it when u need to log in
Yep my bad would need to clarify, so if you lose the device with the authenticator there has to be a way to retrieve it and I suggested backup codes and a backup code you can save to authenticate if necessary. Or depending on security could restore by email but usually all sites that implement 2FA properly do not allow you to reset by email when you have 2FA active which is intended.
Sep 5, 2018 3:09 PM

Offline
May 2016
276
Yeah just like what Discord does, just make sure you have a folder for all the txt documents with the backup codes and zip it up and put a password on it. (I believe anyone who sets up 2FA should always have a fail safe
Sep 5, 2018 7:21 PM

Offline
Sep 2018
111
2FA should be everywhere as an optional plugin.
Sep 5, 2018 8:13 PM

Offline
Jun 2016
2632
HELL NO!

If this site wants me to verify my email every goddamn time just like discord I'll leave for AniList. This is an anime forum not a bank.
Sep 6, 2018 7:48 AM

Offline
May 2016
276
Lost_Viking said:
HELL NO!

If this site wants me to verify my email every goddamn time just like discord I'll leave for AniList. This is an anime forum not a bank.

no no no not like that XD. It should be optional XD
Nov 9, 2019 5:17 AM

Offline
Dec 2014
15
yuwib said:
I hope this gets implemented

+1

I agree, we should at least have the option to activate the 2FA, just like the other sites.
Nov 9, 2019 8:42 PM

Offline
Feb 2017
298
Mandatory, no.
Optional, yes.

I would probably use it but I would like the option of not having to and it seems pointless to make it mandatory now considering it's not a new site. It would help some users if the site ever has a massive breach or force logout of everyone (again).





Just some guy who likes anime

Feb 4, 2020 11:41 PM
Offline
Sep 2012
3
plain and simple, i think this site should have 2FA incase anyone is going around trying to hack accounts. they would have to put in that "extra effort" if they really wanted to get into someone's account and adds a little more peace of mind for the users. Also, would like a little more to have 2FA through an app rather than email/number if possible
MapuDofuFeb 5, 2020 12:35 AM
Feb 4, 2020 11:42 PM

Offline
Jul 2012
48248
i support this.
Feb 6, 2020 11:10 PM

Offline
Jun 2016
733
Didn't even realize MAL didn't have an option for 2fa til I saw this thread. How does a site this large not have 2fa?

I also second this suggestion but I am quite certain it won't be added, much like every suggestion in suggestions.
Feb 6, 2020 11:33 PM

Offline
Nov 2016
1916
We need this very soon.
Signature removed. Please follow the signature rules, as defined in the Site & Forum Guidelines.
Feb 6, 2020 11:53 PM

Offline
Jan 2017
250
An Authy based 2FA system sounds neat.
Feb 7, 2020 12:05 AM

Offline
Feb 2015
102
Agreed 100%, this needs to be done.
A true man never dies.
Feb 7, 2020 2:09 AM
Offline
Feb 2015
568
So true, that would be a lot better!!
Feb 9, 2020 10:36 PM

Offline
Apr 2019
62
yes, we need this. there should always be more ways to secure your accounts
Feb 9, 2020 10:40 PM

Offline
Jan 2016
1
this should be be there. while you are at it, make sure you arent still using MD5 hashes for passwords (without salts) or even worse plaintext!
Feb 9, 2020 11:56 PM

Offline
Jan 2020
99
I'm in support of this.



"No letter that could be sent deserves to go undelivered." - Violet Evergarden
signature and forum avatar made by Memor!
Feb 10, 2020 9:05 AM

Offline
Oct 2017
2700
I sign this. We should've such system in place already.
''Enemies' gifts are no gifts and do no good.''
Feb 10, 2020 6:56 PM

Offline
Jun 2016
10245
Highly requesting this be added - its 2020...
Feb 12, 2020 7:46 AM

Offline
Jan 2009
92531
if not the users then the moderators and staff really need this
Feb 24, 2020 12:17 PM
Offline
Sep 2012
3
bumping this to get more attention and everyone that replied so far has been in support of it
Feb 24, 2020 5:49 PM
Offline
Jul 2018
564612
I'll pitch in my support for it as well.
Feb 24, 2020 5:57 PM
Offline
Jul 2018
564612
what's there to secure? if someone hacked into my account it would benefit them in no way lol
Mar 21, 2020 7:49 AM

Offline
Jul 2014
4195
the only thing the hackers would gain would be degenerate taste in hentai :dolanpls:

seriously 2fa for an anime tracking website? lmao
Mar 21, 2020 8:59 AM

Offline
Jul 2015
1857
All I have are cringy forum posts and a list I can just transfer over within a minute so why bother? It's not like there's anything actually important tied to these accounts you can't recover in less than an hour.
Mar 21, 2020 8:12 PM

Offline
Oct 2012
15987
Fuck 2FA besides for staff.
  1. Your anime list just isn't that important.
  2. No one gains anything from hacking your MAL.
  3. You only get "hacked" if you click on fake HTML elements. Which means if MAL still has this problem, it needs to take care of cross-site scripting and SQL injections before it even starts to worry about 2FA.
  4. I don't want to go through my phone every time I click +1 on my list.
  5. If you click on something stupid and it grabs your session cookies, then the only thing that's going to save you is to have cookie expirations, not 2FA.
  6. I don't want to have to keep logging in every 30 minutes.

Maybe enable it for people who want it.
My subjective reviews: katsureview.wordpress.com
THE CHAT CLUB.
Mar 22, 2020 7:37 AM

Offline
Jul 2015
1857
katsucats said:
Fuck 2FA besides for staff.
  1. Your anime list just isn't that important.
  2. No one gains anything from hacking your MAL.
  3. You only get "hacked" if you click on fake HTML elements. Which means if MAL still has this problem, it needs to take care of cross-site scripting and SQL injections before it even starts to worry about 2FA.
  4. I don't want to go through my phone every time I click +1 on my list.
  5. If you click on something stupid and it grabs your session cookies, then the only thing that's going to save you is to have cookie expirations, not 2FA.
  6. I don't want to have to keep logging in every 30 minutes.

Maybe enable it for people who want it.


If I require a phone to log in, I'm finding a new site. Straight up.
Mar 22, 2020 11:50 AM
ᕙ(⇀‸↼‶)ᕗ

Offline
Aug 2014
4279
katsucats said:
Fuck 2FA besides for staff.
  1. Your anime list just isn't that important.
  2. No one gains anything from hacking your MAL.
  3. You only get "hacked" if you click on fake HTML elements. Which means if MAL still has this problem, it needs to take care of cross-site scripting and SQL injections before it even starts to worry about 2FA.
  4. I don't want to go through my phone every time I click +1 on my list.
  5. If you click on something stupid and it grabs your session cookies, then the only thing that's going to save you is to have cookie expirations, not 2FA.
  6. I don't want to have to keep logging in every 30 minutes.

Maybe enable it for people who want it.

I agree that it should be implemented for staff and optional for anyone else who wants it (but never required or "strongly encouraged" with obtrusive popups).
Apr 8, 2020 10:54 PM
先輩

Offline
Apr 2016
172
yeah i agree, it needs one. this is one of my few profiles online that i dont want anything to happen to.
Apr 10, 2020 1:00 AM

Offline
Sep 2015
1082
I don't mind if its optional and through an app like freeOTP. If it's mandatory and uses SMS or proprietary authorization tool like Google Authenticator, then fuck it.

I also don't think my anime list is important enough to be necessary to have 2fa.
Jul 8, 2020 7:22 AM
Offline
Apr 2020
4
I support this topic because cybersecurity is one of the most important areas in our time. Besides I don't want to lose my titles) If the administration wishes, they can easily enter this function by connecting OTP tokens with 2FA service or using Google Authenticator. The fact is that it is also important not only the application that generates passwords, but also the server that checks them. For example, an adequate 2fa platform will offer various security options, including TOPT tokens, IP verification, or data monitoring. Unfortunately, going out of all this information, connecting this service will cost money, so most likely some payment options will be enabled for this authorization method. Many financial companies or blockchain resources have been using it for a long time, which is explained by the importance of stored information. I would love to pay a small price, but I don't want people to fall into stupid categories.
Jul 9, 2020 12:16 PM

Offline
Nov 2008
998
Heldengeist said:
I don't mind if its optional and through an app like freeOTP. If it's mandatory and uses SMS or proprietary authorization tool like Google Authenticator, then fuck it.

I also don't think my anime list is important enough to be necessary to have 2fa.

Second this. As long as it's an option and accounts that don't turn it on aren't restricted in any way, i'm fine with MAL implementing it. But i don't want to enter a code from e-mail every time i log in or share my phone number with MAL.
AnimeThemes.moe <- the largest collection of anime Openings & Endings on the Web
AnimeMusicQuiz.com <- guess an anime from your list by it's Opening/Ending music browser game
Jul 13, 2020 4:05 AM

Offline
Mar 2018
19
I agree, there definitely needs to be a 2FA for MAL.
Jul 14, 2020 8:57 AM

Offline
May 2018
1809
As long as it's optional, I don't care.
Oct 3, 2020 11:50 PM
Offline
Sep 2019
257
Haha are we getting it?
Oct 4, 2020 12:54 AM

Offline
Dec 2009
9489
Heck, I'm surprised MAL still doesn't have a 2FA...
Oct 4, 2020 1:49 AM

Offline
Feb 2019
3432
For an anime site? lol.
Oct 4, 2020 3:03 AM

Offline
Sep 2017
3917
I don't even know what 2FA is
خ
Oct 9, 2020 10:21 PM
Community Admin
sunny moment

Offline
May 2010
2700
Duplicate threads merged.
Dec 7, 2020 9:11 PM
Offline
Sep 2012
3
MapuDofu said:
plain and simple, i think this site should have 2FA incase anyone is going around trying to hack accounts. they would have to put in that "extra effort" if they really wanted to get into someone's account and adds a little more peace of mind for the users. Also, would like a little more to have 2FA through an app rather than email/number if possible
TO EVERYONE THAT SAID THAT 2FA WAS USELESS: https://twitter.com/myanimelist/status/1336174602024783873
Pages (2) [1] 2 »

More topics from this board

» @ sign spam/attack

kuroneko99 - Apr 16

4 by traed »»
Today, 9:50 AM

» Add the option to change profile favorites pictures

k1rb - Oct 21, 2022

20 by Astachanna »»
Today, 9:05 AM

» An "Anime Franchise" page

_cjessop19_ - Today

1 by Astachanna »»
Today, 9:04 AM

» Combining every season of an Anime?

Dennisss - Apr 1, 2021

17 by _cjessop19_ »»
Today, 1:08 AM

Poll: » Add list setting to make notes private (on public lists)

S_h_a_r_k_93 - Nov 12, 2022

25 by anonymate »»
Apr 24, 9:57 PM
It’s time to ditch the text file.
Keep track of your anime easily by creating your own list.
Sign Up Login