Jump to content

 Something great is coming! 🤖

Stay tuned for the big reveal happening here on iOSGods on the 20th of February!

The countdown has finished!

Future Login Changes: Logging in with Email Address Instead of Display Name


20 posts in this topic

Recommended Posts

Posted (edited)

Hello everyone!


This is an announcement to inform everyone about the upcoming changes to iOSGods Logins. Currently, iOSGods allows Display Name Sign Ins, which is very convenient, but, it poses a security weakness to the accounts.


Why are Display Name logins an issue?
That is a good question! And the answer to that is all Display Names are publicly viewable by anyone, and knowing the user's display name allows the malicious user to attempt to login to multiple accounts with common passwords until they find an account for which the passwords work. And we all know there's always those people who use the same passwords everywhere.

As you can understand, Display Name logins make it easier for a malicious person to do bad things — we do not want that. We have already added a CAPTCHA on login which greatly helps securing the user's account,
and we automatically lock a user account for a certain period of time upon multiple failed attempts, and we also believe switching over to email only logins will secure accounts even further.

We understand this may be an inconvenience to some, but it is necessary. So during the "transition" period, we will allow users to login via Display Name or Email Address so they can get accustomed to the new change.
Then we will move over to email address logins only. We have also added an announcement on the login page regarding this change.

 

What you can do in advance

  1. Ensure the email address associated with your iOSGods account is correct and that you have access to it.
  2. We will be enabling Display Name & Email logins for a while so users can get used to the new changes. Login with your email to check & verify all is correct.
  3. If you're using social logins like Twitter or Google, you should still make sure that the email address on your iOSGods account is correct.

 

What will we do in advance

  1. At some point we will be checking in with our members to make sure their emails are up to date.
  2. This topic serves as an early notice and we'll also be displaying a message on the login screen as well as a contact email address for support.
  3. If there are any issues at all with logging in, we will be available for community's email.

 

We've seen enough unsuccessful brute-force attempts on accounts on our community to make this a sensible move.

Thank you for understanding!

 

Visual example of what we're talking about:

OHa8paA.png

Updated by Rook
  • Like 4
  • Thanks 1
  • Agree 2
  • Informative 1
Posted
2 hours ago, S13GE said:

Can you add the link for authy along with this post for those that don’t know it’s an option 

You’re referring to 2FA? We’ve been thinking of forcing it for ViPs but it’s way more inconvenient.

Posted
6 minutes ago, Rook said:

You’re referring to 2FA? We’ve been thinking of forcing it for ViPs but it’s way more inconvenient.

Yeah 2FA, don’t we use text for Authy? I don’t much care for google Authenticator.

Posted
35 minutes ago, S13GE said:

Yeah 2FA, don’t we use text for Authy? I don’t much care for google Authenticator.

Authy would work the same too, but it’s still a bit much.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines