Forums

RuneScape Authenticator

Quick find code: 294-295-311-65405052

Noztrom
Dec Member 2021

Noztrom

Posts: 38 Bronze Posts by user Forum Profile RuneMetrics Profile
In the Google Authenticator app, your code will change every few seconds. I am not sure if that is suppose to be safe. I was going to disable JAG, but I only remember 4 of my 5 JAG security questions. So I am unable to safely disable JAG. I just hope this authentication system helps up stop any hackers from getting into our accounts.

24-Jun-2014 05:49:52

Rune King

Rune King

Posts: 4,573 Adamant Posts by user Forum Profile RuneMetrics Profile
NZ Sheeps said :
Theos said :
This new authenticator, however, uses 2 step authentication. In order for someone to hijack you, they would need to steal your cell phone in real life. This makes the chances of getting hijacked nearly impossible for someone with the authenticator.

Folks who had JAG without using an email with 2 step authentication were still easy phishing targets for hijackers, because gaining control of the email account would enable the hijacker to easily gain control of the account.


Let's face it, it's more likely for a someone after your Runescape account to go after your online email account than your physical phone.

If a hijacker does gain control of your email (which you say is the weakness of JAG) then what is to stop them resetting your pass-word AND disabling the authenticator straight away.

Also the Google appstore for android and your android mobile account are all tied to your email so again a hacker just has to get your email. Also I don't use apple products but aren't iphones the same way? Everything is simply tied into a single email account?

24-Jun-2014 06:16:25

Irish Shaman

Irish Shaman

Posts: 6,991 Rune Posts by user Forum Profile RuneMetrics Profile
Now it could just be me as I don't use apps or waste money on these new smart phones or the app stores, but wasn't it confirmed by at least two Jagex staff members on the BTS video last week, that there would be an option or ability to use this on your computer to get the code?

I don't see the point in removing JAG though. The removal of JAG was "explained" as simply "It's more secure, as JAG is sometimes simple to bypass". Well unless most of us here are really, really bad judges of characters and pick bad friends, I don't really see that as a danger.

24-Jun-2014 06:18:59 - Last edited on 24-Jun-2014 06:22:27 by Irish Shaman

Shaunmcfc

Shaunmcfc

Posts: 1,177 Mithril Posts by user Forum Profile RuneMetrics Profile
NZ Sheeps said :
Theos said :
This new authenticator, however, uses 2 step authentication. In order for someone to hijack you, they would need to steal your cell phone in real life. This makes the chances of getting hijacked nearly impossible for someone with the authenticator.

Folks who had JAG without using an email with 2 step authentication were still easy phishing targets for hijackers, because gaining control of the email account would enable the hijacker to easily gain control of the account.


Let's face it, it's more likely for a someone after your Runescape account to go after your online email account than your physical phone.

If a hijacker does gain control of your email (which you say is the weakness of JAG) then what is to stop them resetting your pass-word AND disabling the authenticator straight away.


This ^ +1
And then with Jag step 2 they need to know your security questions
plus be on a PC That Jag/Jagex recognises before they can even do that.
At least give us the choice of security we wish to use on OUR accs.
.And now the end is near its time to raise the final curtain.
Regrets i have a few, but i did it my way.

Proud 10 year veteran
Hate Botters and key abusers.

24-Jun-2014 06:23:25

Andi

Andi

Posts: 4,831 Adamant Posts by user Forum Profile RuneMetrics Profile
Original message details are unavailable.
18. What if I don’t have my authentication device on me?

If you are trying to login from a new PC but do not have your device with you, simply click on the ‘disable authenticator’ link on screen and an email will be sent to your registered email containing a link to disable the authenticator. With the authenticator disabled, you’ll be able to access your account, but we strongly recommend that you re-enable the authenticator when you get your device back.


So what you are saying is if someone who has lost control of their e-mail as well will easily have their account hacked. A hacker can log into the account management, disable the authenticator and then access the e-mail to disable it.

After doing so, the hacker can then add the scanbar into their own phone to set it up for themselves.

p.s. people who do not have a phone, there are computer authenticators that work as the same way a phone does. winauth is a good program that can do this type of feature.

Edit: people who use gmail and have the 2-step verification are more secured than others. I would encourage people who do have a phone to use gmail.

cute af said :

Well, no. Each device has it's own personal ID that no other has. You would have to get a hold of the physical phone in order to use the app. You use your camera to scan a bar code and it gives you a number to put in. Then your account is linked with the phone ID forever unless you remove it. Even if they logged into your e-mail or apple account associated with it, they wouldn't be able to get 'into' your phone because they are separate devices. I hope that makes sense. :P


It is possible to have one account tied into more than one phone. I have google authenticator with the same accounts on two different phones. The generated numbers even work as well.

(¸„‹•*˜
Andi
˜*•›„¸)
(¸„‹•*˜
Andi
˜*•›„¸)

24-Jun-2014 06:34:29 - Last edited on 24-Jun-2014 06:41:33 by Andi

Quick find code: 294-295-311-65405052 Back to Top