The fact that they got your SE Account password and you don't use a token = you're most likely screwed even if they send you an e-mail.
Printable View
The fact that they got your SE Account password and you don't use a token = you're most likely screwed even if they send you an e-mail.
In theory, in practice people aren't going to write exploits that depend on having the multi-factor authorization on the same machine when they have to be a minority of token users, and it's demonstrated that so many people don't even use security tokens. Low hanging fruit and all.
I can agree with that. Though that being said, it still would be dumb to have the token on your computer, lol. That is effectively like hiding your spare house key under your doormat. The door is still locked, but..... :P
If more people would just use the token a LOT of the gill seller issues would go away as they can't hack as many accounts. The 5 second "hassle" of entering the code is totally worth it. I don't understand people who refuse to use it.
Two factor authentication, what's hard to understand. Out of all the compromised accounts hijacked by RMT, I'd bet none used the security token. Personally, I think it's time to make two factor authentication mandatory.
Technically, PS3/PS4 playerswith a security token have 3 factor security since PSN authenticates you and your license, then SE takes your password and one time security code.
I've heard many unpleasant news regarding to the smartphone token, so I'm bit scared to use it.
If you lose your phone you're in totally bad position beyond any help.