Replace F2A with more stable security system
Becoming eligible for discovery & so on requires F2A being enabled & after being enabled mod actions require you to go through annoying process, I am simply asking that actions such as these would require instead you using your discord account's password which you can change from your email.
I am asking that you would replace F2A with more stable security system (account's password which you can change via email) or atleast give option for it.
Currently F2A works only to make sure that only owner of the account can do mod actions on his servers. Some problems with this are that F2A isn't exactly a stable system.
I had today my first stress moment when I couldn't delete useless server of mine because Authy gave me wrong password even tho my Authy was linked to my discord from the previous time I enabled F2A. I tried backup codes but for the first 3 times they didn't work either. 4th time it worked & I got logged in.
Anyone who has access to the application itself on my devices can access those backup codes so basically whole Authy system is useless from protecting anyone making changes if someone is on my device.
Basically F2A means that you have to go through unnecessary process to do administrative actions & if you can access your account so can anyone else who can access your discord application via your phone or computer. It doesn't protect servers or your account. It just adds the possibility that you cannot access your account anymore if you happen to lose the backup codes on device resets.
Also the F2A sms system doesn't work...
Running a community server with Authy doesn't safe it from griefing. Actually moderators themself usually end up raiding instead of someone else from their device.
Also for mobile & pc users running a community server have no protection what so ever on their Authy application unless they put a pincode on the app it like usually people do on discord already
1
-
I agree too that this system should be changed and replaced with a easier method by email or just using passwords.
0
Du måste logga in om du vill lämna en kommentar.
Kommentarer
1 kommentar