The Importance of Account Security

Discussion in 'General Discussion' started by eekelmo, Aug 21, 2015.

  1. eekelmo

    eekelmo Builder
    Builder ⛰️ Ex-EcoMaster ⚜️⚜️⚜️⚜️ Premium Upgrade

    Joined:
    Jul 19, 2012
    Messages:
    3,289
    Trophy Points:
    69,090
    Ratings:
    +7,789
    Hello everyone,
    Today I'd like to raise awareness about a little something called '2 Factor Authentication', or '2fa' for short. It's a handy thing that'll stop your account from becoming compromised. You may think 'Oh, no one would hack me, I'm too smart for that!', well if we look at recent events - we see that anyone is at risk of having their account compromised (Mojang pls).

    So what can I do? How do I keep my precious ECD from being stolen by a keyboard warrior?
    Simple - if you're a donator;
    2 Factor authentication.

    Step 1.
    Type '/2fa' into chat. You should receive a map.

    Step 2.
    Download google authenticator for free at:
    Android: https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en
    IOS: https://itunes.apple.com/au/app/google-authenticator/id388497605?mt=8

    Step 3.
    Type in the really long code that is written on the top of the map you get from typing '/2fa' and now you have linked Google Authenticator to Minecraft! Alternatively you can scan the QR code on the map.

    Step 4.
    Now type /2fa and the 6 digit code you are given on the Google Authenticator application.

    Step 5.
    Now whenever you log in on a different IP you will be required to type '/2fa <code>' for security purposes - you simply get this code from the Google Authenticator application.

    But I haven't donated to the server - and I don't plan to do so any time soon, how do I keep my account safe?

    Well here are some general tips for non-donors and donors
    - Use different passwords for everything
    - Change your passwords regularly
    - Set security questions for your account at http://www.mojang.com/ to ensure no one can steal your account.
    - Don't tell anyone your password
    - Don't send your .minecraft to other users
    - Common sense

    If you need anything clarified or have other tips please feel free to ask/respond.
     
    • Friendly Friendly x 1
    • Creative Creative x 1
    • List
    #1 eekelmo, Aug 21, 2015
    Last edited: Sep 21, 2015
  2. 314

    314 Irrational Moderator, former ServerAdmin
    SuperMod EcoLegend ⛰️⛰️⛰️⛰️ Ex-President ⚒️⚒️ Prestige ⭐ VI ⭐ Premium Upgrade

    Joined:
    Apr 1, 2014
    Messages:
    7,046
    Trophy Points:
    97,160
    EcoDollars:
    $1,400,000
    Ratings:
    +4,917
    Exchange for step 3...
    Scan the QR code itself with your phone and save you lots of annoyed typing? :p
     
  3. eekelmo

    eekelmo Builder
    Builder ⛰️ Ex-EcoMaster ⚜️⚜️⚜️⚜️ Premium Upgrade

    Joined:
    Jul 19, 2012
    Messages:
    3,289
    Trophy Points:
    69,090
    Ratings:
    +7,789
    Added. I forgot about that as it didn't work for me :)
     
  4. Mission001

    Mission001 Ex-EcoLegend HⱻặĐHůƞẗǝɍ
    ECC Sponsor President ⛰️⛰️ Ex-EcoLegend ⚜️⚜️⚜️⚜️ Prestige ⭐ III ⭐ Premium Upgrade

    Joined:
    Apr 16, 2011
    Messages:
    5,563
    Trophy Points:
    102,160
    Gender:
    Male
    EcoDollars:
    $495
    Ratings:
    +6,485
    tl:dr
    Don't be stupid and make your password a:eek:bvious b:like everything else.
     
  5. BrokeMel

    BrokeMel broke
    Resident ⛰️ Ex-Tycoon ⚜️⚜️⚜️ Premium Upgrade

    Joined:
    Jul 26, 2013
    Messages:
    1,018
    Trophy Points:
    61,160
    Gender:
    Female
    Ratings:
    +830
    The app requires iOS 7.0 or later and I already typed /2fa...
     
    #5 BrokeMel, Aug 21, 2015
    Last edited: Aug 21, 2015
  6. eekelmo

    eekelmo Builder
    Builder ⛰️ Ex-EcoMaster ⚜️⚜️⚜️⚜️ Premium Upgrade

    Joined:
    Jul 19, 2012
    Messages:
    3,289
    Trophy Points:
    69,090
    Ratings:
    +7,789
    If you haven't set it up with Google Authenticator yet then you should be fine.
     
  7. 2RCR

    2RCR Builder
    Builder ⛰️ Ex-Mayor ⚒️⚒️ Premium Upgrade

    Joined:
    Mar 1, 2013
    Messages:
    67
    Trophy Points:
    35,420
    Gender:
    Male
    Ratings:
    +18
    Did you guys insure that it wasn't the forums that were compromised? Someone could have implemented a back door into the forum database. If said person uses the same password for both MC and forums their account would be compromised. Id check I.P logs to be safe.
     
    • Winner Winner x 1
    • Potato Potato x 1
    • List
  8. JamieSinn

    JamieSinn Retired Lead Administrator/Developer
    Builder ⛰️ Ex-Tycoon ⚜️⚜️⚜️ Premium Upgrade

    Joined:
    Jun 4, 2011
    Messages:
    5,517
    Trophy Points:
    78,090
    Gender:
    Male
    Ratings:
    +4,588
    We're safe thanks.
     
    • Winner Winner x 1
    • Creative Creative x 1
    • Potato Potato x 1
    • List
  9. 29dude

    29dude Builder
    Builder ⛰️ Ex-President ⚒️⚒️

    Joined:
    Mar 8, 2015
    Messages:
    728
    Trophy Points:
    19,620
    Gender:
    Male
    EcoDollars:
    $0
    Ratings:
    +859
    Is this an ECC thing, or a mojang thing?
     
  10. myminecrafter01

    myminecrafter01 Builder
    Builder ⛰️ Ex-President ⚒️⚒️

    Joined:
    Jun 25, 2012
    Messages:
    1,073
    Trophy Points:
    29,340
    Gender:
    Male
    EcoDollars:
    $0
    Ratings:
    +184
    /2fa is an ECC command, has nothing to do with Mojang.
     
  11. BaccaAMP

    BaccaAMP Bacca Mafia
    EcoMaster ⛰️⛰️⛰️⛰️ Ex-Tycoon ⚜️⚜️⚜️ Prestige ⭐ II ⭐ Premium Upgrade

    Joined:
    Jan 4, 2014
    Messages:
    593
    Trophy Points:
    64,410
    Gender:
    Male
    Ratings:
    +751
    ur instructions confused the hell out of me
     
  12. Monchy93

    Monchy93 Builder
    Builder ⛰️ Ex-Mayor ⚒️⚒️

    Joined:
    Jul 31, 2014
    Messages:
    584
    Trophy Points:
    23,040
    Gender:
    Male
    Ratings:
    +436
    It took me a while to realize you don't need a space between the 6 digits. ^.^
     
  13. andrewkm

    Founder Premium Upgrade

    Joined:
    Apr 5, 2011
    Messages:
    20,603
    Trophy Points:
    102,160
    Ratings:
    +15,128
    No, we're perfectly fine.
    What happened was someone literally carelessly gave their password away.
     
    • Informative Informative x 1
    • Optimistic Optimistic x 1
    • List
    #13 andrewkm, Aug 22, 2015
    Last edited: Aug 22, 2015
  14. Willebrandt

    Willebrandt Builder
    Builder ⛰️ Ex-Mayor ⚒️⚒️

    Joined:
    Aug 21, 2015
    Messages:
    57
    Trophy Points:
    14,590
    Gender:
    Male
    Ratings:
    +58
    Who would give their password away? lol
     
  15. myminecrafter01

    myminecrafter01 Builder
    Builder ⛰️ Ex-President ⚒️⚒️

    Joined:
    Jun 25, 2012
    Messages:
    1,073
    Trophy Points:
    29,340
    Gender:
    Male
    EcoDollars:
    $0
    Ratings:
    +184
    Technically is wasn't the password but it might as well have been. It was the session authentication token. I'm not sure how much I'm allowed to disclose but for the benefit of everyone else.

    DO NOT SHARE YOUR .minecraft FOLDER!

    In a file called launcher_profiles.json it contains your session authentication token. Your account can be hijacked with this token. This token doesn't allow someone to change your Minecraft password but it does allow them access your account until the session is re-authenticated.
    If you do feel the need to share your Minecraft folder make sure you remove the launcher_profiles.json and all the log files. Disclaimer: I can't guarantee this is all you need do to ensure you're safe from this form of attack. Exercise extreme caution and only share with people you trust, or better still don't share with anyone. There really is no reason to share your entire .minecraft folder.
     
    • Informative Informative x 5
    • Like Like x 1
    • List
    #15 myminecrafter01, Aug 22, 2015
    Last edited: Aug 22, 2015