Skip to content
This repository has been archived by the owner on Mar 28, 2024. It is now read-only.

[BUG-18201] Two step login authentication to prevent phishing and account theft #2601

Closed
1 task
sl-service-account opened this issue May 24, 2016 · 1 comment

Comments

@sl-service-account
Copy link

sl-service-account commented May 24, 2016

How would you like the feature to work?

Use the same model many other online services have:

  1. If you attempt to log in to your account from a computer/IP/whatever you normally use, login proceeds as normal
  2. If you attempt to log in to your account from a computer/IP/whatever you've never logged in from before, a verification code is sent to your email address or cell phone, depending on how you've set it up.

Why is this feature important to you? How would it benefit the community?

Phishing is a serious problem that has been plaguing Second Life for a long time because SL users are easy targets with nothing protecting them beyond advice. No matter how many times you give warnings not to click on the fake marketplace links, people still fall for it again and again. This is not going to stop happening unless something is done to protect less savvy players.

Two step authentication would save Second Life users from incredible grief, financial loss, and loss of reputation. The benefits for players are clear and massively outweigh the minimal inconvenience, so I'm going to focus on how this benefits Linden Labs, because as a business they have to weigh the costs vs benefits of implementing any feature.

  • Linden Labs has to use resources helping users get their accounts back, directing resources away from beneficial features. Two step authentication would reduce the operating costs of Second Life.

  • Making the scams go away raises confidence in Second Life as a platform, encouraging people to stick around and spend money, increasing Linden Labs' revenue.

  • The same two step authentication system can be applied to Project Sansara.

Links

Related

Original Jira Fields
Field Value
Issue BUG-18201
Summary Two step login authentication to prevent phishing and account theft
Type New Feature Request
Priority Unset
Status Closed
Resolution Duplicate
Reporter Fouette (fouette)
Created at 2016-05-24T05:44:56Z
Updated at 2016-05-25T18:51:25Z
{
  'Business Unit': ['Platform'],
  'Date of First Response': '2016-05-24T00:50:28.678-0500',
  'How would you like the feature to work?': "Use the same model many other online services have:\r\n\r\n1) If you attempt to log in to your account from a computer/IP/whatever you normally use, login proceeds as normal\r\n2) If you attempt to log in to your account from a computer/IP/whatever you've never logged in from before, a verification code is sent to your email address or cell phone, depending on how you've set it up.",
  'ReOpened Count': 0.0,
  'Severity': 'Unset',
  'Target Viewer Version': 'viewer-development',
  'Why is this feature important to you? How would it benefit the community?': "Phishing is a serious problem that has been plaguing Second Life for a long time because SL users are easy targets with nothing protecting them beyond advice. No matter how many times you give warnings not to click on the fake marketplace links, people still fall for it again and again. This is not going to stop happening unless something is done to protect less savvy players.\r\n\r\nTwo step authentication would save Second Life users from incredible grief, financial loss, and loss of reputation. The benefits for players are clear and massively outweigh the minimal inconvenience, so I'm going to focus on how this benefits Linden Labs, because as a business they have to weigh the costs vs benefits of implementing any feature.\r\n\r\n- Linden Labs has to use resources helping users get their accounts back, directing resources away from beneficial features. Two step authentication would reduce the operating costs of Second Life.\r\n\r\n- Making the scams go away raises confidence in Second Life as a platform, encouraging people to stick around and spend money, increasing Linden Labs' revenue.\r\n\r\n- The same two step authentication system can be applied to Project Sansara.",
}
@sl-service-account
Copy link
Author

Christi Charron commented at 2016-05-24T05:50:29Z

I agree. good idea

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

1 participant