two-factor authentication – Devstyler.io https://devstyler.io News for developers from tech to lifestyle Mon, 07 Feb 2022 12:20:45 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.5 Microsoft requires an Account for Playing Minecraft Java Edition https://devstyler.io/blog/2022/02/07/microsoft-requires-an-account-for-playing-minecraft-java-edition/ Mon, 07 Feb 2022 12:20:45 +0000 https://devstyler.io/?p=80615 ...]]> From March 10 people will no longer be able to play Minecraft: Java Edition unless they create a Microsoft account. 

The news was announced on Minecraft’s official website in a blog post. It was also said that this action was taken in order to ensure player’s safety and security.

However, there are some advantages which are meant to be beneficial for users.

Single account for all Microsoft games, two-factor authentication and improved safety are just some of the options which are supposed to make players’ experience much more enjoyable.

Players don’t have to worry about their data and game progress because all of this will be retained.

In October 2020 Minecraft announced its plans and explained all the changes that are about to become a reality. It has also said that everyone who changes their account from Mojang to Minecraft will receive a cape as a special reward.

]]>
Google is changing the way it handles 2FA https://devstyler.io/blog/2021/10/13/google-is-changing-the-way-it-handles-2fa/ Wed, 13 Oct 2021 09:02:32 +0000 https://devstyler.io/?p=73214 ...]]> Google is making it easier for users to sign into their accounts using backup codes after losing their smartphone with a new dedicated backup codes page.

When users set up two-factor authentication (2FA) or two-step verification (2SV) as the search giant refers to it, the company issues 10 backup codes that can be used to gain access to your account should you happen to lose your smartphone or your security key. Since you no longer have a second device to verify that it really is you, you’ll need to enter these backup codes along with your Google credentials.

In an update to the Google Workspace blog, the company announced that it has created a dedicated backup code page instead of a pop-up. However, you’ll still access it from Google’s 2-Step Verification list on Android, iOS and the web.

This new backup code page can be used to generate new backup codes or refreshed for additional backup codes that users will need to print or download as they did before. However, Google has also added a new option that allows you to delete your backup codes.

OAuth incremental authorization

In a separate post on the Google Developers blog, the company revealed that it’s changing the OAuth consent experience to simplify how users share data with third-party apps. This new experience also improves the consent conversion for apps that utilize incremental authorization.

After consolidating multiple-permission requests into a single screen back in July, Google is now removing the check box when an app only wants to access one of the company’s services.

For instance, if an app wants access to both Google Drive and Google Calendar, a user would need to click on checkboxes for each service. Now when an app only needs to access one of the company’s services such as your cloud storage users can simply click continue which should help speed up the process of giving third-party apps access to your Google account.

]]>
Largest Password Data Breach in History Has Been Leaked Online https://devstyler.io/blog/2021/06/10/largest-password-data-breach-in-history-has-been-leaked-online/ Thu, 10 Jun 2021 13:25:09 +0000 https://devstyler.io/?p=54412 ...]]> Back in 2009, threat actors hacked into the website servers of social app RockYou, accessing over 32 million user passwords stored in plaintext. Now, in what appears to be the largest data breach in history, attackers have compromised with 3.2 billion leaked passwords from multiple databases. This attack has been dubbed RockYou2021.

As only 4.7 billion users utilize the Internet, that means RockYou2021 could actually involve the passwords of nearly twice the global population. Therefore, users should immediately check to see whether their passwords were affected by this leak. Users can check for password compromise using the website Have I Been Pwned or the CyberNews personal data leak checker.

Threat actors can take advantage of the RockYou2021 password collection by combining 8.4 billion unique password variations with existing breach compilations of email addresses and usernames. The hackers could then use these credentials for dictionary and password spraying attacks against an unknowable number of online accounts.

So far, research suggests that all of the passwords involved in this leak have non-ASCII characters between 6-20 characters each, with white spaces removed.

If you believe that one or more of your passwords may have been compromised in the RockYou2021 breach, you can take mitigation steps by immediately changing your passwords for all of your online accounts. In fact, using a password manager can help you create strong, complex passwords that don’t have to be easy to remember. Furthermore, you can enable two-factor authentication (2FA) on all of your accounts.

Finally, as always, make sure to always closely examine all unsolicited spam emails, calls and text messages for potential phishing activity. Most importantly, never click on links or download any executables in messages that you weren’t expecting or from senders you don’t recognize.

]]>