Page 1 of 3 123 LastLast
Results 1 to 10 of 21

Thread: n_t reports Support can and will remove 2FA via tickets

  1. #1
    Ice's Avatar
    Joined
    Aug 2012
    Posts
    2,862
    Pronouns
    She/Her
    Userbars
    100
    Thanks
    11,591
    Thanked
    9,239/2,714
    DL/UL
    21/0
    Mentioned
    950 times
    Time Online
    116d 18h 12m
    Avg. Time Online
    39m

    n_t reports Support can and will remove 2FA via tickets

    (you need an account to see links)

    OP about user getting locked out of acct




    Of course I take everything n_t says with a grain of salt but honestly... I want to be surprised but really it was probably only a matter of time for some shit like this to happen. Boy did I really believe for half a second TNT had turned over a new leaf by implementing 2FA. :/ This is such a joke and quite frankly so unacceptable after everything they said about using 2FA to keep your account secure. The user said they have NC logs so hopefully they can get it all set to rights but seriously wtf.

  2. The Following 14 Users Say Thank You to Ice For This Useful Post:

    Buizel (03-21-2023),Cat Purrson (03-21-2023),cuddlypanda (03-21-2023),DarkSkies (03-22-2023),♥ Dita ♥ (03-21-2023),Erik. (03-21-2023),Fiore (03-21-2023),♥ foxe ♥ (03-22-2023),Houndoom (03-21-2023),I_royalty_I (03-21-2023),Nyanobyte                      (03-21-2023),Sakuras (03-21-2023),Synth Salazzle (03-22-2023),Trash Panda (03-21-2023)

  3. #2
    I_royalty_I's Avatar
    Joined
    Dec 2011
    Posts
    7,028
    Userbars
    78
    Thanks
    6,794
    Thanked
    10,970/3,916
    DL/UL
    30/0
    Mentioned
    1,998 times
    Time Online
    437d 22h 11m
    Avg. Time Online
    2h 29m
    Why is that surprising though?
    MFA is meant to keep your account safe from other people who are trying to take it. Any MFA that is implemented by a company, they should 99% of the time hold the keys to the castle for that authentication. In fact, just today I removed MFA auth from about 2 dozen employees who left out company last month. Depending out what kind of tools they use on the backend, it's just a simple matter of clicking and removing MFA. If you were a malicious actor who was trying to get into an account though, you wouldn't be able to do that and would be forced to go through the auth process.

    This isn't anything groundbreaking at all. I support them being able to do this, sucks for the person who got locked out of their account though. It is kind of wild that TNT would remove it in a situation like this, but if the person who targeted the account had all the right info, how is TNT to know the difference.
    What's my definition of success?
    Creating something no one else can
    Being brave enough to dream big
    Grindin' when you're told to just quit
    Giving more when you got nothin' left

  4. The Following User Says Thank You to I_royalty_I For This Useful Post:

    Corliss (03-21-2023)

  5. #3
    Ice's Avatar
    Joined
    Aug 2012
    Posts
    2,862
    Pronouns
    She/Her
    Userbars
    100
    Thanks
    11,591
    Thanked
    9,239/2,714
    DL/UL
    21/0
    Mentioned
    950 times
    Time Online
    116d 18h 12m
    Avg. Time Online
    39m
    Quote Originally Posted by I_royalty_I View Post
    Why is that surprising though?
    MFA is meant to keep your account safe from other people who are trying to take it. Any MFA that is implemented by a company, they should 99% of the time hold the keys to the castle for that authentication. In fact, just today I removed MFA auth from about 2 dozen employees who left out company last month. Depending out what kind of tools they use on the backend, it's just a simple matter of clicking and removing MFA. If you were a malicious actor who was trying to get into an account though, you wouldn't be able to do that and would be forced to go through the auth process.

    This isn't anything groundbreaking at all. I support them being able to do this, sucks for the person who got locked out of their account though. It is kind of wild that TNT would remove it in a situation like this, but if the person who targeted the account had all the right info, how is TNT to know the difference.
    Given the track record of support literally not knowing night from day yeah I rather put the onus on myself to keep my backup codes safe. I'd much rather lose access to my account completely due to my own fault than make it a precedent that you can roll up to support and get them to remove your 2FA 🤷*♀️ if I'm in the minority here then sure. But regardless especially in OP's case where it doesn't sound like their original email was recreated if it was on an old defunct hotmail extension so whoever put a ticket in must have pulled the wool over support's eye in some other manner. (And still, the whole og email rule is absolutely batshit in the first place but hey talking to support when your own stuff is on the line is basically like talking to a wall anyway...) Either way technically speaking yeah TNT should have the power to remove 2FA in extreme circumstances but still the issue lies with lack of proper logic being executed at any point in time to tell whether or not someone really should be granted access to an account. #justneopetssupportthings 🥴

  6. The Following 3 Users Say Thank You to Ice For This Useful Post:

    Buizel (03-21-2023),Corliss (03-21-2023),I_royalty_I (03-21-2023)

  7. #4
    TsUNaMy WaVe's Avatar
    Joined
    Nov 2014
    Posts
    3,429
    Pronouns
    she/her
    Userbars
    104
    Thanks
    5,078
    Thanked
    7,193/2,446
    DL/UL
    47/0
    Mentioned
    449 times
    Time Online
    64d 11h 25m
    Avg. Time Online
    26m
    Rip that person's account.
    But also, that's really sad... people using support to get into other people's accounts is nothing new, but the fact it still happens even with 2FA is outrageous. Though from the post it's unclear if this person actually had it activated?
    Either way, a depressing story all around

    (you need an account to see links)




    (you need an account to see links) || (you need an account to see links)
    I̶ ̶w̶a̶n̶t̶ ̶t̶h̶e̶ ̶b̶a̶k̶a̶ ̶u̶s̶e̶r̶b̶a̶r̶ ̶v̶e̶r̶y̶ ̶m̶u̶c̶h̶!̶ I GOT IT!!!

  8. The Following 2 Users Say Thank You to TsUNaMy WaVe For This Useful Post:

    Corliss (03-21-2023),Fiore (03-21-2023)

  9. #5
    DrSloth's Avatar
    Joined
    Jun 2013
    Posts
    2,179
    Userbars
    45
    Thanks
    1,616
    Thanked
    2,900/953
    DL/UL
    222/0
    Mentioned
    224 times
    Time Online
    101d 8h 12m
    Avg. Time Online
    36m
    Why bother inplementing 2fa if they are gonna act like this left and right? Definetly something useless that just make an extra step for logging in every time

  10. The Following User Says Thank You to DrSloth For This Useful Post:

    Fiore (03-21-2023)

  11. #6
    I_royalty_I's Avatar
    Joined
    Dec 2011
    Posts
    7,028
    Userbars
    78
    Thanks
    6,794
    Thanked
    10,970/3,916
    DL/UL
    30/0
    Mentioned
    1,998 times
    Time Online
    437d 22h 11m
    Avg. Time Online
    2h 29m
    Quote Originally Posted by Ice View Post
    Given the track record of support literally not knowing night from day yeah I rather put the onus on myself to keep my backup codes safe. I'd much rather lose access to my account completely due to my own fault than make it a precedent that you can roll up to support and get them to remove your 2FA 🤷*♀️ if I'm in the minority here then sure. But regardless especially in OP's case where it doesn't sound like their original email was recreated if it was on an old defunct hotmail extension so whoever put a ticket in must have pulled the wool over support's eye in some other manner. (And still, the whole og email rule is absolutely batshit in the first place but hey talking to support when your own stuff is on the line is basically like talking to a wall anyway...) Either way technically speaking yeah TNT should have the power to remove 2FA in extreme circumstances but still the issue lies with lack of proper logic being executed at any point in time to tell whether or not someone really should be granted access to an account. #justneopetssupportthings 🥴
    I hear ya there. I’d much rather control my own MFA, just because I’m paranoid and would trust Google or Microsoft auth over anything somebody else puts together.
    The MFA is relatively new which means whoever hit this account must have been hitting actives.. which is definitely shitty. There are plenty of inactive accounts out there, no need to target the actives that are keeping the site going.

    I’ve definitely had a lot of luck working through support to get access to things in the past, but long inactive accounts that nobody will miss. The OG email thing makes it easier while harder at the same time. So many defunct mail extensions. Even if you’re the OG owner of the account, they don’t usually budge on needing to use the OG to contact them.
    What's my definition of success?
    Creating something no one else can
    Being brave enough to dream big
    Grindin' when you're told to just quit
    Giving more when you got nothin' left

  12. The Following User Says Thank You to I_royalty_I For This Useful Post:

    Ice (03-21-2023)

  13. #7
    Bui bui!
    Buizel's Avatar
    Joined
    Sep 2013
    Posts
    3,506
    Pronouns
    She/her
    Userbars
    105
    Thanks
    10,316
    Thanked
    11,438/2,828
    DL/UL
    67/0
    Mentioned
    713 times
    Time Online
    356d 42m
    Avg. Time Online
    2h 12m
    TNT does everything in their power to go for the "Worst Security on the Internet" award and push people away from the site. I've never seen support for any site be so topsy turvy with their policies and such.



    Ryu adoptable made by Stardust
    Waving Buizel avatar made/animated by Da Plushee Boree
    Buimeleon made by Hare
    Static User bar & Anarchy Buizel made by honeycomb
    Name User bar made by Lyrichord
    Buizel Ryus made by Zapdos & GWN, respectfully
    Cutey Buizel made by Wooloo
    Buizel gif User bar made by Zenitsu
    Vector Buizel made by Hollow
    Ryu Buizel User bar made by Dero
    Christmas Buizel made by DankRUSE


    National Dex Number: 418
    Type: Water
    Sea Weasel Pokemon
    (you need an account to see links)

  14. The Following User Says Thank You to Buizel For This Useful Post:

    Ice (03-21-2023)

  15. #8
    Dero's Avatar
    Joined
    Jun 2014
    Posts
    177
    Pronouns
    he/him
    Userbars
    13
    Thanks
    121
    Thanked
    220/106
    DL/UL
    4/0
    Mentioned
    28 times
    Time Online
    6d 17m
    Avg. Time Online
    2m
    This is depressing and worrying at the same time.
    Something worth noting is that the hotmail.com domain still exists and new accounts can either choose @(you need an account to see links).com or @hotmail.com with them, so it could be a necrod email case?
    Which raises the question, is the ONLY way to keep your account safe to have whatever number of linked emails in the past and present time still active and with access on (and properly secured)? Or will they break through that as well with a sob story
    - ⚡ -
    Userbar by me

  16. #9
    *squeak*
    Bat's Avatar
    Joined
    Nov 2012
    Posts
    4,040
    Userbars
    152
    Thanks
    2,147
    Thanked
    46,673/3,563
    DL/UL
    34/1
    Mentioned
    1,769 times
    Time Online
    644d 1h 41m
    Avg. Time Online
    3h 41m
    Either that, or try to find a way to delicately phrase the following request in a support ticket:

    Hey, Neopets team! Could you please permanently erase my account's registration e-mail address from your records and only use the e-mail address I'm currently using for all time in perpetuity? Thanks!

  17. The Following User Says Thank You to Bat For This Useful Post:

    Buizel (03-21-2023)

  18. #10
    I_royalty_I's Avatar
    Joined
    Dec 2011
    Posts
    7,028
    Userbars
    78
    Thanks
    6,794
    Thanked
    10,970/3,916
    DL/UL
    30/0
    Mentioned
    1,998 times
    Time Online
    437d 22h 11m
    Avg. Time Online
    2h 29m
    Quote Originally Posted by Bat View Post
    Either that, or try to find a way to delicately phrase the following request in a support ticket:
    I don’t think they’d comply with a request like that. They’d have no way to “confirm who the original owner” of the account is if they do that.
    Unless they did this but made it so you had to know what the OG email was and then they can confirm and wipe it as an account that is associated with your account anymore. It’s a fine line to walk and points can be made for both sides of the coin.
    What's my definition of success?
    Creating something no one else can
    Being brave enough to dream big
    Grindin' when you're told to just quit
    Giving more when you got nothin' left

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •