• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

DFG

Self requested ban
Banned
Oct 25, 2017
3,591
Someone tried to hack into my Xbox account but too bad for them I've got Two-factor authentication on my accounts. Otherwise I would've been dealing with some crap now.
 

Green Mario

Member
Oct 27, 2017
4,319
Someone in Russia has been steady trying to log into my old Steam account that has one game on it for years now. Thanks to 2FA, they'll never get to experience the first Max Payne.
 

Musubi

Unshakable Resolve - Prophet of Truth
Member
Oct 25, 2017
23,620
Yup. My Microsoft, Google, Nintendo, Sony and Discord accounts are all 2FA'd up. Glad Sony finally lets you use an app instead of SMS.
 

Yes

Member
Oct 28, 2017
848
Glad Sony finally lets you use an app instead of SMS.
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.
 

Blue Hedgehog

Member
Mar 7, 2018
207
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.

There are other authenticator programs like Authy which lets you back up your 2FA codes to the cloud.
 

ChemicalWorld

Member
Dec 6, 2017
1,742
I learnt that lesson the hard way long ago. When my BT e-mail was logged into because I used the same/similar password for most things. Didn't take long for my original ChemicalWorld gamertag to disappear into the void of being hacked. Thankfully I was able to recover my PlayStation account/Star Citizen account (with all the pledged content intact...) and anything else that had been messed around with.

When that happened I switched to multiple e-mail addresses, Last Pass and 2FA where possible to prevent fucking up to that extent ever again.
 

ZeroDS

The Fallen
Oct 29, 2017
3,421
I actually just turned on 2fa on my Microsoft account with their app and every day I'm horrified when I log in to the app and see about 10 different sign in failures from all around the world.

Like is this normal, it's freaking me out
 

demi

Member
Oct 27, 2017
14,849
Someone tried to hack into my Xbox account but too bad for them I've got Two-factor authentication on my accounts. Otherwise I would've been dealing with some crap now.

How do you know when and if someone is trying to hack your Xbox account? Is there anything weird in your Sign-In Activity page?
 

AIan

Member
Oct 20, 2019
4,869
How do you know when and if someone is trying to hack your Xbox account? Is there anything weird in your Sign-In Activity page?

From my experience, I would receive e-mail alerts, which then pop up on my mobile push notifications bar.

2FA is pretty much a must these days. I also strongly recommend against reusing any passwords. You think it's fine but eventually you will likely get pwned from a site somewhere and hackers will have gained a password that's shared with a ton of your accounts.

I didn't think hackers would want my accounts but nope, they tried getting into my Microsoft, MEGA, Sony, Bank (successful), and others. I save my passwords in a special place. You could consider getting a physical key like a flash drive with a notepad of your passwords, as well as on your phone on a default notepad app (preferably password-protected)
 

Blue Ninja

Prophet of Truth
Member
Oct 25, 2017
2,774
Belgium
How do you know when and if someone is trying to hack your Xbox account? Is there anything weird in your Sign-In Activity page?
Yeah, you'll find it in your sign in activity page. If 2FA is activated, you'll also get an alert when someone signs in using the correct password, so if that happens you know to change it.
 

Rosebud

Two Pieces
Member
Apr 16, 2018
43,625
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.

Always save your backup codes.
 
OP
OP
DFG

DFG

Self requested ban
Banned
Oct 25, 2017
3,591
How do you know when and if someone is trying to hack your Xbox account? Is there anything weird in your Sign-In Activity page?
From my experience, I would receive e-mail alerts, which then pop up on my mobile push notifications bar.

2FA is pretty much a must these days. I also strongly recommend against reusing any passwords. You think it's fine but eventually you will likely get pwned from a site somewhere and hackers will have gained a password that's shared with a ton of your accounts.

I didn't think hackers would want my accounts but nope, they tried getting into my Microsoft, MEGA, Sony, Bank (successful), and others. I save my passwords in a special place. You could consider getting a physical key like a flash drive with a notepad of your passwords, as well as on your phone on a default notepad app (preferably password-protected)
Pretty much what Alan said. I got a text about using a code to sign in. Obviously I didn't even sign in through the website.
 

Tunesmith

Fraud & Player Security
Verified
Oct 25, 2017
1,939
If you get a 2FA code that wasn't issued by yourselves, update your passwords.

Failed logins with no 2FA codes issued = the perpetrator don't know your password and are just credential stuffing emails on various services to try and get lucky.

Failed logins with 2FA codes issued = they know your username and password combination and you are likely to be targeted for additional attacks specific to circumventing 2FA layers of protection. Maybe not today, or this week, but your account goes into a list, that info may be resold to other perpetrators that will eventually target you again through more elaborate vectors you may not successfully stop.
 

Deleted member 44122

Guest
If you get a 2FA code that wasn't issued by yourselves, update your passwords.

Failed logins with no 2FA codes issued = the perpetrator don't know your password and are just credential stuffing emails on various services to try and get lucky.

Failed logins with 2FA codes issued = they know your username and password combination and you are likely to be targeted for additional attacks specific to circumventing 2FA layers of protection. Maybe not today, or this week, but your account goes into a list, that info may be resold to other perpetrators that will eventually target you again through more elaborate vectors you may not successfully stop.
you wouldnt even know with a 2fa app
 

THEVOID

Prophet of Regret
Member
Oct 27, 2017
22,873
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.

I use MS auth which backs up on iCloud.
 

I_love_potatoes

Attempted to circumvent ban with alt account
Banned
Jul 6, 2020
1,640
I actually just turned on 2fa on my Microsoft account with their app and every day I'm horrified when I log in to the app and see about 10 different sign in failures from all around the world.

Like is this normal, it's freaking me out

That happens when you use the same email multiple times. That's why I have a separate email for Xbox, PS and Switch accounts. I don't use those emails for anything else.
 

Ninjadom

Member
Oct 25, 2017
5,197
London, UK
I had two emails from Nintendo yesterday. Both the same. Someone had attempted to add my Nintendo account to their Nintendo Switch.

"It looks like this e-mail address is already registered to a Nintendo Account."

Hmmm...
 

Musubi

Unshakable Resolve - Prophet of Truth
Member
Oct 25, 2017
23,620
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.
Yeah that's the downside to 2FA but I think any implementation of 2FA also has backup codes incase you get locked out. And yes SMS 2FA can be defeated by a hacker spoofing your SIM card essentially.
 

jokkir

Member
Oct 25, 2017
8,171
Also a reminder to save your backup codes somewhere and keep them up to date (not filled with used codes). Backup codes saved me more than a few times so it's definitely recommended you keep it safe and organized until when you need it.
 

greengr

Member
Dec 3, 2018
2,713
doesnt MS basically force you to 2FA even if you havent turned it on?like if you sign in with a new device,they send you a security code in your e-mail to log in?
 

ArchAngel

Avenger
Oct 25, 2017
1,476
2FA for the win! On the Sony site it still only shows SMS as the only option for me 😭

Since some months 1password also has a function for storing 2FA codes and inserting them automatically. Idk if LastPass had it too, but I stopped using Authy since then because I have it in one app instead of 2. Very convenient :)
 

crazillo

Member
Apr 5, 2018
8,186
I've had trouble setting up the Sony 2FA with my authentificator app so I'm using SMS again now. Are these considered less secure?
 

Yuuber

Member
Oct 28, 2017
4,153
My friend lost his PSN account with hundreds of games due to not having a 2FA in place. Sony, obviously, gave zero fucks and was of no avail.


So, yeah. Turn it on.
 

Decarb

Member
Oct 27, 2017
8,643
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.
Never use Google Authenticator. If you break or lose your phone and don't have backup codes, your account is gone forever.
 

Decarb

Member
Oct 27, 2017
8,643
How is that different from any other authenticator?
With Authy as long as you're using same phone number you can restore it on a new phone easily. I had my Ninitendo account 2FA'd with Google on an old phone, broke its screen this year and had to spend $70 to get it fixed just to disable the 2FA.
 
Jan 10, 2018
6,927
Someone cracked my passwords on a couple of sites last week so I updated them now with 2FA. I think I've had about 4 breaches in total and they've all been big american services. It was Netflix, Amazon, Microsoft and Blizzard. The last one hurt the most because they took all my gear in Diablo 3. :(
 

g-m1n1

Member
Oct 27, 2017
2,409
Luxembourg
With Authy as long as you're using same phone number you can restore it on a new phone easily. I had my Ninitendo account 2FA'd with Google on an old phone, broke its screen this year and had to spend $70 to get it fixed just to disable the 2FA.
Yep Authy or Microsoft Authenticator have some clouds saves. So you can switch phone or even use it on 2 devices simultaneously (at least id does with MS app). Have it on my iPhone and iPad.

Call me dumb, I never found how to change to 2FA on PSN. I still get a SMS...
Edit: I needed to deactivate and reactivate it, then I could chose between SMS or App.


Also, don't forget to download a Password Manager! BIWARDEN is free and open-source. Also avalaible for different platforms.
bitwarden.com

The password manager trusted by millions | Bitwarden

Bitwarden makes it easy for businesses and individuals to securely generate, store, and share passwords from any location, browser, or device. Create your free Bitwarden account today.

(I use mSecure, but you need to buy it. Installed Bitwarden on my GFs iPhone and Laptop, works great!)
 
Last edited:

survivor

Member
Oct 25, 2017
570
Is anyone actually brute forcing some of these sites for Microsoft or Nintendo or just trying passwords from data breaches?

it feels like a lot of account hacks are either reused passwords or some social engineering like with sim swapping.
 
OP
OP
DFG

DFG

Self requested ban
Banned
Oct 25, 2017
3,591
What happens if my phone breaks as I'm using Google's authenticator for like 8 services? Always kinda bugged me, but never tried to find out. SMS always comes to the number and the number doesn't get affected by say a broken phone. But I hear SMS is not that secure. And they've added a warning on the SMSs that some charges may apply.
Make sure you create back up code. This link will help you explaining the process.

Sign in with backup codes - Computer - Google Account Help

If you can’t sign into your Google Account with your normal 2-Step Verification, you can use a backup code for the second step. Create backup codes to use in case you lose your phone, change your phon
 

Musubi

Unshakable Resolve - Prophet of Truth
Member
Oct 25, 2017
23,620
Is anyone actually brute forcing some of these sites for Microsoft or Nintendo or just trying passwords from data breaches?

it feels like a lot of account hacks are either reused passwords or some social engineering like with sim swapping.
Probably a combination of both.