Waterwater10 2 Posted ... Maybe have it as an optical step for people. but so a person can't just say hack your account or get your password somewhere and then log in and change your email address and password, have it s that if you change your password or email address, a confirmation email has to be sent to your email address, or maybe implement a Google authenticator or alternative into it, maybe even some security questions, but they'd also have to be protected somehow, maybe by Google auth or email again. I just feel atm, all someone needs to be able to take over your account is your password and email address and they have full reign. Quote Share this post Link to post
iwih2gk 93 Posted ... If someone has your username and password, + full control over your email they have PWN'd you completely anyway! You may want to consider having a more secure email account to use for website authentications. Keep a "bullshit" clearnet email account for chatting with friends but use a solid one for keeping password credentials secure. As a for instance the email account attached to my Air username is ONLY used for this site and only when needed. It is easy to maintain multiple email accounts and such a practice provides additional security in my opinion. Also, depending upon how you pay, having all the receipts for the payment transaction may just allow for Air Mgmt to research and determine that YOU are who you claim. I don't speak for them; but providing them with all the specific transaction details may allow them to reset and restore your account. e.g. I use BTC and keep the transaction details. I can SIGN the BTC address used to make payment, which the person that would potentially steal my account could not do. It is much easier to use good OPsec and avoid needing for someone to assist you in the first place. Quote Share this post Link to post
OpenSourcerer 1435 Posted ... have it s that if you change your password or email address, a confirmation email has to be sent to your email address, This actually would be quite useful... maybe a good thing for the devs to look at when they have too much spare time. or maybe implement a Google authenticator or alternative into it, maybe even some security questions, but they'd also have to be protected somehow, maybe by Google auth or email again. ... but this is overkill. You have no sensible information saved in an AirVPN account. The only thing it protects is the right to use the connection slots. Quote Hide OpenSourcerer's signature Hide all signatures NOT AN AIRVPN TEAM MEMBER. USE TICKETS FOR PROFESSIONAL SUPPORT. LZ1's New User Guide to AirVPN « Plenty of stuff for advanced users, too! Want to contact me directly? All relevant methods are on my About me page. Share this post Link to post
zhang888 1066 Posted ... Valid emails are not required for signing up. This is one of some challenges with sending confirmations to old emails that might not exist.You can always recover a lost account with a ticket. 1 iwih2gk reacted to this Quote Hide zhang888's signature Hide all signatures Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees. Share this post Link to post
iwih2gk 93 Posted ... Valid emails are not required for signing up. This is one of some challenges with sending confirmations to old emails that might not exist.You can always recover a lost account with a ticket. That is what I would have expected from a good quality service provider! Still solid OPsec in the first place is the preferred solution, LOL! Quote Share this post Link to post