ekricket
Royal Flush
This is a place where we spend $4 to represent $0.25, not once but several hundred timesAre you kidding ? Maybe if the members would use a little common sense .
Just sayin
This is a place where we spend $4 to represent $0.25, not once but several hundred timesAre you kidding ? Maybe if the members would use a little common sense .
We're hiring.I work in I.T. for a financial institution and I appreciate that there might be a few less people to scam me. I have no common sense with 'too good to be true' chip deals.
https://www.pokerchipforum.com/threads/fraud-and-the-dibs-system.83834/I hope so. Given the number of people that go after a popular item, though, they may just pass over you and go to the next buyer in the queue who is less demanding and/or more trusting. The buyer has to assume that they may lose out on the item if they make that request, and be willing to accept that. It's the price of diligence.
If the seller states that the sale is a dibs sale, I agree. If they post an ad without restrictions (including mentioning of dibs., as it restricts the seller), I believe that the seller remains free to sell to whomever they choose. Dibs means nothing in that case. Hence the risk.https://www.pokerchipforum.com/threads/fraud-and-the-dibs-system.83834/
... Nope, that's what dibs-based sales are for. If I post a dibs and I ask for a follow-up picture to authenticate the seller and they refuse and skip over me, then they are getting publicly outted.
Sellers have a right to sell to who they want (asshat clause, etc), but when they post a classifieds ad that doesn't have restrictions, then they are committing to respecting reasonable authentication requests.
I've used all three of these apps, and I currently use MS Authenticator for multiple accounts.I highly recommend that members use a 2FA app on their phone vs email just because there can be issues with getting the code via email. The codes via a 2FA app are instantly on your phone and refresh every 30 seconds.
View attachment 837783
View attachment 837784
Microsoft Authenticator
Android: https://play.google.com/store/apps/details?id=com.azure.authenticator
iPhone: https://apps.apple.com/us/app/microsoft-authenticator/id983156458
Authy Authenticator
Android: https://play.google.com/store/apps/details?id=com.authy.authy
iPhone: https://apps.apple.com/us/app/twilio-authy/id494168017
Google Authenticator
Android: https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2
iPhone: https://apps.apple.com/us/app/google-authenticator/id388497605
Good way to get rid of the users who lurk 2-3 times a month like me ... I obviously managed to get through but only because I got lucky on my second guess at my password (and I don't even remember what I typed in even though it was only about 5 minutes ago). If I had to reset my password and then get a 2FA email and come back to the site to enter it, I'm probably going to move on and surf elsewhere. But I don't really spend much money here and don't contribute a ton, so it's not much of a loss for the site. Those of you who do contribute a lot are more likely to jump through all these extra hoops. But hey, I'm good for 30 days, so you might see me around every week or two through the end of the month.
That guy only posted 100+times a year as compared to Tommy's astounding 1,940 per year average (approximate) for a high of 5.3 posts per day average. But that record for highest per day average is held by @FordPickup92 with an astonishing 7,774 posts per year rounding out to 21.2 messages a day!
I suppose that depends on what 2FA app or device you're using. The Google Authenticator app just uses a synced clock algorithm to generate a 6 digit code at the site and in the app. I'm not aware of it doing any location tracking.2FA also tracks your location by your IMEI number on your phone. No amount of a VPN will allow you to be anonymous when you 2FA. What is PCF response as it pertains to tracking information and how all of that information gets disseminated?
Source?2FA also tracks your location by your IMEI number on your phone. No amount of a VPN will allow you to be anonymous when you 2FA. What is PCF response as it pertains to tracking information and how all of that information gets disseminated?
Almost all 2FA "require a phone number" for creating accounts including Authy. Currently i did 2FA through email which cannot as easily identify the person. Basically with 2FA your phone number IMEI is being recorded with each 2FA activation and easily track the person and where and when they were "authenticated". You are correct then that the app is responsible for that recorded info, but PCF should make that information that your Identity is/or could be recorded through 2FA since this has been the chosen method for verification on this forum, and update their terms of service when joining the forum.I suppose that depends on what 2FA app or device you're using. The Google Authenticator app just uses a synced clock algorithm to generate a 6 digit code at the site and in the app. I'm not aware of it doing any location tracking.
1Password (no subscription, no password) + iOS. Better than a kick to the groin.Almost all 2FA "require a phone number" for creating accounts including Authy. Currently i did 2FA through email which cannot as easily identify the person. Basically with 2FA your phone number IMEI is being recorded with each 2FA activation and easily track the person and where and when they were "authenticated". You are correct then that the app is responsible for that recorded info, but PCF should make that information that your Identity is/or could be recorded through 2FA since this has been the chosen method for verification on this forum, and update their terms of service when joining the forum.
It should be obvious that on a google android phone google apps are always authorized to access the imei and all other identifiers and obviously the same
applies to apple on their phones. Till now the tracking of ip addresses... phone numbers and locations can reveal a real identity but it is not 100 percent guarantee. They can assign a probability that an ip address that's been seen before is you or your family but with people now using vpns this is not guaranteed. Same with locations if people turn off location permissions on their devices then they can no longer get a high probability of accuracy with these tracking identities this prevents them from doing cross device tracking or tracking what you do over several devices. You can see this being pushed by google as now the only acceptable 2fa to them is your mobile phone so if you have two computers a tablet and a mobile phone they want all the devices to have 2fa using the mobile phone only.
Blah blah blah. Discussing all this here would hijack this thread i just wanted to let the forum Admin know the issues and they should update terms of service to let the users here know.
Hahaha1Password (no subscription, no password) + iOS. Better than a kick to the groin.
The info in this post is largely false and/or outdated.Almost all 2FA "require a phone number" for creating accounts including Authy. Currently i did 2FA through email which cannot as easily identify the person. Basically with 2FA your phone number IMEI is being recorded with each 2FA activation and easily track the person and where and when they were "authenticated". You are correct then that the app is responsible for that recorded info, but PCF should make that information that your Identity is/or could be recorded through 2FA since this has been the chosen method for verification on this forum, and update their terms of service when joining the forum.
It should be obvious that on a google android phone google apps are always authorized to access the imei and all other identifiers and obviously the same
applies to apple on their phones. Till now the tracking of ip addresses... phone numbers and locations can reveal a real identity but it is not 100 percent guarantee. They can assign a probability that an ip address that's been seen before is you or your family but with people now using vpns this is not guaranteed. Same with locations if people turn off location permissions on their devices then they can no longer get a high probability of accuracy with these tracking identities this prevents them from doing cross device tracking or tracking what you do over several devices. You can see this being pushed by google as now the only acceptable 2fa to them is your mobile phone so if you have two computers a tablet and a mobile phone they want all the devices to have 2fa using the mobile phone only.
Blah blah blah. Discussing all this here would hijack this thread i just wanted to let the forum Admin know the issues and they should update terms of service to let the users here know.
I dont think that's correct even with Android 10+. If you can setup a 2FA without a Phone Number, then you would be correct. I will double check your points, but i'm pretty sure that even with Authy (which was suggested) you cannot setup an account to use it without a Phone Number and you have to verify your phone number, usually through a PUSH notification which is using a "platform app" or system app to generate the push - which you clearly specify as one of the "very limited exception" android will allow access to the IMEI.The info in this post is largely false and/or outdated.
Android:
1) Modern versions of Android (10+) do not allow apps to access the IMEI, with the very limited exception of platform apps and specific carrier apps.
2) Older versions of Android only allow apps to access the IMEI if they have the "phone state" permission.
3) None of the 2FA apps mentioned here request the phone state permission, so they literally cannot get the IMEI from the phone.
iOS:
1) App Store applications cannot access the IMEI in any way short of requesting the user to type it in manually.
It is a good general practice, especially if you are running a phone with an older OS, to remove apps that you don't use and to only grant phone state permission to trusted apps that have a reason to need it. But you don't need to worry about 2FA apps "tracking you through IMEI" and PCF certainly does not need to change their TOS.
I don't recall if I had to give my phone number to set up MS Authenticator, but I probably did. But IMEI is not a phone number. It's a non-modifiable hardware identifier tied to a specific device.I dont think that's correct even with Android 10+. If you can setup a 2FA without a Phone Number, then you would be correct. I will double check your points, but i'm pretty sure that even with Authy (which was suggested) you cannot setup an account to use it without a Phone Number and you have to verify your phone number, usually through a PUSH notification which is using a "platform app" or system app to generate the push - which you clearly specify as one of the "very limited exception" android will allow access to the IMEI.
I will confirm that you might be right on this or i might be wrong.
FreeOTP adds a second layer of security for your online accounts identity, a QR-code which would be scanned by user’s mobile device can be used and weakness of traditional password based system can be improved by one time password (OTP) which can be calculated by user transaction information and data unique at user side like IMEI number of the user mobile device.There are many 2FA implementations out there, and surely some of them might actually tie to the hardware of the device you use.
The 2FA algorithm used here on this site does not.
It's called TOTP (Time-based One Time Password) and the input data to generate the current code is nothing but:
A) the secret key, which is included in that QR code you are supposed to scan but also is shown in plain text below it
B) the current time
There is no tracking possible on what device you generated a code.
If an authenticator app that you want to use for 2FA on here requests any more info from you or to sign into something or other BS, I recommend you to dump it and use a different one. The app doesn't need anything but the secret key in order to be able to generate codes for you.
I personally use FreeOTP, which is developed by a large company called Red Hat, but still open source. You can get it for Android and iOS. This app definitely does not ask any more info from you than it actually needs to work.