of     4   
chevron_rightchevron_rightchevron_right

SubZeroDegree
#189244340Monday, May 16, 2016 8:48 PM GMT

Being on Roblox of a substantial amount of time (almost 4 years), I've noticed that throughout that time there has been no real secure feeling of "safety" with my account. What I mean by this is that there happens to be verification or multi-step logon from another computer or IP address. This can become a huge problem when players can be easily fooled into logging on to a phishing website or just simply clicking a bad link which results in an account being wiped or stolen for a period of time. The average age of people who are on the Roblox website is around 13-14 as stated by a "Kids Tech News" article called "Young Entrepreneur Makes $20K Monthly". It states "Children with an average age of 13-14 are logging in to play these games."; which was written during 2014.(1) Since I believe there has not been a great change in the age difference and range between now and 2014, it is safe to say that the statement is to be still true. So, what's the point of telling you the age of people playing Roblox? Well, at the age of 13-14 kids (or "new teens" if you will) are not fully exposed and have a full grasp and understanding of account safety and/or phishing links. So being of that age, you're going to be a little ignorant towards the fact that your account can be easily stolen through a single string of characters which happens to be your pw. This is not to say that anyone above or below the ages of 13 and 14 aren't as just as prone as to getting their account stolen. Another piece of information that remains to be relevant is, once your account has been taken there is only a few reasons that the person wants to obtain your account. From my experience on the Roblox website they would be the following: 1. To just have you acknowledge they have access to your account 2. To grief and wipe the account, taking everything in its inventory, leaving all the groups, and taking all of its currency 3. To obtain a group or place 4. To just completely take the account and change the pw 5. Get the account banned By reading these reasons it is clear that it can be absolutely devastating to have a simple string known as your pw stolen or tricked into giving out. Also with the new "DevEx" side of the website, you can now almost translate the accounts worth into real life currency and can just imagine how much money you would have lost if you were robbed in real life; roughly 2.50 USD for 1,000 R$.(2) If your account happens to be in the hands of another user of the website and you're unable to access your account or, you're able to access your account but still know that someone else is also on it, the amount of time it takes to reset your pw the offender may have already done what he has intended to and is too late. Once the damage is done it isn't technically final, but as anyone knows an account recovery could happen and it could not. If it does happen and Roblox is able to recover all that you have lost, days, weeks, or even months could have pwed by and that's not even guaranteeing that everything may be recovered. And those things that have been recovered may be rendered useless and irrelevant now with all the time that has been pwed. This is excluding pw recoveries; I'm talking about item/group recoveries. Also, Roblox (no offense to you Roblox if you're reading this), but you don't do a very good job of publicizing item/group recoveries. One way that could possibly prevent and fix or even just improve these problems could be by implementing a multi-step login verification if your account is being logged into by another computer or on another IP address. A couple ideas for some verification steps could be two personal questions that only the holder of the account would know, a notice that would be sent to the holders email and they would then go to that email and click a verification link, a 6 digit code that could be sent to the users phone, an app linked to the users Roblox account made by Roblox only used for verification codes, and an option to trust the computer that you're currently logging on to or not every 30/60 days. Doing this would save a lot of accounts and a lot of stress from the users that own an account with valuable things on it. However, it is still possible for you to keep your account and your account pw safe without Roblox actually adding any of these ideas. But as people get more diverse/unique and clever on ways to steal accounts it would definitely be appreciated by the whole community if Roblox could add some of these ideas. In conclusion I would rather take the extra 2 minutes out of my day to verify that it is actually me logging on to my account from another computer or IP address than to have someone else with unauthorized access to do what they please to my account. And if Roblox would like, I would be more than happy to start up an online petition for them to understand the full gravity of this thread. Citations (1) "Young Entrepreneur Makes $20K Monthly." Kids Tech News. N.p., 03 Nov. 2014. Web. 15 May 2016. (2) "Welcome to the ROBLOX Developer Exchange!" ROBLOX.com. ROBLOX, n.d. Web. 15 May 2016. . PS. I was unable to give the full citations for the first article because of Roblox's policy of "No offsite links" (I would be more than happy to provide the article if needed). Also I hope you can gather that "pw" is the second piece of information you use to login to Roblox with. Please type "Support" if you agree with this. Best Regards, SubZeroDegree
SlightlyEnder
#189244463Monday, May 16, 2016 8:51 PM GMT

needs a tl;dr section also tl;dr but from what I did read, it seems like a good idea. ( ͡°( ͡° ͜ʖ( ͡° ͜ʖ ͡°)ʖ ͡°) ͡°)
hockeychris11
#189244465Monday, May 16, 2016 8:51 PM GMT

support. too bad mods wont ever look at this
Falms
#189244742Monday, May 16, 2016 8:57 PM GMT

support
iamkiller21
#189245133Monday, May 16, 2016 9:05 PM GMT

Support sadly the mods are too lazy to ever look at the post
UltChowsk
#189246349Monday, May 16, 2016 9:28 PM GMT

I support this post on behalf of me, Keystone Studios, and The Global Army.
Dyrrachas
#189246604Monday, May 16, 2016 9:33 PM GMT

support when the leefs fall from the tree, it becomes fact
ErtyyWasHere
#189247685Monday, May 16, 2016 9:51 PM GMT

support
TechnoUser
#189247736Monday, May 16, 2016 9:52 PM GMT

Support, i've tried to email ROBLOX about this and still haven't been given confirmation on this.
TechnoZentuz
#189248109Monday, May 16, 2016 9:58 PM GMT

Support!
Volleybot
#189248122Monday, May 16, 2016 9:59 PM GMT

No support; we've had heaps of these threads before.
TechnoZentuz
#189248158Monday, May 16, 2016 9:59 PM GMT

Haxers suck, all they do is hack accounts for there own will
Flamefox16
#189248304Monday, May 16, 2016 10:02 PM GMT

Support!
SubZeroDegree
#189248346Monday, May 16, 2016 10:02 PM GMT

@2013Henry So because a 'heap' of people want this to happen you don't support it too actually happen... makes sense...
TechnoUser
#189248834Monday, May 16, 2016 10:12 PM GMT

People that don't want this to happen are revealed hackers c:
Warmist
#189249281Monday, May 16, 2016 10:20 PM GMT

Support
Chromal
#189249383Monday, May 16, 2016 10:22 PM GMT

i dont want this to happen i need to hak accountz111111 - angry hakkr aka me jk no ban pls im innocent i swear :)
CPTAndy
#189249403Monday, May 16, 2016 10:22 PM GMT

support
Resolite
#189249547Monday, May 16, 2016 10:25 PM GMT

Support, but I doubt anything will happen.
NightAtlas
#189249632Monday, May 16, 2016 10:26 PM GMT

As a 2011 ROBLOX Veteran myself, I completely agree with you and that "new teens" are not aware of security breaches can be done simply and easily. Great message.
Falms
#189249679Monday, May 16, 2016 10:27 PM GMT

Post this in c&g
Resolite
#189250047Monday, May 16, 2016 10:34 PM GMT

To follow up what I previous said, account phishing has been a problem in ROBLOX ever since I've joined. Since I've joined, literally no steps have been taken to try and reduce the amount of account stealing going on. Anything they have done has been extremely minimal or has been reversed after implementation. ROBLOX do not publicize account protection. For example, when there was a site that could steal your ROBLOX information by just going on it what did we hear from the mods? Nothing. It was up to the users to inform others and try to give support to those that needed it. All in all, ROBLOX's efforts to protect accounts really come across as lazy and a few other words I can't put on here. As a social site for a younger audience, I believe it is their responsibility to introduce kids about how important account protection is. Even little things like quizzes on security with rewards I feel could go a long way, and as long as one person's account is prevented from being stolen the efforts have not been a waste. As someone with an account that has a lot of power in several large groups, I would greatly appreciate it if I could do more to protect my account. Full support. also: sorry for mistakes I'm really tired right now
The_Harbinger
#189250971Monday, May 16, 2016 10:49 PM GMT

Support.
DYNAGUYx
#189251276Monday, May 16, 2016 10:54 PM GMT

Support
DYNAGUYx
#189251326Monday, May 16, 2016 10:55 PM GMT

Support.

    of     4   
chevron_rightchevron_rightchevron_right