Hello, everyone!
New Subeta is a platform for a lot of fun changes for the site, such as border cosmetics and better organization across different features, and it has also been a way to increase account security. However, security is always a balance between assurance and usability and the current method is not the answer for both. Given that, Keith is looking into new ways to handle this. Options to pursue include building an authentication protocol provider, which is more secure and cheaper but will involve more time and development, or using an external service which will be require payment but would also require some budgeting from Subeta (not from users)!.
However, Keith is going to able to devote more time to the site and finding the best solution, along with putting together a plan for adding programming assistance. Working on the log-in issues has not fallen by the wayside! It is in active discussion and in progress, and will be covered in more detail as we have it. Thank you!
- - -
Signature art: Original pencilwork by , digital lineart and coloring by
So it gonna turn to a pay site? Or i am miss understanding?
I think that's supposed to be 'an external service would require payment' (by Keith), considering self-building an authentication server is marked as the opposite (' which is more secure and cheaper but will involve more time and development'' - it's cheaper because he can make it himself, it'd just take more effort).
Er, yes, have edited to 'or using an external service which will be more convenient but would also require some budgeting from Subeta (not from users)!' Thank you!
There are no plans for Subeta to become a pay-only site and Keith specifically wants to avoid that route. This is mostly to let people know that we are aware of issues with New Subeta log-ins and are looking at alternatives.
- - -
Signature art: Original pencilwork by , digital lineart and coloring by
Monthly Subscriptions and CSC purchases help with this and other site costs, no need to pay extra!
That's it exactly. We're considering the trade-off carefully, considering the pros and cons; building is more time and effort and users working with the development, whereas buying does require budgeting but may be a smoother user experience overall.
- - -
Signature art: Original pencilwork by , digital lineart and coloring by
Ok. Now it makes sense. I was really worried that Subeta was going to become a pay site for users. Thanks for letting us know what's going on. :)
Thank you for the update. Thank you for taking the time to explore alternatives to the login issues. Hugs!!!
Calendar days are closer than they appear! [item=mocking clock]
thanks for updating this post to clarify it, i read it when it first posted and was very confused, appreciate it!
Is this why I have to constantly have to log out and log back in when playing from my cell phone? So annoying!
It's okay, I have the amogus symbol in my password 👍
Thanks for the info!
RIP Mom, I love & miss you more than you know. Tell Dede hi.
Ocean Conservation Namibia on YouTube... they do good work! https://www.ocnamibia.org
Just wanted to come here and say I really appreciate Keith's continued dedication. I was on Subeta in the early years many years ago before coming back and making this current account. Keith has been such a constant on this site and I think that's awesome. He even shouted me out on my birthday during a live stream once XD
If Keith is looking to add MFA authentication my wishlist would be: time based token (requires users to have a device to run the client) FIDO2 key (requires users to have two physical keys)
There's also: SQRL (requires users to run the client on all their devices) (actually, does’t look viable yet) SMS (requires Subeta to keep personal information it shouldn't otherwise have any business collecting, SMS isn't really secure, not recommended by NIST) Email (requires the least onboarding, but is only as secure as your email is)