Stop spreading misinformation.
There is no need to tell ms or google you use this site to have MFA.
I was replying to Johnny_Guitars comment that suggested Windows Hello and a Google account in Android as an easy way to get past this hurdle.
Whether you like it or not, those are the immediately available services for people, when looking for a way around the obstacle you decided to put in their way. There are many options, I know, but they are not that easy to configure or use. Chances are that users will say fuck it and leave.
I used my main gmail to register this account on a windows device, I think MS and google knows that I’m on this site without inspecting my passkeys
I am not worried if they know I’m here, worst that can happen is that I get to block out a customised thehandy ad or two.
You are correct that I used the easiest and most convenient way around this imo unnecessary obstacle, and I wanted to share that with people who don’t want to install a lot of third party stuff just to get into ES.
Yeah. I agree in that sense. There are emails from here and various other places in gmail, including order confirmations for several devices. So I’m not under any illusion that it’s a secret.
It’s more about it rubbing people the wrong way, to be faced with putting a porn site url in a tool from these companies that are known to data mine you as much as they can.
Its completely stupid, no way to login w my desktop and I don’t want to get on discord to town hall to NOT change something especially regarding something where some people want maximum privacy. Ill just find scripts somewhere with reasonable security and services I can actually access.
While 2FA is an industry standard I implement professionally to protect critical assets, its application here at EroScripts is, in my opinion, a mismatch. For a niche community, this level of friction is a net negative.
-
User Retention: High-effort authentication creates a barrier that risks thinning an already niche user base. While some of us find it trivial, do we have data on the general tech literacy of our user base to justify this barrier?
-
Over-Engineering: Excessive security for a low-stakes forum is inefficient. It mirrors the trend of fast-food apps demanding 2FA - adding friction that often results in decreased app usage without a proportional increase in risk mitigation.
Given EroScript’s niche status and lack of alternatives, a majority of current users will be forced to adapt. However, the growth of new users may stifle. I know that if I wasn’t here already, no way am I setting up 2FA for what is essentially, a porn forum.
In “The industry” MFA is a base requirement. Not for critical assets. I would be surprised if an insurance provider would even insure someone if MFA was not enforced unilaterally.
I would be interested to hear what threat models you think would be solved by other methods.
While many users we know are technical due to the high number of engineers we have in the forum, I have an expectation of all users to be capable adults. Even if you are not technical there are technical expectations in society. Such as AI literacy, how to use microsoft word, how to do your banking etc.
This makes me think you either don’t work in “The Industry” or you’re ill informed on the security process that all businesses should be taking and why.
Firstly, the forum itself has no expectation to meet a certain level of activity.
Secondly there’s no need for “Increased risk”. MFA is a baseline standard in 2026, and is frankly quickly becoming not enough.
The MFA enforcement was honestly overdue, and what prompted it was a scary wake up call.
This is a net positive. If adults in 2026 don’t know how to use MFA, that’s terrifying. The attack surface to a community, the forum itself and your individual privacy is something I’m aware of and I refuse to let that continue to be unprotected.
This further makes me skeptical you truly understand why MFA is used and what threat models it targets.
The fact that so many people in here are hostile to MFA kind of tells my why so many people get hacked and/or scammed every day.
Some people smoke, some drink alcohol, some use drugs, some are hostile to MFA.
They call it ‘Freedom of responsibility’ or ‘self-responsibility’.
I think accounts that don’t have 2fa should be in a limited state where they can like posts only but can still look at posts and access support. I don’t agree with 2fa there is no guide on a reliable extension that can be used in any browser. If I understand correctly the reason why we are forced to have 2fa now is because someone on here got hacked I don’t see how that’s a liability for the site or a common occurrence. It would make sense for admins/mods to be required to have 2fa but for most users it doesn’t make sense especially if an email otp isn’t an option on this site and as well as a saved failsafe password that can never be changed in case of being hacked. These options would allow people to have more security than normal while not being as annoying and off putting as the forced 2fa that we have now.
Well personally I saw no major announcement about this. There’s still just the Discord Age verification announcement. A heads-up would’ve been nice. Not everyone delves that deep into the forum to keep up with things.
That said, it was fairly easy to add an authenticator extension but it’s another RAM-hog of a browser plugin to add to the mix if you want a fast way to authenticate. I already use long randomly generated unique passwords for every site and keep them in a password manager so I feel this just adds unnecessary friction into the process. The site is already slow to load if you just want to check the newest scripts real quick.
But on the other hand I also understand security concerns but it feels a bit of a overkill for a forum of this kind. Just my 2 cents.
I’m an adult. I’d prefer to make my own decisions.
It was pinned at the top for a full month and was not dismissable.
Fair enough. All I’ve seen has been always that Discord announcement to this day though. I know this because I often accidentally scrolled on that announcement instead of the forum content and it was all about the Discord age verification.
Applying security without context is dogma. I don’t just “apply” 2FA, I model the trade-off between risk mitigation and the net cost of implementation.
A standard engineer treats security as a binary requirement. We teach this to junior engineers because it is safer for their learning. If we tell them it is malleable, they make adjustments without the experience to judge risk. A Principal Engineer or Director treats it as a calculation of capital utilization and risk-adjusted returns. This includes quantifying the dollar value of current growth rates against expected friction.
-
Risk vs. Dogma: If security friction stifles growth, you must calculate if the forum can actually justify the loss in community ROI.
-
Insurance Fallacy: Comparing EroScripts to an insured corporate entity is a false equivalence. Insurance providers require specific security for assets with high liquidity or PII risk. Most forums carry neither, and the liability profiles are not the same.
-
Design Flaw: The “adults should just know” argument ignores fundamental product design. If the friction outweighs the reward, users simply leave.
-
Cost-Benefit: Unilateral 2FA for low-stakes environments is often over-engineering. It is easy to shout “security” at every problem, but much harder to architect for accessibility.
Ultimately, the argument for mandatory 2FA here appears more attached to the dogma of security and the moral high ground of “best practice” than it is to data-driven, context-aware engineering. Decisions at this level should be driven by probability and impact, not just because it is 2026.
“I didn’t read any of the previous threads”
– danielbaker17
Most of these responses have been answered previously in the other threads.
Before posting in here read the other threads.
I read the previous threads and they are entirely correct. You are applying security as dogma because you are dogmatic about it, due to working in a security background.
Unfortunately, whenever someone implies or directly states such to you, you start attacking their background or pretend they haven’t read prior discourse on the topic, as if that invalidates their points. You treat your responses as statements of fact, which is basically a dictionary characteristic of dogmatic.
You’re the admin. You represent this site. Mocking a user with a fake quote because they disagreed with you is not okay. It doesn’t matter how many times the topic has been discussed or how tired you are of the conversation.
I have no obligation to appease anyone.
I am generally polite because it’s the ethical thing to do.
I don’t even think what I did was mock them. I merely pointed out they wasted their time making a point I already answered for.
I read the previous threads and they are entirely correct. You are applying security as dogma because you are dogmatic about it
I’m not dogmatic. I’m well-informed.
Here’s one of the thing I said about the threat model.
I am enforcing it because people wouldn’t use it otherwise. This is a threat because the community trusts each other. I don’t want hackers to abuse that trust by hacking an account and distributing malware. There are other threats but this is the threatmodel I care about right now.
While I think that should be enough here is verbatim what I answered over on this discord:
Just wanted to make a comment to be as crystal clear as I can.
With what happened, it was malware that was an infostealer. It stole session tokens to gain access to accounts that were already authenticated sessions.
MFA would not prevent this form of attack, but it would minimize damage.
If a session token were compromised, we could invalidate it, and MFA would stop the malware from refreshing tokens.
That was the trigger that made me decide to do this. But there are other threat models that warrant MFA anyway and I will admit, not having it for as long as it was was irresponsible.
MFA also makes alt account botting infeasible. We have already had this issue before.
Another thing MFA protects against is low skill phishing.
I’m not going to enforce passkeys but I do recommend them to avoid high skill phishing. I don’t have reason to believe Eroscripts would be a target for reverse proxy phishing but that is an attack vector we are vulnerable to without passkey enforcement.
I don’t appreciate users making accusatory statements that are demonstrably false and making points that have already been answered for. I don’t like making it a habit to type the same thing 100 times. The information is already out there. People need to take responsibility for themselves and read what is already out there.
If there is NEW concerns I’m happy to investigate, resolve, answer for, etc.
I timed it.
It takes me, on average, 4.7 seconds to open ES, use my passkey, unlock my phone, open my authenticator, and type in the temporary PIN. Other forms of MFA are undoubtedly faster.
Seriously, I don’t get the resistance to MFA whenever and wherever it’s implemented.
Not trying to ruffle any feathers, but, you’ll likely spend more time replying to this thread than you will logging into ES during the rest of 2026.