• Rusty Raven @aussie.zoneM
    link
    fedilink
    arrow-up
    9
    ·
    1 month ago

    I had a MyGov message yesterday that my account was locked because of too many attempts to sign in. It wasn’t me, so I assume it was a hacking attempt using data leaked from somewhere else. I was able to unlock the account and discovered there is a setting that stops you email or phone being an option for the username, so they shouldn’t be able to try again.

    • tombruzzo@aussie.zone
      cake
      link
      fedilink
      arrow-up
      4
      ·
      1 month ago

      I didn’t even know that was an option. Maybe my mygov account is so old I created it when you could only use a random string of numbers they assigned you. I guess that’s the on upside to an inscrutable, completely unrelated username

      • Rusty Raven @aussie.zoneM
        link
        fedilink
        arrow-up
        3
        ·
        1 month ago

        That’s the username I use, but the email is in the settings as an alternative option. I presume someone had a list and was trying all my known passwords with the email - it wouldn’t get them in (I use unique random passwords for everything of any importance) but trying over and over gets me locked out. It might be worth checking your settings to see if it is enabled.

    • Duenan@aussie.zone
      link
      fedilink
      arrow-up
      3
      ·
      1 month ago

      I had that recently too a couple of weeks ago and it locked my account and I turned off being able to use my email as a login for it.

      Was a royal pain in the butt.

    • Pilk@aussie.zone
      link
      fedilink
      arrow-up
      3
      ·
      1 month ago

      Ooh, I didn’t know about that setting. Had the same too many attempts thing recently so I’ve turned those off too. Thanks.

    • Baku@aussie.zone
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      I didn’t even know you could get usernames, I’ve only ever signed in through email. Happen to know where I could find my username by chance?

      • dumblederp@aussie.zone
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        1 month ago

        There’s an option to have them email the username to you. I did it recently and it’s all in the same area of mygov security settings. Worth it because if your mygov gets breached I’ve heard they force you to make a new one.

        • Rusty Raven @aussie.zoneM
          link
          fedilink
          arrow-up
          2
          ·
          1 month ago

          It also displayed the username in the same place in settings as the option to remove the email and phone number as login options.

          From what I read if you are forced to make a new login you also can’t reuse the same email address without phoning up and doing something to release it. Just unlocking it from the temporary lock I needed the correct password, answer to a secret question plus an SMS code which was stilll a bit of a nuisance.