New security feature for NCsoft master accounts

1 pages Page 1
Isfit
Isfit
Lion's Arch Merchant
#1
http://wiki.guildwars.com/wiki/User:...curity_Feature

Why is NCSoft unable to make it impossible to change the old password without knowing it?
I mean I can log into my master-account and change my GW password w/o knowing my old GW password...
And they keep implementing pointless security measures, which only burden the real person but do not stop hackers at all...

So NCSoft: CHANGE THE PASSWORD SYSTEM INSTEAD OF ADDING ADDITIONAL THINGS NOONE NEEDS!
tasha
tasha
Auctions Mod
#2
I agree with the OP on the old password thing, but I certainly wouldn't call these security methods pointless. They'll be asking you to answer additional security questions the first time you access the Master Account from a new pc to verify its you, and after that you'll be able to log on as normal from that pc. Not only will they force people to know more about your master account before they can successfully access it, but they'll be able to identify the pcs that credit card fraudsters are using regardless of proxy.

Unless of course, their new security measures are rendered optional by lack of flash or use of NoScript (not sure on that one yet, seemed so this morning). Or your information is phished.

Big leap in the correct direction though.
MithranArkanere
MithranArkanere
Underworld Spelunker
#3
The page is now in 'scheduled maintenance'.

I suppose it will be ready after that.
cosyfiep
cosyfiep
are we there yet?
#4

would rather they just put in "old password" instead of putting information on my pc (which has been rebuilt a few times) that I would rather NOT be there ..paranoid YES!

though I have no need of using the ncsoft master account anyways---still wish we could DELETE the link it has to our guild wars account.
FalconDance
FalconDance
Jungle Guide
#5
Have had so much trouble in the past with NCSoft's system that I don't even know what my master password is anymore! All I can hope for is that I never *have* to change my password(s) as the original emails are long non-functional.
Aljasha
Aljasha
Krytan Explorer
#6
While I applaud NCSoft for committing manpower to account security, I'd prefer seeing anything which makes the account, hence your characters, immune to hacking or "cleaning" in a proactive way. The HoM makes it possible to register weapons, armors and all the stuff people care about and being expensive. It would be relatively easy to reproduce your items after a hack and lock characters permanently (so they cannot be deleted).

BTW: I don't think this measurement is good for anything, since once phishing occured, they know your account details (including security answers) anyway.
` Marshmallow
` Marshmallow
Wilds Pathfinder
#7
Quote:
Originally Posted by cosyfiep View Post

--still wish we could DELETE the link it has to our guild wars account.

|: I want to have this option, too.
f
fowlero
Jungle Guide
#8
Personal irony that this happens having just been hacked on the only 2 accounts i have tied to a master account, when the other 2 are fine.

Finally admitting their master account security flaws?
TheGizzy
TheGizzy
Krytan Explorer
#9
Quote:
Originally Posted by tasha View Post
I agree with the OP on the old password thing, but I certainly wouldn't call these security methods pointless. They'll be asking you to answer additional security questions the first time you access the Master Account from a new pc to verify its you, and after that you'll be able to log on as normal from that pc. Not only will they force people to know more about your master account before they can successfully access it, but they'll be able to identify the pcs that credit card fraudsters are using regardless of proxy.

Unless of course, their new security measures are rendered optional by lack of flash or use of NoScript (not sure on that one yet, seemed so this morning). Or your information is phished.

Big leap in the correct direction though.
It asked me for my date of birth.

This does not constitute allowing me "to create additional security questions" for my account.

Now add to this the fact that according to their support FAQ, the first time I logged in from this location it was supposed to prompt me to answer my password hint question.

*crickets chirping*

There are no prompts or instructions on the site, or links, pointing to where I can create these additional security questions.

I'm not impressed.
r
rb.widow
Lion's Arch Merchant
#10
They should do both,

If the site can tell you what computer your at and knows its not you great, but what if a user has say a Trojan on there comp and its being remote accessed, so the site now thinks its you, security breach,

It should ask you a security question regardless, and i agree with the OP it should also ask you for your old Password, such a simple fix,

Of course they could remove the ability to reset your password from the account full stop?
J
JONO51
Wilds Pathfinder
#11
Its as good step, yes, but for the love of god just ask users to input their old pw when they change their game account pw. Its a basic security feature that would ease the minds of so, so many people.
jimbo32
jimbo32
Site Contributor
#12
I guess it's better than nothing so long as it's implemented properly.

One thing they should've done ages ago is to allow you to assign approved IP addresses to your GW account. Most gamers only play from one or two locations anyway (in my experience), so it's not like it'd be a huge pain if you had to wait 48 hours (for instance) when adding a new IP. And it'd prevent RMT's from immediately logging into an account and wiping out everything of value.
AngelWJedi
AngelWJedi
Furnace Stoker
#13
i find it funny they added new stuff. people still get hacked with the other stuff they added what makes them think this would work? when past stuff hasnt worked out.
BenjZee
BenjZee
Forge Runner
#14
Well it might help distinguish those people going around faking that they were banned for no reason and were 'hacked'..meh atleast one step anyway
d
darthlight
Ascalonian Squire
#15
Does anyone know if it is possible to manually unauthorize a location without waiting for the automatic removal after a "long period of time"? [1]
t
thedukesd
Frost Gate Guardian
#17
If it was me doing the new system, you could had login to your master acount without being asked any additional question and only when you wanted to change some important informations (example: the pasword for your gw account) you would had been asked one random chosed question from the additional questions.
TheGizzy
TheGizzy
Krytan Explorer
#18
Quote:
Originally Posted by AngelWJedi View Post
i find it funny they added new stuff. people still get hacked with the other stuff they added what makes them think this would work? when past stuff hasnt worked out.
The majority of people who are hacked are hacked via their own stupidity and greed, not because of any failure on the part of ANet/NCSoft's security measures.

Yes, I find it insane that you do not have to enter your old password correctly in order to change it... that's pretty basic and standard account security everywhere else - and yet, hacking still happens on an incredibly wide scale, even in games or other applications which require the old password.

Here's a tip - most of the time when someone hacks an account, they DO have the old password. This is why ANet/NCSoft doesn't feel requiring it to be entered is going to help matters any.

People are inherently stupid about their internet behaviors... they use the same password everywhere. They use stupid passwords like "password." They use one of these as their passwords. They go bleating their IGNs on forums such as this, or worse, use their IGNs as IDs on sites like this - along with the same password they use everywhere else... and sites like this are easy to hack. Not because of a failure on the part of the site management or site programmers, but because software like vBulletin is inherently chock full of security holes. They let friends/guildies log into their account. They have never learned to comprehend the idea that "if it seems too good to be true, it probably is." They are driven by greed, and will buy into any scam that they think is going to somehow gain them an advantage (beta keys, unique weapons, extra platinum, etc.). They're stupid enough to deal with RMTs. They don't pay attention to the links they're clicking on, will download questionable software, and end up with keyloggers on their system... and they don't have the sense to scan for these things regularly, or to change their passwords regularly, or to have a single dedicated email address for each game they play, etc.

The list goes on...

And of course, when they DO get hacked, they come here and cry about it... and insist that they never did any of those things.

Yes, they did.

IF their account being hacked was a result of an exploit on a site like Guru, there would be hundreds, if not thousands of people all reporting their accounts hacked over a period of days, if not hours.

People get hacked because they are lax about their own security... then they blame everyone else for their problem. It's never them... how often do we see a "damn, I got hacked because I was stupid" post?

Despite that usually being the reason the majority of them were hacked to begin with.

I spend about 10 hours a week of my 40+ hour work week dealing with gamers whose accounts have been hacked or whose credit card info has been phished. The instances where it was truly a failure on the side of the provider, rather than on the side of the client (player), are exceedingly rare.
Ghull Ka
Ghull Ka
Wilds Pathfinder
#19
Came to this thread hoping to see that Gaile was back and has been hired to do security.

I am disappoint.

<3 @ Gaile
AngelWJedi
AngelWJedi
Furnace Stoker
#20
yeah its true a large bunch could have been hacked due to be stupid. but you cant say all are! remember when some people got hacked due to a problem on here? so yeah some people have been hacked havent done stupid stuff as others had.