http://wiki.guildwars.com/wiki/User:...curity_Feature
Why is NCSoft unable to make it impossible to change the old password without knowing it?
I mean I can log into my master-account and change my GW password w/o knowing my old GW password...
And they keep implementing pointless security measures, which only burden the real person but do not stop hackers at all...
So NCSoft: CHANGE THE PASSWORD SYSTEM INSTEAD OF ADDING ADDITIONAL THINGS NOONE NEEDS!
New security feature for NCsoft master accounts
1 pages • Page 1
I agree with the OP on the old password thing, but I certainly wouldn't call these security methods pointless. They'll be asking you to answer additional security questions the first time you access the Master Account from a new pc to verify its you, and after that you'll be able to log on as normal from that pc. Not only will they force people to know more about your master account before they can successfully access it, but they'll be able to identify the pcs that credit card fraudsters are using regardless of proxy.
Unless of course, their new security measures are rendered optional by lack of flash or use of NoScript (not sure on that one yet, seemed so this morning). Or your information is phished.
Big leap in the correct direction though.
Unless of course, their new security measures are rendered optional by lack of flash or use of NoScript (not sure on that one yet, seemed so this morning). Or your information is phished.
Big leap in the correct direction though.

would rather they just put in "old password" instead of putting information on my pc (which has been rebuilt a few times) that I would rather NOT be there ..paranoid YES!
though I have no need of using the ncsoft master account anyways---still wish we could DELETE the link it has to our guild wars account.
While I applaud NCSoft for committing manpower to account security, I'd prefer seeing anything which makes the account, hence your characters, immune to hacking or "cleaning" in a proactive way. The HoM makes it possible to register weapons, armors and all the stuff people care about and being expensive. It would be relatively easy to reproduce your items after a hack and lock characters permanently (so they cannot be deleted).
BTW: I don't think this measurement is good for anything, since once phishing occured, they know your account details (including security answers) anyway.
BTW: I don't think this measurement is good for anything, since once phishing occured, they know your account details (including security answers) anyway.
f
Quote:
|
I agree with the OP on the old password thing, but I certainly wouldn't call these security methods pointless. They'll be asking you to answer additional security questions the first time you access the Master Account from a new pc to verify its you, and after that you'll be able to log on as normal from that pc. Not only will they force people to know more about your master account before they can successfully access it, but they'll be able to identify the pcs that credit card fraudsters are using regardless of proxy.
Unless of course, their new security measures are rendered optional by lack of flash or use of NoScript (not sure on that one yet, seemed so this morning). Or your information is phished. Big leap in the correct direction though. |
This does not constitute allowing me "to create additional security questions" for my account.
Now add to this the fact that according to their support FAQ, the first time I logged in from this location it was supposed to prompt me to answer my password hint question.
*crickets chirping*
There are no prompts or instructions on the site, or links, pointing to where I can create these additional security questions.
I'm not impressed.
r
They should do both,
If the site can tell you what computer your at and knows its not you great, but what if a user has say a Trojan on there comp and its being remote accessed, so the site now thinks its you, security breach,
It should ask you a security question regardless, and i agree with the OP it should also ask you for your old Password, such a simple fix,
Of course they could remove the ability to reset your password from the account full stop?
If the site can tell you what computer your at and knows its not you great, but what if a user has say a Trojan on there comp and its being remote accessed, so the site now thinks its you, security breach,
It should ask you a security question regardless, and i agree with the OP it should also ask you for your old Password, such a simple fix,
Of course they could remove the ability to reset your password from the account full stop?
J
I guess it's better than nothing so long as it's implemented properly.
One thing they should've done ages ago is to allow you to assign approved IP addresses to your GW account. Most gamers only play from one or two locations anyway (in my experience), so it's not like it'd be a huge pain if you had to wait 48 hours (for instance) when adding a new IP. And it'd prevent RMT's from immediately logging into an account and wiping out everything of value.
One thing they should've done ages ago is to allow you to assign approved IP addresses to your GW account. Most gamers only play from one or two locations anyway (in my experience), so it's not like it'd be a huge pain if you had to wait 48 hours (for instance) when adding a new IP. And it'd prevent RMT's from immediately logging into an account and wiping out everything of value.
d
Does anyone know if it is possible to manually unauthorize a location without waiting for the automatic removal after a "long period of time"? [1]
NCSoft did in fact require you to input your old Guild Wars password in order to change it, but that security feature was deemed unnecessary and subsequently removed.
http://www.guildwarsguru.com/forum/p...urity+password
Martin Kerstein's response in the thread
Gaile Gray's statement
http://www.guildwarsguru.com/forum/p...urity+password
Martin Kerstein's response in the thread
Gaile Gray's statement
t
If it was me doing the new system, you could had login to your master acount without being asked any additional question and only when you wanted to change some important informations (example: the pasword for your gw account) you would had been asked one random chosed question from the additional questions.
Quote:
|
i find it funny they added new stuff. people still get hacked with the other stuff they added what makes them think this would work? when past stuff hasnt worked out.
|
Yes, I find it insane that you do not have to enter your old password correctly in order to change it... that's pretty basic and standard account security everywhere else - and yet, hacking still happens on an incredibly wide scale, even in games or other applications which require the old password.
Here's a tip - most of the time when someone hacks an account, they DO have the old password. This is why ANet/NCSoft doesn't feel requiring it to be entered is going to help matters any.
People are inherently stupid about their internet behaviors... they use the same password everywhere. They use stupid passwords like "password." They use one of these as their passwords. They go bleating their IGNs on forums such as this, or worse, use their IGNs as IDs on sites like this - along with the same password they use everywhere else... and sites like this are easy to hack. Not because of a failure on the part of the site management or site programmers, but because software like vBulletin is inherently chock full of security holes. They let friends/guildies log into their account. They have never learned to comprehend the idea that "if it seems too good to be true, it probably is." They are driven by greed, and will buy into any scam that they think is going to somehow gain them an advantage (beta keys, unique weapons, extra platinum, etc.). They're stupid enough to deal with RMTs. They don't pay attention to the links they're clicking on, will download questionable software, and end up with keyloggers on their system... and they don't have the sense to scan for these things regularly, or to change their passwords regularly, or to have a single dedicated email address for each game they play, etc.
The list goes on...
And of course, when they DO get hacked, they come here and cry about it... and insist that they never did any of those things.
Yes, they did.
IF their account being hacked was a result of an exploit on a site like Guru, there would be hundreds, if not thousands of people all reporting their accounts hacked over a period of days, if not hours.
People get hacked because they are lax about their own security... then they blame everyone else for their problem. It's never them... how often do we see a "damn, I got hacked because I was stupid" post?
Despite that usually being the reason the majority of them were hacked to begin with.
I spend about 10 hours a week of my 40+ hour work week dealing with gamers whose accounts have been hacked or whose credit card info has been phished. The instances where it was truly a failure on the side of the provider, rather than on the side of the client (player), are exceedingly rare.


