Security suggestion: separate forum accounts?
The current system is fine imo, the additional step for two-factor authentication only takes me about 10 seconds longer than a simple login. Security by obscurity has never been a good choice. I guess we see a lot of support/community forum hacks because their respective owners seem to think exactly that, “well, it’s just a forum, no need for secure auth”, and the security measures are just not as strict as with the actual product. Better implement a reliable, secure authentication backend (which ANet seems to have done) from the beginning and don’t run into problems at all.
Considering the amount of time it takes them to fix usability bugs with these forums, I hope they put a lot of work in making it secure, which would explain a slow rollout (or they’re just lazy).
Most of the ANet hacks I heard about were because people reused logins from places that had been hacked. I just use KeePass and had it generate new a really strong password, and set up a separate alias email (a bunch of email services let you set up fake emails that redirect to your real email, so there’s no way for hackers to use your fake email to take control of your real email).
It’s terrible that some people resuse insecure passwords, but I don’t know what ANet can do about it.
I believe folks need to be more proactive in their own behalf for security on their accounts. This, more than anything else, helps the company (no matter which one) help keep the consumers’ accounts safer as well.