Exploit discovered with Google Authenticator

Exploit discovered with Google Authenticator

in Guild Wars 2 Discussion

Posted by: Milamber.9387

Milamber.9387

Hi there

I don’t wish to post this exploit on here for all to see, but what I have discovered is a major security hole with the authentication that is used when logging into my account with Google Authentication enabled, I just discovered this today. I can bypass the Google Authentication prompt and login.

I have tested this numerous times and I’d like to contact someone from Anet in a forum that is more appropriate than here. I didn’t want to log a ticket since the personnel that deal in that area have proven in the past to reply with templates and this is something that needs viability and attention from someone senior.

Thanks

(edited by Milamber.9387)

Exploit discovered with Google Authenticator

in Guild Wars 2 Discussion

Posted by: Dra Keln.2015

Dra Keln.2015

Are you sure its not a result of the newly added remember network feature?

80 ele
Yaks Bend

Exploit discovered with Google Authenticator

in Guild Wars 2 Discussion

Posted by: Blackwolfe.5649

Blackwolfe.5649

That is correct, there is now a “remember this network” function. Im not sure if its automatic or not but its there.

Colin Johansen casts – Working As Intended
Colin Johansen hits you for 239407889 damage
Game over

Exploit discovered with Google Authenticator

in Guild Wars 2 Discussion

Posted by: Milamber.9387

Milamber.9387

Nope, nothing to do with remembering a network. I can bypass Google Authentication completely and then log in with it or without at my leisure on any PC.

Exploit discovered with Google Authenticator

in Guild Wars 2 Discussion

Posted by: CC Eva.6742

CC Eva.6742

Community Coordinator

Hello everyone.

Milamber, could you please send a report to Customer Support (preferably) or to exploits@arena.net and provide an specific description of this? I will just pass on the info to the team in any case but you should also use the other channels. They are definitely more helpful in this respect than the forums.

Thanks!