2-Step Authentication & Security Issues

2-Step Authentication & Security Issues

in Account & Technical Support

Posted by: LoreChief.8391

LoreChief.8391

I don’t have a smart phone, so I can’t use the 2-step authentication app. I’ve got the email authentication for the game account set up, and I have 2-step authentication set up for my email as well. However, I checked my “authorized networks” today (I had previously been hacked a few months ago and deleted all of the authorized networks to start from scratch) and found that there were authorized networks in Idaho, California and Europe. This is a bit of a problem since I haven’t traveled, and I’m in Oregon.

I would also like to bring everyones (including ANets) attention to this thread, http://www.reddit.com/r/Guildwars2/comments/17zt6l/psa_check_your_authorized_networks/

Can we get a desktop app for the 2-step authenticator? And can you stop letting networks from outside my network access my account? I haven’t been hacked that I’m aware of, but it’s pretty bull-kitten to have so many networks that are obviously not mine, being authorized on my account.

Thanks,
-LoreChief

2-Step Authentication & Security Issues

in Account & Technical Support

Posted by: Michael.4791

Michael.4791

There was a time, that Anet authorised itself due to an error. Just remove the “wrong” IPs and you are on the bright side again.

2-Step Authentication & Security Issues

in Account & Technical Support

Posted by: Healix.5819

Healix.5819

Can we get a desktop app for the 2-step authenticator?

As you may already know, the authenticator used is a standard implementation and for mobile devices, Google’s authenticator is used. Since Google’s authenticator is open source, there are many adaptaions of it.

http://en.wikipedia.org/wiki/Google_Authenticator

The HTML5 one for example is very simple, just download and open the html file with your browser.

The reason why desktop authenticators aren’t showcased is because of security. If you allow someone to see your secret key, your authenticator is pointless, since they will also be able to generate the key.