what is the issue than
Thank you for your fast response. If it is not a break down in your companies security measures although that is arguable. Where is the problem stemming from? Personally i do not use email do not open them and i do not go to web sites or follow links. So how is it feasible to hack that account? Also with the issue that is so obviously present is there any future plan to offer an authentication system?
As we have explained repeatedly, tens of millions of account credentials have been hacked/stolen from other places: games, email accounts, forums, websites, through Trojans and keyloggers, etc. Do a Google search, you’ll be amazed at the highly reputable companies who had have security breaches.
We’re seeing thousands of attempts to use those stolen credentials, and in cases where someone has been foolish enough to use shared credentials — the same password on more than one resource — the RMTs are trying to gain access and, in some cases, succeeding. Example: RMT has username “gamer@fakeemail.com” and a password that Gamer has used on his email account or another game service: “password123.” (Ok, I joke about my examples, but you see my point. ) RMT says, “Let’s try that possible username and password on Guild Wars 2.” And if the user has created his/her GW2 account with those credentials, well, the RMT succeeds in stealing the account.
Please recognize that this is outside our control." However, we are looking at potential new measures to try to reduce their likelihood of success, even while it should be clear that this is not a security issue on our part, but on the part of individual users.
You can read more about this in a blog post that will be published soon, written by ArenaNet President Mike O’Brien.
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet
Uhm, no it isn´t outside of your control.
It´s YOU (ArenaNet) who “cunningly” forced us to use the e-mail address as the login name.
An obviously abundant resource to buy from certain elements on the internetz.
I personally have never encountered such a thing.
As well as the authentication system you came up with, that makes it basically unusable for a good chunk of your customers who have an ISP that gives out dynamic IP-Adrs only.
I’m sorry that you’re unhappy with the system, and that you misunderstand how it works. As for using an email address as a log-in, that’s commonplace across many games and media. If your email is secure, it’s no more a risk than making a “creative” user name. The problem is, people are not keeping their entire security exposure to a minimum and that can impact everything, from games to bank accounts.
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet