Is it too easy to reset the password?

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

Q:

My account was hacked and have just been recovered thanks to the rapid response of the support team. I suspect that my email account is also hacked so that someone now knows quite a lot of information about my account such as the serial code, credit card last four digits, etc.

Now, even if I changed my email address and passwords, I still feel unsafe since resetting my GW2 password only requires my email account, serial code and the name of one of my characters. Certainly, I can’t change my serial code nor my characters’ names. So if the hackers can hack into my email account again then they can reset my GW2 password.

Maybe I get too afraid after being hacked once but I think the system should ask for more secured questions and allow user to set up some security questions. I think security questions are quite common in many games or websites. Or can someone provide me some suggestions about this situation?

Anyway, once again thank you for the immediate help from the support team.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: MikeLewis

MikeLewis

Lead Gameplay Programmer

Next

A:

Account recovery requires us to strike a difficult balance.

We need to ask for information that you know, but only you should know; the easier those questions are to answer, the less secure the recovery process. However, the harder those questions are to answer, the less likely that our players will be able to actually reclaim their own accounts through that mechanism.

Obviously we want to protect accounts as much as possible, but we also have another real concern to manage, which is helping players get back into the game as quickly as possible. Account recovery has been carefully designed to be generally secure (in terms of the questions it asks) while still being effective for as many players as we can help.

The combination of serial code and character name has proven to be a very effective balance for meeting these requirements. Keep in mind that unless you are being very selectively targeted by an attacker, the odds of them knowing your character names and serial code are extremely small. Account recovery is secure in the face of anonymous mass attacks based on stolen password databases and so on.

At some point we have to draw the line. There is no conceivable set of hoops to make you jump through in account recovery that could not be compromised by a suitably dedicated attacker. The fact is that protecting your account is a cooperative effort – we are happy to do everything we can, but there are also steps that individuals need to take to protect themselves.

Securing your email address with a unique password is a good first step. (And I don’t mean just “password123” instead of “password” – something totally unrelated to your other passwords is a good idea.)

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

Add the authenticator to your account for another layer of protection.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

Adding the authenticator wouldn’t help since it can be disabled in exactly the same way as resetting the password.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

With authenticator, they will have to enter the time-based code in order to get into the account first. That means they will not be able to reset your account password.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

I have tried it myself and I can simply disable the authenticator by account recovery.
Account recovery doesn’t require you to login your account (because it is also used when you forgot your password ! ) It only requires email, serial code and one of your characters’ name ! So ridiculously the only protection is my email address password ! Maybe you can try it yourself to see if it works.
https://account.guildwars2.com/recovery
Enter your email, serial code and one of your characters’ name and then click “Disable linked authentication”

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

As far as I know, the serial code is not in the account setting. How would hacker know about your serial code ?

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

Since I purchase GW2 digital version, it sends me an email with the serial code and I didn’t delete it. As mentioned, my email account has probably been hacked since the hacker was even able to change my GW2 account name.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

You need to protect your email account in that case.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Gaile Gray

Previous

Gaile Gray

ArenaNet Communications Manager

I am going to ask our Security Coordinator about this. I understand your concerns, and I think things are more secure than you understand, but I’ll see if he can share some info on this and either he or I will post to get you up to date.

Gaile Gray
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

Another thing you can do is using Gmail’s alias function as mentioned http://support.google.com/mail/bin/answer.py?hl=en&answer=12096

With Gmail, you can even add the authenticator to it. That means, the hacker will have to guess your right gmail with the alias, then they have to have the authenticator to hack into your email.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

Thank you for answering my questions. The gmail authenticator seems useful.
I agree that in general the email, serial code together with character’s name is safe enough. But the key point I want to say is that these three information are unchangable, thus it could be dangerous once they are known to hackers.

In fact, I still couldn’t figure out how the hacker is able to change my email account name. How can I change my email address?

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

How long ago were your account hacked ? There was a period of time we are able to change the login email but it was later disabled since a lot of people’s email were hacked ( I think it was related to a certain fan site being hacked ).

If you wish to change the login email now you will have to have support help you with that.

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

Then it is strange since my account was hacked two days ago…

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Zaken.1806

Zaken.1806

They might have hacked your email first. You said your serial code is in it. They might have reset the password, got your character name and file for support to change your email ?

Is it too easy to reset the password?

in Account & Technical Support

Posted by: Bloody Rhapsody.3810

Bloody Rhapsody.3810

yes..probably…