The "Change Your Password" Request
If you’re required to change your password, your password is known to hackers. I’m sorry if you disbelieve that, but that is the case. The password may not have been used yet, but to prevent a future compromise, why not just change your password and move on?
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet
I have that message too, and there is no way someone could know the password I am using right now, it’s exclusive for GW2, unless as “Lwd” said “someone breached your defense”. If something like that happens, password change should be forced not recommended.
(edited by NeHoMaR.9812)
Do you mean the meassage on the login prompt “Please consider changing your password”?
I was under the impression everyone was seeing that.
I think the problem is they blacklisted all passwords some time ago, including all recently changed passwords (days before the blacklist creation) that are not in any danger, so a lot of people get the message. The password I am using right now, is not the same I was using at game launch, and not the same I use for Blizzard or email, it’s a completely new one, exclusively created for GW2.
(edited by NeHoMaR.9812)
I will change it just to stop the annoyance.
If you’re required to change your password, your password is known to hackers. I’m sorry if you disbelieve that, but that is the case. The password may not have been used yet, but to prevent a future compromise, why not just change your password and move on?
Because if someone breached your defense – we’ll need to change password in other projects too. I’m not usual user , so my password can’t be known to hackers because of my “mistakes”. Other companies have much stronger defense , than you do (never saw such army of bots anywhere). And to be clear – where did you find such black list? Can I have a link if it’s so easy to get? As far as I know any big company won’t give their user details to anyone and etc…
All I want to see such list to check if my pass really there, or something like: “hackers breached our defense” or “we’ve made this message for everyone, because of security reasons , you can click here to get rid off it”.
Also thanks for answer, as for your last question : I don’t believe in fairy tales – that’s why
If I had a nickel of everyone who said “I’m secure” and then was proved not to be secure, I’d be quite wealthy right now.
Bots do not signify a security breach; they signify the use of stolen credit cards and the creation of accounts, which has nothing with your contention that there is or has been a security breach in our game or on our network. Just consider volume to assure yourself that this is not the case.
The password lists are widely available; feel free to do a few Internet searches to learn more.
The bottom line is that you should do what you desire in relation to your account. We’ll continue to take the best measures possible for our players.
Communications Manager
Guild & Fansite Relations; In-Game Events
ArenaNet
If I had a nickel of everyone who said “I’m secure” and then was proved not to be secure, I’d be quite wealthy right now.
Bots do not signify a security breach; they signify the use of stolen credit cards and the creation of accounts, which has nothing with your contention that there is or has been a security breach in our game or on our network. Just consider volume to assure yourself that this is not the case.
The password lists are widely available; feel free to do a few Internet searches to learn more.
The bottom line is that you should do what you desire in relation to your account. We’ll continue to take the best measures possible for our players.
I understand your position;) “There is nothing that can’t be hacked” ©
Not having scripts for banning 3rd party auto-programs, that’s security related issue in my opinion for such great project.
Just checked most “big” of them, and as I thought my pass is clear. Maybe you have unique list
We can discuss this forever, anyway reason maybe – that my dynamic IP connects me from different location or something else. At least can we, players, have an ability to disable this message without changing password ?:) And please add an ability just to add phone number to account information(not authentication), just in case of someone’ll manage to steal both acc and mail – we’ll have chance to prove our ownership.
Thanks:)
So, for a long time I didn’t have this note asking me to change my password. But that has changed quite recently (around Act I of Halloween Event) and it makes me wonder: was my old password somehow guessed/obtained, ‘tested’ by someone from a suspicious location and then blacklisted, or is there some other reason of it’s appearance?