Showing Posts Upvoted By Saraphim.1230:

Well there goes all my hard work good job arena net

in Account & Technical Support

Posted by: Farham.7321

Farham.7321

The problem here is that Arena Net has had the past 5+ years of online gaming experiences to draw from as it pertains to security. There are very easy and common sense controls they could have put in place to massively curtail what is turning out to be a huge embarrassment.

1. Email addresses should never be your logon.

2. Location IP based aware logon protection. If your account suddenly logs on from a new location based on IP you must provide a second security challenge to authorize that location.

3. Optional 2 Factor logons should have been ready from go. An SMS/text cell phone version and a pay key FOB.

4. Any change of password or other account info should require that a verification email or text message code be used before it can be made.

5. Provide a pin or have the user set a pin at account creation(that can not be changed unless the account is verified compromised and returned to the rightful owner) that can be entered on the game support site (along with some other user information) to temporarily “freeze” the users account and automatically start an investigation/open ticket into the comprised account.

And so on and so on. This entire mess is pretty bush league and worrisome from a company that wants access to things like Pay Pal and credit card info to sell you gems.