GReaper
Part of the furniture
- Joined
- Dec 22, 2003
- Messages
- 1,984
As [thread=197345]Elkie's thread[/thread] and quite a few others have seen in the past, some account hackers use weaknesses in other email hosts to get a new password generated for the account.
Why does GOA rely on a system to send passwords and other account details by email? All it takes is someone to figure out an easy password for an account, or use a password reset and find an easy question (favourite football team, birthplace), then they've got the email account. Once they've got the email account they can generate new passwords for the DAoC account very easily.
I have no idea how many accounts have been hacked in this way (only GOA will know), it might not even be that many. I know it's not a direct problem with GOA's systems, but relying on the security of email to instantly send password resets and game passwords probably isn't the best idea.
Am I just being paranoid or is this something that GOA should be more concerned about?
Why does GOA rely on a system to send passwords and other account details by email? All it takes is someone to figure out an easy password for an account, or use a password reset and find an easy question (favourite football team, birthplace), then they've got the email account. Once they've got the email account they can generate new passwords for the DAoC account very easily.
I have no idea how many accounts have been hacked in this way (only GOA will know), it might not even be that many. I know it's not a direct problem with GOA's systems, but relying on the security of email to instantly send password resets and game passwords probably isn't the best idea.
Am I just being paranoid or is this something that GOA should be more concerned about?