#More Account Security options

28 messages · Page 1 of 1 (latest)

fading bloom
#

I think its about time you did a full rework of the runescape account security options. For example, if your email is compromised, they can remove authenticator, change password, change registered email with no limitations.

Some suggestions:

  1. record more identifiable information, name, dob, address
  2. security questions
  3. registered mobile / cell phone numbers with single use sms codes.

And then for any critical account security changes, require a COMBINATION of the above, not just 1 of them before allowing any account changes to be made.

Multiple other games, services, platforms already do this, why doesnt Jagex?

novel sundial
#

💯

topaz smelt
#

Genuinely, if they start demanding 2fa, my cell phone number, my real name/address or that I actually set a bank pin i'm quitting.

reef sparrow
#

Security questions are a terrible form of account security. The best thing to add is u2f support so we can use something like a yubikey with the account.

#

The important thing is that if you enable Authenticator on your account, no one should be able to disable it with just your email. This is a hard problem to solve at scale because any added security comes with the risk of people being locked out of their own account so you need to strike a balance between making accounts easy to recover which can lead to accounts being compromised and making them hard to recover which can lock people out if they get a new phone without transferring the authenticatior codes to it

meager current
#

Tbh its almost impossible to have a compromised email in current days

#

Sms validation for every login ez.

reef sparrow
#

SMS is a lot easier to compromise than email

meager current
#

Sms validation ? Not really lol what are you tlaking about ?

reef sparrow
#

Many instances of people going into a mobile carrier store and saying "I lost my phone and need a new SIM" and the person who works there not properly verifying before giving them one

meager current
#

To get my phone number you really gonna have to go thru many different step with my carrier

reef sparrow
#

Varies by carrier and some have gotten better in response

#

But I know computer security people who won't trust SMS auth for sensitive/critical stuff

meager current
#

I think you under estimate how hard it is and your opinion is based on very litle % of the population

reef sparrow
#

It's only really relevant if you're targeted, not as a broad attack, true

unreal kiln
#

Yeah I mean it does happen to people but not nearly on the scale of compromised email accounts

meager current
#

As a matter of fact im working for one of the main carrier, ive heard case of id theif that ordered cell phone. Never, and ill repeat that. I NEVER saw or heard a case of someone phone being xfered to another sim by someone else

#

Been working there for 15yr btw.

reef sparrow
meager current
#

Like if that ever happen its not their rs account that is at risk

#

Its their whole bank account

reef sparrow
#

Usually true, I'm thinking more in the context of high profile streamers/YouTubers rather than the average user

meager current
#

Cause to get thru a sim swap you need ids, you need personal info.

reef sparrow
#

There are definitely people who would deliberately target and compromise their RS account for shits and giggles

meager current
#

That to some extens if they do that to get hang of a rs account they also go thru id tief which is a serious offense in many country/ state

reef sparrow
#

Anyway my point was that my email is more secure than my phone number because I use yubikey/u2f for second factor which is pretty foolproof as far as things go today. I'm not the only one but probably not in the majority

meager current
#

I think theres a bit of paranoïa mix with that

#

2fa with sms is more than enough