#Add email without requesting password for old accounts
28 messages · Page 1 of 1 (latest)
yeah but as far as the system's concerned your account's still super active right now
of course this probably implies having valid tokens for a self-serve password reset but it still greatly reduces the security of accounts when many tetr.io accounts are used without concern in public spaces such as libraries or schools
something like this may have to stay email request-only
......with that said please email [email protected] regarding account issues such as these 
support won't help with my issue since I do not have an email linked to my account :')
I have been trying to link my account to my email forever now but since I can't remember my password, I can't link it to an email
No password manager?
Well atleast the damage is only an tetrio account. Rip.
doesn't change the fact that [email protected] is for account issues
i'm telling you as a manager of the email we manage those issues lol
this's planned actually
setting an email without having one set will become passwordless in the future as to allow people to claim their account without problems, and facilitate those who enter nonsense then go "wait this game isnt As dogshit as i thought"
well the phishing would involve getting the password you apparently don't know yourself to login in the first place
the important security consideration being you'd need to be already logged in
otherwise there's no phishing involed as you can just do it without knowing any special information lol
kinda just becomes a benign ransom at that point
the catch is
we also plan to require email verification for accounts to be eligible for leaderboards and matchmaking (essentially, to do any real registered features and lift it beyond an anon with a fixed taken name)
so an acc without an email set can't rly be valuable by definition
except for the legacy accounts 
well, legacy accs will also be forced to verify an email to enter MM, and after a while may be hidden too
not planning to grandfather much here outside of edge cases
think you're gonna try and nudge people who've already set bogus email addresses to verify? E.G. [email protected] has well over a hundred associated accounts lol
Why
it shuts up The annoying Warning that Doesn't Mean Anything™️
well ye they'll still be forced to verify to enter MM and enter leaderboards
they'll just need to change email first
speaking of, can't wait for them to complain they lost the password AND set a bogus recovery