Change email security issue

The worst monsters in the Hearthlands warp the fabric of space and time...

Change email security issue

Postby APXEOLOG » Tue Mar 01, 2016 1:14 pm

So i've decided to restore some of my old accounts and faced this issue.
When you change email, confirmation letter goes to the new email. WTF? What's the point?
You can change password and email if you know only the password, like it was years ago...
W10 Meme Plot | W9 Mantis Garden | W8 Core | W7 Ofir | W6 the City of Dis | W5 Vitterstad | W4 A.D. | W3 Mirniy
jorb wrote:All your characters will be deleted, and I will level every village any one of them were ever members of.
User avatar
APXEOLOG
 
Posts: 1296
Joined: Fri Apr 23, 2010 7:58 am
Location: Somewhere on Earth

Re: Change email security issue

Postby shubla » Tue Mar 01, 2016 1:48 pm

Known issue,
Complained once.
They didnt do anything.
They dont care probably.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Change email security issue

Postby jorb » Tue Mar 01, 2016 2:06 pm

Will look at it.
"The psychological trials of dwellers in the last times will be equal to the physical trials of the martyrs. In order to face these trials we must be living in a different world."

-- Hieromonk Seraphim Rose
User avatar
jorb
 
Posts: 18436
Joined: Fri Apr 03, 2009 7:07 am
Location: Here, there and everywhere.

Re: Change email security issue

Postby loftar » Mon Mar 07, 2016 4:37 am

I generally don't consider the e-mail address to be a security attribute of an account -- if someone has your password, the account is compromised anyway. The reason a confirmation mail goes to the new account is simply to verify that you actually own the account (as is also done when creating an account in the first place).

Conversely, if changing the e-mail address requires verification from the previous e-mail account, then that thwarts the main purpose of being able to change e-mail address on the account, namely to update if you've switched actual e-mail accounts.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Change email security issue

Postby sabinati » Mon Mar 07, 2016 8:35 am

it's supposed to be an alert to the old account with a "no action required unless you did not initiate this" message
User avatar
sabinati
 
Posts: 15513
Joined: Mon Jul 13, 2009 4:25 am
Location: View active topics

Re: Change email security issue

Postby loftar » Tue Mar 08, 2016 2:56 am

sabinati wrote:it's supposed to be an alert to the old account with a "no action required unless you did not initiate this" message

Such a message is indeed sent, though.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Change email security issue

Postby sabinati » Tue Mar 08, 2016 3:13 am

Not according to the OP
User avatar
sabinati
 
Posts: 15513
Joined: Mon Jul 13, 2009 4:25 am
Location: View active topics

Re: Change email security issue

Postby loftar » Tue Mar 08, 2016 4:14 am

There are two mails that are sent when switching e-mail addresses; one verification e-mail to the new address, and one "receipt" e-mail to the previous address. I'm pretty sure what OP was referring to was the verification mail, whereas I assume you're talking about the receipt mail, no?
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Change email security issue

Postby sabinati » Tue Mar 08, 2016 4:33 am

ok, as long as both of them are sent, it should be fine
User avatar
sabinati
 
Posts: 15513
Joined: Mon Jul 13, 2009 4:25 am
Location: View active topics


Return to Bugs

Who is online

Users browsing this forum: Amazon [Bot], Claude [Bot] and 30 guests