Email address change should have better confirmation

Thoughts on the further development of Haven & Hearth? Feel free to opine!

Email address change should have better confirmation

Postby Phaen » Wed May 22, 2013 4:38 am

Currently, changing the email of an account requires only the password. This is a problem for people who sometimes like to share characters with their villagemates such as a chieftain alt, crafting alt, or keyalt. Its also a concern for anyone letting another person borrow their account while they are away from the game. Any one of the people with access could change the password and email, claiming it as their own forever.

Perhaps this is meant to be intentionally unsafe, but I suggest giving the account owner more security.
I think the email change should require not just the new email but also the old one, as well as confirmation emails for both.

The way it works currently:
1. Log into havenandhearth.com
2. Enter the new email and current password
3. Press OK, which sends a mail to the new email
4. Log into the new email and confirm by clicking a link

Ideally it would work like this:
1. Log into havenandhearth.com
2. Enter the old email address
3. Enter the new email address
4. Press OK, which sends mails to both
5. Log into the old email and confirm by clicking a link
6. Log into the new email and confirm by clicking a link
7. Go back to havenandhearth.com and confirm the swap

This way even if the account owner is canoodled out of his password, he still has a path to recovering the account in the event of a password change.
Last edited by Phaen on Wed May 22, 2013 5:12 am, edited 1 time in total.
Image
User avatar
Phaen
 
Posts: 995
Joined: Fri Jan 21, 2011 2:17 am

Re: Email address change should have better confirmation

Postby TamaOkina » Wed May 22, 2013 4:50 am

This sounds like a good idea to me.
TamaOkina
 
Posts: 36
Joined: Mon Mar 12, 2012 9:51 am

Re: Email address change should have better confirmation

Postby borka » Wed May 22, 2013 4:51 am

too bad if you don't have access to the old email account anymore

prolly it might be better to ask a control question - the answer is given when account is created and stored in database
Avatar by SacreDoom
Java 8 - manually downloads - good to check for actual versions url here:
viewtopic.php?f=42&t=40331
Remember what the dormouse said: Feed your head Feed your head
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Email address change should have better confirmation

Postby SuperNoob » Wed May 22, 2013 4:54 am

what about a security question when changing things in an account like passwords or email adresses? I never share an account with anyone, but I understand why its done with key alts in villages before idols and CRs are up...
SuperNoob
 
Posts: 521
Joined: Sat May 11, 2013 1:41 am

Re: Email address change should have better confirmation

Postby Phaen » Wed May 22, 2013 5:12 am

And btw... no, I'm not posting this because of a personal loss.
I've never had an account stolen. I've only shared with people I trust and only for a limited time.
Its just something that's been on my mind in light of the events lately.

edit: Not sure what exceptions can be made about lost old email access :s is this a common problem?
Last edited by Phaen on Wed May 22, 2013 5:14 am, edited 2 times in total.
Image
User avatar
Phaen
 
Posts: 995
Joined: Fri Jan 21, 2011 2:17 am

Re: Email address change should have better confirmation

Postby borka » Wed May 22, 2013 5:13 am

for sure a good suggestion
Avatar by SacreDoom
Java 8 - manually downloads - good to check for actual versions url here:
viewtopic.php?f=42&t=40331
Remember what the dormouse said: Feed your head Feed your head
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Email address change should have better confirmation

Postby Arcanist » Wed May 22, 2013 6:08 am

send a link to the old email, either wait for confirmation/cancelation, or wait 48 hours.
User avatar
Arcanist
 
Posts: 2664
Joined: Mon Mar 19, 2012 2:01 pm

Re: Email address change should have better confirmation

Postby LadyV » Wed May 22, 2013 10:35 pm

I agree an extra step of protection would be nice.
User avatar
LadyV
 
Posts: 3114
Joined: Wed Jan 25, 2012 2:34 am

[Announcement About Account Security] Haven/Salem

Postby ramoness » Wed May 29, 2013 6:12 pm

Just a quick thought about account security, wouldn't it be better that email address that you register hnh account with couldn't be changed at all? In that case, no one can actually steal your account? Even if your password is guessed or gained anyhow, you are still able to obtain it back (well, if char is dead or not that does not matter, i'm only looking account-wise).

Or did I maybe miss anything negative here?
User avatar
ramoness
 
Posts: 30
Joined: Sat May 04, 2013 10:01 am

Re: [Announcement About Account Security] Haven/Salem

Postby Oddity » Wed May 29, 2013 10:29 pm

ramoness wrote:Just a quick thought about account security, wouldn't it be better that email address that you register hnh account with couldn't be changed at all? In that case, no one can actually steal your account? Even if your password is guessed or gained anyhow, you are still able to obtain it back (well, if char is dead or not that does not matter, i'm only looking account-wise).

Or did I maybe miss anything negative here?

What if you lose access to the email address?
jadamkaz wrote:ah i remember my run in with odditown they are good ppl im sure the only reason they killed ME is because they are troll hunters and i was a troll
User avatar
Oddity
 
Posts: 1979
Joined: Sun Jun 20, 2010 12:04 am
Location: BC, Canadia

Next

Return to Critique & Ideas

Who is online

Users browsing this forum: No registered users and 33 guests