Sources: Authenticators May Become Mandatory

According to WoW.com, "trusted sources close to the situation" have stated that Blizzard is giving serious consideration to making authenticators mandatory for all players. The sources say that details have not been finalized, but it's a "virtually forgone conclusion that it will happen."

This news should be considered a rumor until Blizzard makes an official announcement, but it would make sense following the addition of the Core Hound Pup pet. What do you think? Should authenticators be mandatory? Do you already have one?

Comments

Post CommentRoot Thread
Please make these mandatory!
# Jan 08 2010 at 1:57 PM Rating: Default
15 posts
This really SHOULD be mandatory. Blizzard makes NO money on the Authenticators. That's why the App for your iTouch/iPhone is free. To get it on your other phones, it simply costs $1. And, the Authenticator Key-Chain costs $6.50. Why? Because they get those through another company. They obviously need to pay that company for all the materials and labor that they did. Especially now that the shipping is free. And you get persuaded with a pet. Which is nothing but a good thing.

The funny thing is... once someone gets hacked, the next thing they do is get an authenticator. And Blizzard is so swamped it takes 1-2 weeks just to get your stuff back. How about that. 1.5 weeks of WoW having naked characters.
____________________________
SIGNATURE: http://sig.gamerdna.com/quizzes/INFLU_zam/cralor.png
Please make these mandatory!
# Jan 08 2010 at 3:28 PM Rating: Good
4 posts
Current keyloggers can grab the WoW authenticator code in real-time while delaying YOUR login, to give the remote attacker time to log in before you do.

http://it.slashdot.org/story/09/08/23/2015208/Real-Time-Keyloggers

So these will just advance the arms race between users and account thieves another notch.

A better solution would be to record the IP address you last logged in from, and throw an alert if the current IP is from another ISP.
Unless the user has explicitly set the option otherwise, refuse more than a small number of trades or mailings of gear & gold per day in that case.

A possibility:
If logging off showed you a very unique image, would you remember that image when logging in the next time?
Mismatch would lock account until you replied to an email from them.
The first attempt to crack your account would fail due to giving wrong image as last one seen.
Successful crack would require your email account to be cracked as well.
If you try to log in and get notice to check your email, you know your PC is probably infected.
If you forget the last image, you just have to wait on the email to log in.
Post Comment

Free account required to post

You must log in or create an account to post messages.