Thread Tools Display Modes
12-18-11, 08:46 AM   #1
Xrystal
nUI Maintainer
 
Xrystal's Avatar
Premium Member
AddOn Author - Click to view addons
Join Date: Feb 2006
Posts: 5,892
New Changes to the Automated Account Recovery System

It looks like as recent as 4.3 they added a new step in security ... not great for those of us that log in regularly at different locations ...

Apparently now you are forced to change your password before being able to access any of your account on blizzards website or games. Nice security bonus but .. here's the annoying part ..

Monday - Go home after work after spending the weekend at boyfriends .. Log in to find account locked please change your password now! 30 minutes later playing wow with your new password in place ...
Tuesday to Thursday - Normal process ( hopefully, will see next week I guess )
Friday to Sunday - First time I login at boyfriends with laptop and bam, account locked please change your password ..

Rinse and repeat every week I happen to decide to pop into wow to do some addon stuff which I have been doing recently.

Apparently no option to change it in your account settings .. but I believe my current short lived annoyance will raise its head when I go home Monday and have to do this all over again with a different password.
__________________
  Reply With Quote
12-18-11, 09:16 AM   #2
aapoo
A Deviate Faerie Dragon
AddOn Author - Click to view addons
Join Date: Jan 2008
Posts: 14
the worst part is that this happens even if you're using an authenticator to protect your account.
  Reply With Quote
12-18-11, 09:30 AM   #3
Talyrius
An Onyxian Warder
 
Talyrius's Avatar
AddOn Author - Click to view addons
Join Date: Oct 2008
Posts: 363
This new security feature has been in effect for quite some time now. It happens whenever you try to login from a different geographical location. Usually the locations have to be outside the range of a typical commute.

How many miles/kilometers separate the three locations you mentioned (home, boyfriend's, and work)?

If you continue to access your account from all three locations on a regular basis, the system should learn that connections from those locations aren't out of the ordinary. You should contact Blizzard if the account locking persists.
  Reply With Quote
12-18-11, 10:45 AM   #4
Xrystal
nUI Maintainer
 
Xrystal's Avatar
Premium Member
AddOn Author - Click to view addons
Join Date: Feb 2006
Posts: 5,892
The distance is 30 minutes walk away between my house and his. I logged in at least once here before 4.3 and I would say within the last few months. Last weekend I logged into the website with little problems and the last time I logged into game here as I mentioned above no problems either. Thats why I suspect this part was switched on relatively recent. Although I might have been lucky the last time and didn't get the option appear.

And from about 3 years ago I was playing from a different country every 6 months without any problems. But I expect it was added since then.

But yeah, if its like the repeated authenticator login that starts off frequent and then not so frequent then it shouldn't be too bad. Will have to wait and see. But looking on the forums it seems to be something that started happening in the last week or so as someone posted a message 2 days about it and other people who regularly travel and play have only just hit into this new feature.
__________________

Last edited by Xrystal : 12-18-11 at 10:48 AM.
  Reply With Quote
12-18-11, 12:08 PM   #5
Barjack
A Black Drake
AddOn Author - Click to view addons
Join Date: Apr 2009
Posts: 89
I heard some rumours that Blizzard is able to disable this security feature for your account if you contact them on the phone, but I've not tried so I don't know if it's true.

It annoys me a lot since I often connect over a tunnel, and any time I didn't I'd get locked out of my account exactly as you describe (this is going back at least 6 months as well). So right now I basically have to make sure I always use the tunnel so that Blizzard thinks I live "there" permanently. Thankfully that solution has been pretty stable lately, but at times it wasn't and that was when I definitely thought about contacting them to see if they really could disable it.

I'm guessing people with VPNs and such experience the same problem.
  Reply With Quote
12-18-11, 06:05 PM   #6
Petrah
A Pyroguard Emberseer
 
Petrah's Avatar
AddOn Author - Click to view addons
Join Date: Jan 2008
Posts: 2,988
Originally Posted by ForeverTheGM View Post
This new security feature has been in effect for quite some time now. It happens whenever you try to login from a different geographical location. Usually the locations have to be outside the range of a typical commute.

How many miles/kilometers separate the three locations you mentioned (home, boyfriend's, and work)?

If you continue to access your account from all three locations on a regular basis, the system should learn that connections from those locations aren't out of the ordinary. You should contact Blizzard if the account locking persists.
I went from Tacoma Washington to Chicago Illinois and I never got asked to change my password nor was I locked out of my account. However, I believe this is due to myself and my boyfriend both using Comcast. I've never let him log in to my account, nor I to his. We don't even know one anothers passwords, and we both each have a physical authenticator.

However, after we left his house to go on our vacation, I did get locked out and asked to change my password. While I always stayed at Marriott hotels, they each used different ISP's.
__________________
♪~ ( ) I My Sonos!
AddOn Authors: If your addon spams the chat box with "Addon v8.3.4.5.3 now loaded!", please add an option to disable it!
  Reply With Quote
12-18-11, 09:33 PM   #7
Seerah
Fishing Trainer
 
Seerah's Avatar
WoWInterface Super Mod
Featured
Join Date: Oct 2006
Posts: 10,860
Hubby and I went home to visit over the summer and brought the laptop to play WoW in the hotel. He was locked out of his account, but I was not locked out of mine. We each have an authenticator. /shrug
__________________
"You'd be surprised how many people violate this simple principle every day of their lives and try to fit square pegs into round holes, ignoring the clear reality that Things Are As They Are." -Benjamin Hoff, The Tao of Pooh

  Reply With Quote
12-18-11, 10:26 PM   #8
Flarin
A Frostmaul Preserver
 
Flarin's Avatar
AddOn Author - Click to view addons
Join Date: Mar 2006
Posts: 290
I live in Japan and when I first arrived (6 months or so ago) I didn't notice having any issues. I recently when to China on business and was asked to change the password. Korea as well - so for me it seems I will need to change the password often. It seemed like a simple procedure though - login to Battlenet, change, confirm, blah blah all done back in game within 10 minutes. I think with the authenticator it should be enough. Now, I say that - but I DO change my Battlenet email address every few months now "just in case". I was hacked before without any apparent lack of dilligence on my part - apart from not having an authenticator for 24 hours because it stopped working - and no smartphone at that time - so now I change my email address every few months along with the password. And the password is always something I find relatively easy to type but hard to decipher like j8Huts%Rj or something (of course that is not it, but you get the point) - I never use anything remotely resembling a word, I mix case and add numbers and % symbols.

Gmail is great in that they let you create as many emails as you like - and I NEVER give out the email to anyone but BattleNet - so if I get an email there its just Blizz spam.
__________________

"I will crush and destroy and...ooo...shiny..."

  Reply With Quote
12-19-11, 10:38 AM   #9
Ketho
A Pyroguard Emberseer
 
Ketho's Avatar
AddOn Author - Click to view addons
Join Date: Mar 2010
Posts: 1,026
Originally Posted by Flarin View Post
And the password is always something I find relatively easy to type but hard to decipher like j8Huts%Rj or something (of course that is not it, but you get the point) - I never use anything remotely resembling a word, I mix case and add numbers and % symbols.
What do you mean "relatively easy"?

  Reply With Quote
12-19-11, 01:47 PM   #10
Nibelheim
local roygbi-
 
Nibelheim's Avatar
AddOn Author - Click to view addons
Join Date: Jan 2010
Posts: 1,600
Originally Posted by Ketho View Post
What do you mean "relatively easy"?

*snip*
I'd suspect that sending 1000 password requests to a server per second for the one account would flag that access as suspicious
  Reply With Quote
12-19-11, 04:21 PM   #11
Flarin
A Frostmaul Preserver
 
Flarin's Avatar
AddOn Author - Click to view addons
Join Date: Mar 2006
Posts: 290
What do you mean "relatively easy"?
And you still have to know my email address, which I also change, but point taken - if the server didn't puke on the number of attempts my password has less characters than yours so therefore will take less time. Although when you type passwords like yours into an online account form I bet the system says your password is "weak" and mine is "strong". But if the 1000 tries/second application already takes into account case, numbers and odd characters then it simply comes down to the number of characters.

I am pretty sure though if you are wrong too many times - like 5 or so - you need to go to Battlenet and try again. I am pretty sure when I got hacked it was due to an exploit in a FLASH module on a popular WoW information site that a lot of people got burned with - it somehow put a keylogger on my account and it just so happens when my authenticator was off for that short time they tried my email/pass combo and it worked. If it ever happens again I am out - that was horrible - took over a week to get everything back and I have a lot of characters. Lots of full mailboxes to sort through. Gear with no gems / enchants. It was not nice.
__________________

"I will crush and destroy and...ooo...shiny..."

  Reply With Quote

WoWInterface » General Discussion » General WoW Chat » New Changes to the Automated Account Recovery System

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off