Gaiscioch Select Chapter
POPULAR ADVENTURES:



ACTIVE ADVENTURES:





ADVENTURES:
Blood of Steel
Ashes of Creation
Stardew Valley
Chrono Odyssey
Throne and Liberty
Albion Online
Guild Wars
Foxhole
Enshrouded
Palworld
Camelot Unchained
- Full List -
CHAPTERS:
Chapter 8:
Conqueror's Blade (2019)
Chapter 7:
New World (2021)
Chapter 6:
World of Warcraft: Classic (2019)
Chapter 5:
Elder Scrolls Online (2014)
Chapter 4:
Guild Wars 2 (2012)
Chapter 3:
RIFT (2011)
Chapter 2:
Warhammer Online (2008)
Chapter 1:
Dark Age of Camelot (2001)
Community
Events
CHARITY:

LEGACY EVENTS:


Search Gaiscioch.com:
137 Tuatha Guilds:
8,449 Members:
13,944 Characters:
11,709 Items:
  • Views: 1,701
  • Replies: 9

GW2 Account Security Beta

Lorgaire de na Capall
Shindakun
Lorgaire de na Capall
  • GW2: shindakun.2748
Posted On: 10/10/2012 at 01:36 PM
  • Steam
  • PSN
  • XBOX
  • Twitter

They've turned on the 2 factor auth beta. Go protect your account now! https://forum-en.guildwars2.com/forum/info/news/Beta-Feature-Mobile-Two-Factor-Authentication

Awards & Achievements
Devotion Rank 20Fellowship Rank 5Scholar Rank 1Artisan Rank 3

Response:

Curadh de na Faolchu
Arowefell
Curadh de na Faolchu
  • GW2: Quigley.9236
Replied On: 10/10/2012 at 05:16 PM PDT
  • Twitch

Good on them for getting this set up. Wish I could take advantage of it.

Awards & Achievements
Devotion Rank 20Valor Rank 3Fellowship Rank 10Explorer Rank 2Scholar Rank 3
Saighdiuir de na Faolchu
WinterBeard
Saighdiuir de na Faolchu
Replied On: 10/11/2012 at 07:20 AM PDT

I was wondering when this was going to happen - I already use authentication tokens for Battle.net, GMail, and various work functions and it was one thing that I really felt was lacking in ArenaNet's security portfolio. I'll wait until it's out of beta, but am super pleased that it's finally being offered. Hopefully they'll offer physical authenticators at some point so those without smartphones can take advantage of this as well.

» Edited on: 2012-10-11 07:20:22

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Scholar Rank 1Artisan Rank 3
Ban Caomhnoir de na Aracos Corcra
Twilah
Ban Caomhnoir de na Aracos Corcra
  • GW2: Twilah.3609
  • ESO: @TwilahSilver
Replied On: 10/11/2012 at 08:08 AM PDT
  • Twitch
  • Twitter

I use the app on my phone for my gmail, and am a bit confused if it will be the same code for my game. So I am hesitant to set this up until I see a bit more explanation.

Awards & Achievements
Devotion Rank 20Valor Rank 11Fellowship Rank 12Explorer Rank 9Scholar Rank 6Artisan Rank 11Social Rank 6
Ridire de na Ulchabhan
Kalec
Ridire de na Ulchabhan
  • ESO: @Kalec-Stromhir
Replied On: 10/11/2012 at 12:01 PM PDT
  • Steam
  • PSN
  • XBOX
  • Twitch
  • Twitch
  • Twitter

The app is tied to the account email used. So each one has there own code on a timer. If your email is the same as for GW2, then the code would be the same. I think... That should not stop you from using it.

Awards & Achievements
Devotion Rank 20Fellowship Rank 11Scholar Rank 3Artisan Rank 1Social Rank 4
Saighdiuir de na Faolchu
WinterBeard
Saighdiuir de na Faolchu
Replied On: 10/11/2012 at 12:04 PM PDT

They're sing the Google authenticator? Huh. I didn't realize Google was letting anyone besides, well...Google use their authenticator. That's strange; I wonder why they didn't choose to implement a solution from RSA directly instead of opting into Google's service. I also use the GMail authenticator on my phone and while I like it for my Google-related security, I'd rather keep my peanut butter and chocolate separate. It'll be interesting to see how this pans out in the coming weeks.

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Scholar Rank 1Artisan Rank 3
Curadh de na Faolchu
Arowefell
Curadh de na Faolchu
  • GW2: Quigley.9236
Replied On: 10/11/2012 at 12:37 PM PDT
  • Twitch

RSA is fantastically expensive, requires a lot of infrastructure, a lot of management, and, frankly, a lot of risk (getting compromised is not something that just goes away, especially when you're the leader in two-factor authentication). Their smartphone app sucks really super bad, and their physical key fobs cost hundreds of dollars each. Google Authenticator, on the other hand, is much less expensive, and is operated as a cloud service - ArenaNet signs up for it, integrates the capability with the game client and their existing authentication infrastructure, and then it's more or less hands-off. Magic Google handles everything, and it just works. This is a little lazy on ArenaNet's part, but it's understandable, I suppose, given that none of us are paying a monthly fee. I really wish they would offer a physical token, though. Then I, and everyone else who doesn't have a iOS, Android, or WP7 smart phone, could protect our accounts too.

Awards & Achievements
Devotion Rank 20Valor Rank 3Fellowship Rank 10Explorer Rank 2Scholar Rank 3
Lorgaire de na Capall
Shindakun
Lorgaire de na Capall
  • GW2: shindakun.2748
Replied On: 10/14/2012 at 09:57 AM PDT
  • Steam
  • PSN
  • XBOX
  • Twitter

Anet had their own Android/iPhone authenticator in alpha stages from what I understand, but the large number of hacked accounts seems to have convinced them they needed to act faster. Its super simple and works great so far, not really sure why they decided to say it was beta. As far as I know anyone can use the authenticator with just a bit of coding knowledge. It can even be added to any website, if you really wanted. Physical tokens may be in the works still, not really sure on that front.

Awards & Achievements
Devotion Rank 20Fellowship Rank 5Scholar Rank 1Artisan Rank 3
Ban Caomhnoir de na Aracos Corcra
Twilah
Ban Caomhnoir de na Aracos Corcra
  • GW2: Twilah.3609
  • ESO: @TwilahSilver
Replied On: 10/14/2012 at 01:59 PM PDT
  • Twitch
  • Twitter

Winterbeard, that's exactly my concern.

Awards & Achievements
Devotion Rank 20Valor Rank 11Fellowship Rank 12Explorer Rank 9Scholar Rank 6Artisan Rank 11Social Rank 6
Saighdiuir de na Faolchu
WinterBeard
Saighdiuir de na Faolchu
Replied On: 10/14/2012 at 02:05 PM PDT

Arowfell, let me preface this by saying that I'm not trying to call you out or devalue your comments, so please don't take this post as a personal affront. I just happen to have differing opinions on this topic than you seem to, and my experience in this arena compels me to point out the flaws in a couple of the things you've said. So, yes. RSA is expensive, but "fantastically expensive" is a bit of hyperbole. I know how much RSA solutions cost, as I've sourced and implemented a number of them for clients; most recently the St. Louis City Circuit Attorney's Office, where security is - as you might imagine - a Very Big Dealâ„¢. Cloud authentication was an option briefly on the table along with Barracuda, but both fell short. I have a very strong suspicion that ArenaNet and their sugardaddy, NCSoft, both have a considerably larger amount of expendable income at their disposal than any of the clients I've worked with, so I wouldn't put too much weight on cost here. As for the benefits of a web-based service over a physical appliance, none of those outweigh the inherent security risks. Given that 2-factor authentication is implemented solely as a security precaution, I'd expect securing the system all the way down the line would be taken into consideration. As you no doubt know, the more avenues of approach you have from the outside world to a system, the more risk is introduced. I'd sooner trust RSA, as a company that hangs its hat solely on security and their continued reputation in that arena, than Google, a company which already has its fingers in far too many pies and has a known history of taking security and privacy a bit too lightly. All of that having been said, please just take this as a contrasting viewpoint for the edification of other people who may be interested in this topic, because at the end of the day that's really all it is. Neither of us has any pull in how ANet chooses to secure its customer accounts. I do agree with you completely that physical token would be best, though, and I still hope it's true that ANet is rolling their own and just using Google's service as a stopgap. I'll just have to wait and see.

» Edited on: 2012-10-14 14:07:26

» Edited on: 2012-10-14 14:08:31

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Scholar Rank 1Artisan Rank 3
[0.1689]