Hi guys, I have a real big issue I need to bring up about security.
I was recently hacked; It's being reported and dealt with, yadda, yadda, yadda.
However, this brought a very big security flaw to light: Gaia does not alert users when it comes to changing their emails attached to their accounts.
It's so simple for a hacker: First go in and change the account's attached email with the password they've already acquired. Then they change the password and the real owner is locked out of their account, leaving the hacker time to do as they please while the owner scrambles to get their accounts to a mod's attention.
It's like a burglar enters your house, changes the locks, and leaves you watching through the front window while they pilfer your living room.
It could be as simple as requiring a user to first verify the change from the first account to the second, even though this might leave some users with dead emails in a spot of trouble.
However, Narumi Mitsuhara, who came by
my threadin the Site Feedback proposed:
Narumi Misuhara
This is a good idea... and I'm a bit surprised myself that the process is so easy.
sweatdrop
I don't know about making it so that users
have to verify through both emails since depending on why the email is being changed could leave some users out in the cold. However sending an email to the old address with a message that says something like "Hello <username> we noticed you have changed your email address to <new address>. An email has been sent to this address for verification. ...Did you not do this? Click Here." Clicking the link within maybe a couple of days would disable the accounts trading pass, reset the account password (with an email being sent to the old address to allow for new password creation), and auto-flag the account for moderator investigation.
This would allow the user to reset the password, log in, look over the account and see if anything is missing/wrong. The downside is even if the account is ok, you'd need to wait until a mod could get to it, investigate, and enable the trading pass again. Upside all items there since the link was clicked would still be there.
Sadly I doubt this is something my team would have time to work on but for sure bring it up in ATA.
You guys warned us back in 2008 to make sure our emails were current because you were going to implement security measures to make it harder for our accounts to be compromised. You guys never followed through.
Please, I understand if the developers schedules are full, but please, consider implementing a simple security step like this and putting it on your schedule for the future.