Full disclaimer, I’m typing this as I’ve been waiting on support to reset my 2FA as I’ve lost control to the device I was using, and I’ve successfully used the “Recovery Code” in the past when changing phones. When I asked how to get a new Recovery Code, support said to me “Use your previous one whenever you want to restore 2FA on your account.”
The Recovery Code doesn’t work anymore, so I have to do an ID verification. I don’t mind doing this, but the wait time is excessive for something that most sites use an automated system for.
For a game that touts itself by the amount of money that flows through it per years, Entropia is woefully lacking in modern security measures. This is especially concerning when you take into account the fact that we still have people that regularly play on non-ESU Windows 10 or even 7/8 in some cases.
Data Breaches are everywhere nowadays. It’s no surprise that almost everyone’s credentials that they use somewhere have been leaked online.
I’ve been checking my email like a hawk because I need to implement 2FA as soon as possible to avoid my account being breached, but I don’t have any time frame as to when they’ll deactivate 2FA on my account. I’d change the password now, but surprise surprise, you need 2FA to change your password…
I understand MA’s hesitation towards using SMS as this game is worldwide and that would require spending money on proprietary systems (along with opening an attack vector to SMS swapping), but there’s some relatively simple solutions that could be implemented.
[SIZE=4]Stealing ideas from other games and platforms that have peer-to-peer economies:[/SIZE]
-If you don’t log into your account for a certain amount of time (think months minimum), a 3-day (adjustable duration) trade lock is imposed on your account. If someone logs into your account after a long period of time, you’re automatically sent an email informing you of such, which gives the account owner time to react to the instance. This feature can obviously be modified/disabled in account settings, but disabling it would trigger a temporary freeze on your account of at least 24 hours, for security reasons.
-Toggle for Logging in that sends a 2fa code to your email. Enter this code to log-in.
-Toggle for “Super Protected” , a version of Protecting items that requires you to wait 24 hours before you can TT it or trade it to another player. Doing this exclusively on the website with a warning message containing multiple “Are you sure?” prompts would prevent players from applying this willy-nilly.
Quite frankly, with all the tools we have nowadays, it’s inexcusable that someone can log back into their account after months-years and find it drained without at least an email informing them that someone’s logged in. Even niche games with 100-1000 players have these features. I understand that the solution is “just use 2FA!” , but the recent temporary errors with 2FA bugging out logins (and my own personal issue of the Recovery code just flat out not working) shows that this system alone is flawed. Simple pre-emptive layers of security would go a long way to stop these instances from happening.