Requirements for changing of passwords

Status
Not open for further replies.

Kit

Member
Oct 20, 2018
22
19
13
Singapore
SUGGESTION #1: Make changing of passwords not require email verification, but resetting of passwords via "Forgot Password" require email verification.

I am an old player on AriesMS. My account is a few years old, and I signed up using a random email address and birthday. And here's why.
1. AriesMS is a private server.
2. There wasn't a need for email verification during sign up back then. (Not sure about now)
3. Birthday was never used nor required for anything, not that I know of during my years of playing.
4. Seeing as a player for private servers would create many accounts across multiple servers, the need to provide actual data wasn't necessary.
5. Note point #4, again email and birthday wasn't used at all back then for any purpose.

With the sudden need for email verification now, people in my situation have basically lost their accounts. Now note I didn't forget my password, I was forced by the game to change my password because it is too old apparently. Therefore my point is this situation was forced upon me and/or players like myself. Again I have to stress that email and birthday wasn't required for anything back then, and I mean verification nor were we (players when signing up) informed that email and birthday will be used for verification years ago. Therefore seeing as it is a private server, there wouldn't be a reason to provide actual data.

Now I can understand the standpoint of the staff for implementing what was implemented so far, however I feel there should be at least some service/assistance provided for people in my situation rectify our accounts, or to recover it. Hence my other suggestion.

SUGGESTION #2: Even if the first suggestion will not be implemented, maybe help restore old accounts or affected players like myself.

Now this can be done via a 1 on 1 interview of sorts where the player would provide data to proof that they own the account. I know this can be time consuming, but at the moment I have no other ideas on how it can be done any other way (perhaps someone can come up with a better idea). Now again I have to stress, this situation is forced upon us because AriesMS decided to change its so called "laws" when it comes to account management.

Also I have to say that asking for the first 3 characters' IGNs is really difficult. As for myself, my main character is one I created after months of playing the game with many mules on my account. Everyday I login and I am on the third character page, there is a very high chance that I have never even seen my first three characters' IGNs. To get them 100% right is pretty difficult in my opinion. Hence I present my third suggestion.

SUGGESTION #3: Make the methods for account recovery a little more lenient.

I guess I can safely say that the data required for email change right now is very harsh. You are not asking for a player's email and birthday. You are asking the player for the email and birthday they used to sign up, and you are assuming that they would use their REAL email and birthday (on a private server). Now I understand that the website has included on the register page that these will be used for recovery already. However back to my previous point, these weren't made known to players to signed up years ago.

As of now, I can see multiple threads on the support section pertaining to this issue and with no response from the staff members. I hope a better system is being developed and hopefully in time I will be able to recover my account. Even though it is partially my fault that I couldn't remember what email and birthday I used to register, the migration of the previous system to this new system has landed me in this situation, and I might say it has possibly landed many other players in this situation like myself.

Finally I'd like to say that I know some players will think "This person is stupid, its their own fault for forgetting" and I don't agree with that thinking. This is the first game I've played that requires you to do an email verification just for a password change. Now I am all for changing of passwords regularly to keep the account safe, but to do an email verification is a little too much. It can be justified by saying its for security reasons. Fine, but what about the old players who are in the situation like myself? Does the game just forsake us and lose us as players because of their lack of enforcement back in the days when it comes to the accuracy of the data provided during registration?

I think any new systems that are put in place should have backward compatibility whereby no single group of players should be affected by any way possible. Especially when implementing account management rules like these, certain actions should be taken to ensure all players are being taken care of. I've known AriesMS to be one of the most professional private servers to date, and I hope that the staff team can keep it up. As to my issue and my suggestion, if the outcome doesn't come to be in my favor then I guess my time with AriesMS is over unless in the future I get to change my password without an email verification.

With that I end this lengthy suggestion, thank you very much for reading up to this point if you did. Any comments will be welcomed, and I am prepared to be flamed to the deepest part of hell. Also I did not proof read this, please pardon my bad English, grammar and spelling. Have a nice day ~
 

Spyro

Well-known member
Jul 17, 2018
4,869
892
113
Dragon's Cave
There is no requirement for email verification for in-game accounts, only forum accounts. The only usage of email are (1) changing/resetting of password; and (2) resetting of PIC.

Because we only ask for so little information, that making it lax will easily breach account security.

The only reason why we stepped up on security was due to player accounts being hacked (where the cause was not server-sided). We cannot assume that players may register with a false email account and therefore, we should be more forgiving in terms of such modifications.

This mindset will cost you both security and your account, regardless if you are able to recover it or not.
 
Last edited:
Status
Not open for further replies.