1. Account security improvements

    Hi everyone,

    To maintain the security and integrity of accounts, we are modernizing how both web and game logins are handled.

    From Monday, 18 September at 22:00, if you do not already have Email Two-Factor Authentication or Google Two-Factor Authentication and In-game protection enabled, you will be prompted to enter a code when logging in. This code will be sent to the email address that's currently attached to your account.

    The "in-game protection" setting will also be removed.

    Overall, this system will function similar to other services. Once you've entered the required code to log in, you will not be prompted again unless you are connecting from a different location.

    This change affects all accounts and will be a requirement to log in.

    You can review your current email by logging into the website and visiting My Account.
    Emails can also be updated within the Settings page.

    ---------------

    Frequently Asked Questions

    I'm not receiving any emails

    Authentication emails may be slightly delayed during peak times.

    If after a minute you haven't received the code, double check your emails Spam or Junk folders as it may have been filtered there.

    If still no authentication email has been received, we recommend double checking you're logged into the same email as the one displayed within the My Account section of the website. You could also update your accounts email to a new one as your email service provider may have incorrectly labelled the email as spam.


    Invalid code?

    Ensure that you do not close the authentication request when logging in. Simply log in and when greeted with the authentication request, navigate to your email and then copy paste the newly sent code in without closing the request.

    Repeatedly restarting the authentication process will cause the previous code to expire.


    I have lost or forgotten my email and cannot access my account

    Simply email us directly for assistance - [email protected]

    It's helpful if you include anything you recall surrounding the account to assist us in verifying your ownership in a timely fashion. Such information includes but is not limited to:

    - Account or Forum username (not passwords).
    - Current email or a guess if you have forgotten
    - Character information
    - General account history. For example, "I claimed the holiday gift on my Paladin back in 2018, maybe 2019?"
    - Country where you connected or registered from

    You may also include a new email address that you would like your account to be updated to. If we have enough information, we'll be able to update your account immediately without the need for further verification.

    ---------------

    Update #1:

    The system has been re-enabled, the sending of codes should now be instant, regardless of volume.

    We may enable the use of non-gmail emails over the coming days.
    We will also introduce a username changing system, for those that receive a lot of suspicious TFA requests.

    As someone mentioned, this is indeed a forced-2fa change, as with most modern platforms, security is paramount.
    This is a step to bring us in line with other services, reduce our overheads for account compromise support and overall increase account security which is our #1 priority right now with recent compromising waves.

    Regardless of players dislike for the system, It is a step in the right direction. The alternative is 'Bot Network' bans continue due to large target on our back, slower support due to amount of attention given to compromised accounts and restoring as much as possible for the player, following the hot-potato like movement of stolen items, gold, coins, characters between hundreds of accounts and so on.


    Update #2:

    Restrictions on what emails can be used have been lifted, this allows using your desired email provider.
    Restrictions on usage of "." and "+" have also been lifted, allowing the use of the same email through gmail for multiple accounts for example.

  2. many of us don't have email access, and share accounts with brothers, sisters, friends.
    How? You need an email to create the account, and it's also used for any sort of recovery. Not having access to the email you used to register is negligence on your side and that you should fix, not something we should take into account.

    It's a similar case with sharing accounts. We don't support that, and, although not really heavily enforced, it's against our rules for an account to be shared. If you decide to do it anyway, it's on you how you will deal with any updates we implement that might get in the way, not on us to tweak any of it.

  3. Security implementations such as this should be optional and not forced upon the playerbase simply because there are many accounts that lost their email access one way or another and can no longer play after this update.
    IMO its a step-down for warmane players and community.
    It's a minor inconvenience at worst. This is an industry standard. I don't think we'll be apologizing for heightening our community's account security.
    Dyslexia has a point, not sure why it's AI generated, dude has a point man, you are not reading what he says, you force EMAIL PROTECTION, and that's BAD!!! No big company is using EMAIL protection, it's 2-FA + phone number (sim card), like a BANK! So if you wanna have epic protection, do it how banks do it, via phone + 2FA, emails are **** practice 1000%, have you ever been hacked? Email is first thing hacker takes over and monitor, sadly I know. I don't like this new system, prolly it's gonna drop player base even more meh, ****in world sux, non stop crappy updates
    Phone is the default for many people regarding such systems, but email is and has always been an alternative. Going forward, you might see that sort of integration. But for now, email is what we'll be using. Seeing as how you had to use an email to register your account, this shouldn't be an issue.

    You speak about crappy updates, but you know what also gets constantly updated? Methods used to steal your information.

  4. Dyslexia has a point, not sure why it's AI generated, dude has a point man, you are not reading what he says, you force EMAIL PROTECTION, and that's BAD!!! No big company is using EMAIL protection, it's 2-FA + phone number (sim card), like a BANK! So if you wanna have epic protection, do it how banks do it, via phone + 2FA, emails are **** practice 1000%, have you ever been hacked? Email is first thing hacker takes over and monitor, sadly I know. I don't like this new system, prolly it's gonna drop player base even more meh, ****in world sux, non stop crappy updates
    At what point did anyone say we're forcing the use of email? It's simply going to your email if you don't already have it set up, it's not like we can enable 2fa with the app and inject your unique key into your phone or whatever you're using.

  5. Dyslexia has a point, not sure why it's AI generated, dude has a point man, you are not reading what he says, you force EMAIL PROTECTION, and that's BAD!!! No big company is using EMAIL protection, it's 2-FA + phone number (sim card), like a BANK! So if you wanna have epic protection, do it how banks do it, via phone + 2FA, emails are **** practice 1000%, have you ever been hacked? Email is first thing hacker takes over and monitor, sadly I know. I don't like this new system, prolly it's gonna drop player base even more meh, ****in world sux, non stop crappy updates
    Also, "yeah that other guy has a point!"
    The two of you have the exact same IP.
    Imagine using an alt account to agree with yourself.

  6. simply because there are many accounts that lost their email access one way or another and can no longer play after this update.
    Additionally on top of what Mercy stated, that's an user-created issue that these supposed email-less players should have fixed when it happened. We shouldn't and won't base our security decisions on players being imprudent with their registration email like that. It's them who should take the chance as a nudge to correct that mistake.

  7. well then i loose my 2nd account cuz i used a mail that got deleted for inactivity.
    I have lost or forgotten my email and cannot access my account
    Spoiler: Show
    Simply email us directly for assistance - [email protected]

    It's helpful if you include anything you recall surrounding the account to assist us in verifying your ownership in a timely fashion. Such information includes but is not limited to:

    - Account or Forum username
    - Current email or a guess if you have forgotten
    - Character information
    - General account history. For example, "I claimed the holiday gift on my Paladin back in 2018, maybe 2019?"
    - Country where you connected or registered from

    You may also include a new email address that you would like your account to be updated to. If we have enough information, we'll be able to update your account immediately without the need for further verification.
    Someone didn't read.

  8. Oh you already did it... "account sharing" you run AN ILLEGAL PRIVATE SERVER who cares about account sharing,
    It's not "illegal". Also account sharing has been addressed by our TOS since day 1. Additionally, this change has nothing to do with what you consider to be "account sharing".

    you've affect my alt account(s) which i REALLY dont wanna log into emails and verify it, so guess i'll just never donate here again and start fending off new players from wanting to continue their Azeroth adventures with Warmane... Sad too, been here since early 2016...
    If checking your email one time is enough to get you to leave, then I'd argue you weren't very much attached in the first place.

  9. This is going to be really annoying for those who have a dynamic IP address.

  10. This is going to be really annoying for those who have a dynamic IP address.
    While I don't have access to the logs to run the numbers, but if you take out the people using VPNs or other systems to obfuscate their "home" IP address, I'd say that 90-95% of the remaining playerbase's "home IP" stays the same for at least a week. I'd also say around 75-80% stays the same for more than a month.

    If 25% of the players have to check their email once a month to authenticate...and 10% once a week...I don't think that's a major hassle. Not for the added "I still have access to all my accounts" check.

  11. My question is "Why we can only make warmane account with gmail e-mail?"
    You know there are other e-mail providers!
    We made that change a number of years ago because many of the other e-mail providers were unreliable for a number of reasons. Reasons that would include, but not limited to, deletion for inactivity, slow delivery of mails, irregularity of whether an email actually gets received.

  12. Does that mean it will be linked to the web login which would need a code or ingame 2fa would be fully removed?
    I'm not sure where you got those ideas.

    As the original post says if you do not already have Email Two-Factor Authentication or Google Two-Factor Authentication and In-game protection enabled, you will be prompted to enter a code when logging in. (Authentication and In-game protection will be enabled for you)

    The "in-game protection" setting will also be removed. (You won't be able to disable in-game protection)

  13. This FAQ probably should have been included on this thread:

    https://forum.warmane.com/showthread.php?t=325532

    But can anybody confirm whether the Google authenticator app can be used for multiple accounts? I multibox and I'd prefer the app over email, but I don't know if it can work for 5-10 accounts.

  14. This FAQ probably should have been included on this thread:

    https://forum.warmane.com/showthread.php?t=325532

    But can anybody confirm whether the Google authenticator app can be used for multiple accounts? I multibox and I'd prefer the app over email, but I don't know if it can work for 5-10 accounts.
    It does work, I play multibox as well and I'm using the google authenticator inclusively for all my login codes.

  15. Yeaaaa, i have 2 step login in evrywhere i can tho i thought about turning it off here, my wifi changes evry day and evry day i have to log in like from new device, have to do stupid non robot stuff and after this i get a email code to authenticate that last for 3 or 4 secounds and before i open my email i have to wait for new one since this one is old... Instead of logging with password i have to fight 3-4 min evry single day to log in, now players with shifting wifi like me will be forced to fight with it like me, i dont know if its nice
    Switch over to google authenticator instead of email verification, you can get authenticator app on your phone and you can also get authenticator browser extention, with it a code is always instantly available to you.

123 ... Last

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •