Whats this new security check ? I need to confirm some pictures suddenly?
'); document.write(''); var yuipath = 'clientscript/yui'; var yuicombopath = ''; var remoteyui = false; } else // Load Rest of YUI remotely (where possible) { var yuipath = 'https://ajax.googleapis.com/ajax/libs/yui/2.9.0/build'; var yuicombopath = ''; var remoteyui = true; if (!yuicombopath) { document.write(''); } } var SESSIONURL = ""; var SECURITYTOKEN = "guest"; var IMGDIR_MISC = "warmane/misc"; var IMGDIR_BUTTON = "warmane/buttons"; var vb_disable_ajax = parseInt("0", 10); var SIMPLEVERSION = "422"; var BBURL = "https://forum.warmane.com"; var LOGGEDIN = 0 > 0 ? true : false; var THIS_SCRIPT = "showthread"; var RELPATH = "showthread.php?t=350967"; var PATHS = { forum : "", cms : "", blog : "" }; var AJAXBASEURL = "https://forum.warmane.com/"; var CoTTooltips = { rename: true, icons: false, iconsize: 15, qualitycolor: true, overridecolor: { spells: '#839309', items: '', npcs: '#fff', objects: '#fff', quests: '#ffb100', achievements: '#fff' } }; // -->
Whats this new security check ? I need to confirm some pictures suddenly?
We have moved away from our own captcha system in favor of the new "invisible" recaptcha system.
This is invoked on all things account-access or account-retrieval now, for example the captcha would only come up if you failed one login previously, it is every login now, regardless of fails or successes, to further prevent bots or bruteforcing.
On top of that, we now check for two factor authentication and the date two factor authentication was added on every item trade addition, character trade addition and sending gifts.
Due to the amount of account compromising going on, leaked databases, people buying gold / using 3rd party websites and being scammed/phished, we now require that players have TFA enabled for atleast 3 days before allowing them to use such services.
Lastly, we have updated our policies to reflect assistance provided for those with TFA enabled/disabled, or "half enabled", support is becoming very limited if players are not proactively protecting their information or accounts.
For those of us with dynamic IPs, a two factor authorization setup that requires us to check our email and enter a code every time we log onto the game is pretty much unworkable. So I hope you'll reconsider this policy.