3 ms·
I worked with someone who was a Blizzard GM around when they rolled this out. Recovering stolen accounts was some absurdly large % of their customer service tic
by profmonocle 3y ago
I worked with someone who was a Blizzard GM around when they rolled this out. Recovering stolen accounts was some absurdly large % of their customer service tickets. People would use the same email & password on WoW as on various shady / insecure sites. Bots would try any stolen credentials en masse in WoW. When they succeeded, not only would customer service need to restore a user's access, they would need to roll back their character to restore lost items and gold.
According to my coworker, adding 2FA was primarily about reducing this customer service workload. Eventually they encouraged it by adding in-game benefits, like additional bag space for your character. Not sure they ever went as far as mandating it.
- Paul-Craft 3y agoSo, what happened after they implemented it? Did CS tickets actually go down a lot? Did it save them a ton of money and hassle? You left off the best part of the story :-) As for mandating it, I could see not requiring people who'd already set up accounts to jump through this extra hoop to play the game. I'm sure even a small percentage might not be able to jump through that hoop. I doubt it's a significant percentage, but I could see it becoming a PR hassle, and those are the worst kinds of hassle from the POV of a technical employee lol... But for a new game? If the CS metrics reflected a big drop relative to the number of people using 2FA, then I'd be sold on requiring it.
- hinkley 3y agoFrom what I understand it went down for a long time, but what people did was if they managed to get into your account the first thing they would do is remove the authenticator. That involved entering a couple sequential values. But if you set up the keylogger right, you could trick users into failing the credential check 3 times at login and get their account.
- jonathanlydall 3y agoAs a former GM, as at the time I left in 2012 I had never encountered a case of a 2FA secured account getting hacked and account compromises were easily >50% of our workload. The problem had become that most players wouldn't add 2FA to their accounts until AFTER they got hacked, so any in-game incentive to add it was in our eyes a good one.
- anonymoushn 3y agoCurrently you cannot customize your group in group finder without 2FA, so you cannot list a group for your friend's keystone or specify what sorts of characters you would like to join. It's quite annoying!
- jonathanlydall 3y agoAs a former Blizzard CS rep (I left in 2012), I can see why they'd do things like this to convince people to add 2FA to their accounts as most people wouldn't do so until AFTER they were hacked for the first time. Based on many players saying to me "I don't know why they chose me", it seems that a lot of people don't realize that account compromising is a drag-net operation, it's like a fish thinking that there's no reason for them to be targeted specifically by a fisher, without realizing that fishing is such a large scale and impersonal activity.
- jonathanlydall 3y agoAs a former GM myself, can confirm all the above.