Forums

Unclear Account Security

Quick find code: 278-279-492-65819749

of 6
Vera

Vera

Posts: 16,253Opal Posts by user Forum Profile RuneMetrics Profile
Did you know...?


1. Did you know that if there's a hijacker on your account, you can boot them off by requesting a password reset, which you can find out how to do here?

2. Did you know that a password reset is NOT a password change, despite the fact you receive an email that says you've requested a "Reset" when you request a password change?

--------------------------------------------------------------------------------------------

I didn't know about the second distinction until recently, and your average Runescaper doesn't even know about the first.

A relatively straightforward and simple way to educate people about such a distinction, and as such their differences, could be to
include a password reset link in the Account center, as well as a brief description of what it does.
This can either be in the "Change Password" section or its own.

This would make salient that:
> A password change is *not* a password reset, because both options exist.
> A password reset is something you can automatically do to boot someone off your account, and to lock it (even to yourself) until you set a new password using the link sent to your registered email.

Renaming password resets to 'automatic recoveries' would also a more intuitive way of describing the process
, if that's not too invasive a change. Dermatologists HATE him!!! Read the below if you're interested in why, though feel free to skip to the bottom because it's a lot. :P
VIVLOVESVIX
(click mee)

Vivaire/Vivy/Vera | Join Nomad! | Inform Yourselves | Forum Help

03-Aug-2016 21:30:42 - Last edited on 03-Aug-2016 22:35:23 by Vera

Vera

Vera

Posts: 16,253Opal Posts by user Forum Profile RuneMetrics Profile
.. Password change vs. Automatic recovery vs. Manual recovery ..

A
password change
is where you go into your account settings, click to send an email to your registered email, and from there click on a link to enter in your new password. It is a simple password change, nothing more.

A
password reset
, or
automatic recovery
, however, is different. As soon as you click on the link in your email, after requesting to reset your password, your account 'automatically' gets locked *and* Authenticator is disabled. All you need to immediately recovery your account is access to your registered email, so you can click on a link to enter in your new password.

A
manual recovery
, or
account recovery
since you can no longer access your account, is similar to an automatic recovery but when you no longer have access to your registered email. You provide evidence of ownership in the recovery form to be manually reviewed by a jmod, and your account does not get locked until the jmod decides to do so. If it does get locked because you've proved ownership, it remains so until you set a new password, via the email sent to the email address listed in the recovery form.

Both a manual recovery *and* an automatic recovery process
start
at the Account Recovery page here. However, in the case of an automatic recovery, you would say 'Yes' I have access to my registered email, but for the manual recovery, 'No' I don't have access to my registered email.

Awareness about password resets/automatic recoveries would also inform people about manual recoveries !

(Please read Salubrious' account security thread here, for how to use these tools if hijacked)
VIVLOVESVIX
(click mee)

Vivaire/Vivy/Vera | Join Nomad! | Inform Yourselves | Forum Help

03-Aug-2016 21:31:03 - Last edited on 04-Aug-2016 03:47:03 by Vera

Vera

Vera

Posts: 16,253Opal Posts by user Forum Profile RuneMetrics Profile
..
Being Confused Doesn't Make You a Noob
..
I speak for a lot of people when I say that the distinction is confusing. Someone posted a thread in Account Help, and said he changed his password but it didn't boot off his hijacker. Only until Malua responded that a password change is not a reset was I made aware of this distinction.

Afterward...I went through a LOT of people trying to understand what the differences were, since there was no Password Reset option in my Account settings. Thank you to
Jeremy C
,
Erehk
, especially
Aurella
, and
Salubrious
for your extensive information and help, particularly here!! Gold stars to each of them. I also learned that both Aurella and Salubrious are rock stars when it comes to account security :)

Note
: "_____ for Dummies" is a popular educational series in the United States. For example, "Dog Training for Dummies" and related results, "Cognitive Behavioural Therapy for Dummies"--learning from these is supposed to be more straightforward and lower effort.
VIVLOVESVIX
(click mee)

Vivaire/Vivy/Vera | Join Nomad! | Inform Yourselves | Forum Help

03-Aug-2016 21:31:12 - Last edited on 04-Aug-2016 15:54:28 by Vera

Aurella

Aurella

Posts: 2,302Mithril Posts by user Forum Profile RuneMetrics Profile
Support! ^_^ Jagex can do a lot to encourage can do a lot to raise awareness about Account Security, hopefully they take this to heart and think on a plan to help others to know these things too :) -
Mod Jed
<3
-

"
your imbued heart has regained its magical power
"

03-Aug-2016 23:16:34 - Last edited on 03-Aug-2016 23:26:22 by Aurella

Aurella

Aurella

Posts: 2,302Mithril Posts by user Forum Profile RuneMetrics Profile
Might want to update your post on automatic recovery! The account lock occurs as soon as the confirmation link is clicked, not as soon as the recovery is requested! Just tested on my dummy account to make sure of this :) -
Mod Jed
<3
-

"
your imbued heart has regained its magical power
"

03-Aug-2016 23:42:21

Vera

Vera

Posts: 16,253Opal Posts by user Forum Profile RuneMetrics Profile
Aurella said:
The account lock occurs as soon as the confirmation link is clicked, not as soon as the recovery is requested!
Thanks for the info!! Major distinction :) (I've edited my post, let me know if there was anything else I missed)

Thank you
Liebster
,
Sal
, and
Aurella
for the support :)
VIVLOVESVIX
(click mee)

Vivaire/Vivy/Vera | Join Nomad! | Inform Yourselves | Forum Help

04-Aug-2016 03:45:55 - Last edited on 04-Aug-2016 05:31:48 by Vera

The contents of this message have been hidden

04-Aug-2016 10:42:11

The contents of this message have been hidden

04-Aug-2016 10:42:33

Quick find code: 278-279-492-65819749Back to Top