|
#1
|
|||
|
|||
Disturbing conversation with GamingClub support
I recently opened the GamingClub software for the first time in ages to see what kind of games they had going nowadays. Unfortunately, I didn't have my account login or password and I couldn't find a forgot-my-password function on the software, so I dialed their US toll-free support phone number off their web site (800-890-3304). A few voice-mail prompts later and I'm chatting with a cheerful Brit (I think.)
I tell him that I would like my login and password e-mailed. He asks if I have my login, I say no. He tells me that he can give me the information over the phone. I say OK. He asks me my first and last name and my address. He then reads me my login and tells me to choose a new password. I choose a new password and log into my account. To be fair, I don't think I have ever funded my GamingClub account, and perhaps there is a different security procedure for accounts with, like, actual money in them. Maybe they checked my caller ID and made sure it matched up with what they have on record. Nevertheless, unless someone can reassure me, I'd be leery to play via GamingClub or any of the Prima sites that allow someone to retrieve their login and set a new password simply with a player's first and last name and address. |
#2
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
Please delete this post or at least delete the part where you explain to everyone how to acquire passwords and logins. (Your post is going to cause more harm than the original security flaw). |
#3
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
It's much better if they correct this poor security than it is to risk bad publicity with the original post.
I now know not to open an account there until this is fixed. |
#4
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
[ QUOTE ]
It's much better if they correct this poor security than it is to risk bad publicity with the original post. I now know not to open an account there until this is fixed. [/ QUOTE ] I'm not concerned about bad publicity, I'm concerned about lurkers seeing this post, and then phishing for accounts using the method described, perhaps accounts of other 2+2'ers (I don't think i have an account at this site myself). |
#5
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
hell im gonna try this, I know all my friends info and he has like $2,500 in his account. I wont play his money of course, just gonna see if it works [img]/images/graemlins/blush.gif[/img]) Is there a transfer funds account thingy there hehehe
PS Thank you to the moron who told me about this hehe |
#6
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
[ QUOTE ]
Please delete this post or at least delete the part where you explain to everyone how to acquire passwords and logins. (Your post is going to cause more harm than the original security flaw). [/ QUOTE ] I think it causes more good than harm, as I'll never ever open a TGC account now |
#7
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
[ QUOTE ]
Please delete this post or at least delete the part where you explain to everyone how to acquire passwords and logins. (Your post is going to cause more harm than the original security flaw). [/ QUOTE ] Security by obscurity is the worst kind. It is important to expose vulnerabilities otherwise they will never be fixed. Though it might be better to question the company directly why they didn't require more proof of identity before posting to a public board. |
#8
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
[ QUOTE ]
Please delete this post or at least delete the part where you explain to everyone how to acquire passwords and logins. (Your post is going to cause more harm than the original security flaw). [/ QUOTE ] Deny. Deny. Deny. |
#9
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
I called code poker last night and also talked to a brit. He seemed to be pissed I could not understand him. I told him to slow down, speak slowly, and I could tell he was unhappy. Between the echo from an overseas call and that I live in Kansas (we dont come across a lot of English accents in Kansas) I could not make heads or tails of what he was saying.
|
#10
|
|||
|
|||
Re: Disturbing conversation with GamingClub support
[ QUOTE ]
Between the echo from an overseas call and that I live in Kansas (we dont come across a lot of English accents in Kansas) I could not make heads or tails of what he was saying. [/ QUOTE ] Damn those English people with their English language with their English accents! The nerve of them abusing our language like that! |
|
|