We were complaining about two things:
- Random logouts were hugely irritating, and made the next issue worse.
- Turbine had significant security lapses: transmitting account name and password in the clear on every forum login, sharing game credentials with forum credentials, the security breach and the mishandling of player communications afterwards, etc.
In other words, we were complaining about security shortcomings on your side, not about the choices we had for security (or not) on our side. And instead of solving certain of those issues, you've now made the website more obnoxious in the name of "security", and have taken our choices away. What company solves a problem with random logouts by replacing them with
regular, forced logouts on a much shorter interval than the random ones were? Seriously. I just have to *boggle* over that one.
This is not an online banking site. It's a game. If you offer more security, great! But let us choose what level we want. If you were to make us all use 16-character (or longer) "strong" passwords, and change them every 3 months, that would make things more secure. If you were to require that we all use secondary devices to receive one-time authentication codes before each login, we'd be even more secure. But you'd better believe you'd get blasted for both of those, and you'd have it coming.
"Voice of the Customer" is pretty important in a service, and you've been hearing it quite consistently this past week - even from a lot of your biggest fans. If a security feature is obnoxious,
we want a way to opt out of it. So please tell the web team to listen to what their customers are
actually saying, and give us our options back.
Khafar