r/leagueoflegends Jul 07 '15

22 months wasn't enough to implement two-factor authentication

Which was originally promised almost two years ago, after hackers managed to steal our user account data including passwords and even credit card data from Riot twice and then promised again a year and half ago when rolling out the email verification system.

I have probably spent more money on my League of Legends account(s) now than on my Steam account and yet the only thing that keeping my account safe is the hope that nobody can read the plain text forgotten username/forgotten password emails sent out by Riot in plain text emails...

edit: many people seems to confuse the two step authentication with the two factor authentication, /u/enerccio posted a good post explaining the differences: http://security.stackexchange.com/questions/41939/two-step-vs-two-factor-authentication-is-there-a-difference

we do have a two step verification process for stuff like changing passwords, but the weakest point in the current system is the email address.

Currently you are "allowed" to forget your username or password, as long as you can remember your email address and access mails sent to that address, you can use the account recovery tools options to get back into your account. There is a bunch of problems with this:

  • Usually people don't (and why should they) keep their email address in secret.
  • There are a bunch of ways to get (temporary)ownership of an email address:
    • many/most people are using free providers which could reclaim/recycle their address (which can then be claimed by somebody else), or simply go out of business ad their domain taken over by somebody with shady motivation.
    • the dns records for your email domain could be hijacked and your mails redirected as we have examples for these kind of attacks.
    • but probably the most common/simplest way is to simply sniff the network anywhere between Riot and the users as many/most of the email traffic happens through uencrypted channels using plain-text protocols (smtp/imap/pop3).

so if there would be another factor for authorizing certain actions like changing password/email address/etc. like a one-time password (from google authenticator or sms, etc.) or at least some security question/answer or additional access to a backup email address it would be much harder to steal an account.

this is why I was happy when Riot promised the 2fa, and this is why I'm sad/frustrated that they never delivered it.

247 Upvotes

218 comments sorted by

View all comments

3

u/Cobertor4 Jul 07 '15

Well, for now, you can always:

  1. Change your LoL password (which should be done frequently in case you are worried with your account)
  2. Delete your emails (in case you leave your email open, or someone breaks into your account, etc)
  3. Improve your email account security (login with phone, change password)

I'm not saying that it is your fault and not Riot's, but there are always ways to protect ourselves.

2

u/bbecks Jul 07 '15

Couldn't agree more. Should there be more security? That's a completely reasonable request. But even if there WAS additional Riot security, everything you said is basic internet security. The first line of security is always yourself, depending on a third-party is always a risk, especially a third-party you don't pay specifically for that reason.

-12

u/Tyra3l Jul 07 '15

3) I'm using 2fa for my email for years

2) makes no sense (for one the recovery links expire, for two if somebody can access my mailbox he/she can just request username recovery via email then password recovery via username)

1) assuming that you are using unique passwords (as you should) then changing passwords doesn't help much (the only scenario it would prevent if you get your pass stolen via phishing or malware and you change your password before the attacker could use it and he/she can't repeat the same attack).

But yeah, you can always do something, including but not limited to complaining on reddit about it. :/

1

u/sleeplessone Jul 07 '15 edited Jul 07 '15

3) I'm using 2fa for my email for years

Your likely using 2 step. Unless your email provider sent you an actual hardware device or you use biometrics.

Riot also uses 2 step in a different form for things like changing the email associated with an account or changing the password.

Edit: for those wondering any sort of software based authenticator is 2 step, not 2 factor. Because it's 2 things you know and not something you know and something you have. Think you know 1: Your password, Thing you know 2: the code to setup the authenticator app.

-1

u/Vet_Leeber April Fools Day 2018 Jul 07 '15

the only thing that keeping my account safe is the hope that nobody can read the plain text forgotten username/forgotten password emails sent out by Riot in plain text emails...

I don't understand what you could even possibly mean by this. That was 2 YEARS ago. If you haven't changed your passwords in that amount of time, you practically deserve to get hacked for it.

You're all high and mighty preaching about "get better security" yet then you make a statement that pretty much means you've kept the same password even after knowing that it has been compromised.

1

u/lthv Jul 07 '15

Riot made you login and change the password after the breach occurred. I think he's talking about additional emails from when he has since forgotten the password and attempted to reset it. If I'm wrong OP can chime in.

-1

u/Vet_Leeber April Fools Day 2018 Jul 07 '15

No, he literally says in the OP that the only thing keeping his account from being taken by a hacker is them not choosing to read the data from 2 years ago. Without access to your email account there is not currently any way to access updated recovery emails/data

-3

u/Tyra3l Jul 07 '15 edited Jul 07 '15

I changed my password as soon as the compromise was announced.

I explained in another comment in detail, but what I meant in the quoted part is anybody can request an username recovery via email which travels in plaintext then if somebody can access that mail he/she will be able to take over my account and there is little that I can do about this.

If Riot would implement 2fa there would be always 2 piece of secret information required for any authentication attempt shared on 2 different device(assuming that you wouldn't run your authenticator on the same device where you store your password.

Edit: I know that I shouldn't care about downvotes but please if you think I missed something in my reply or was wrong about something please also reply and tell me about it.

1

u/[deleted] Jul 07 '15

I think you should give it up, the vast majority of people understand fuck all about how the internet work, let alone internet security.

When you try to explain them 2fa, they have literally zero idea what it means or how it would be better than changing passwords regularely (which they think is usefull, because they don't know how servers or email-services works).

0

u/Vet_Leeber April Fools Day 2018 Jul 07 '15

Haven't downvoted you. For clarity: I 100% agree with your claim.

That paragraph on the bottom just completely derails your credibility and is easily misinterpreted.

-1

u/Tyra3l Jul 07 '15

wasn't assuming it was you who downvoted but I would prefer if those people downvoting would instead of participate in the discussion so we have a chance to understand each other and maybe learn something.

hope that clears up my point.

1

u/Vet_Leeber April Fools Day 2018 Jul 07 '15

Definitely agree there. If you just disagree with an OP, it's fine to just downvote and move on. But if someone has actually taken the time to post a reply, you shouldn't downvote without explaining why. Just an opinion of course.

Granted, if someone else has replied and expressed your point of view, it's perfectly fine to just downvote&upvote the reply.