MAJOR security breach after Wolfhunter DLC

SiegeMerchant
SiegeMerchant
✭✭✭
you dont need access code anymore
you can login from any account to any new PC/IP and game will not ask you about access code
tested many times with few accounts and friends

i think its major issue because alot account will be easily stolen...

P.S. confirm in comments guys if you experience the same
Edited by SiegeMerchant on August 15, 2018 7:57PM
  • DuskMarine
    DuskMarine
    ✭✭✭✭✭
    you dont need access code anymore
    you can login from any account to any new PC/IP and game will not ask you about access code
    tested many times with few accounts and friends

    i think its major issue because alot account will be easily stolen...

    oh lord yea this is a huge issue. @ZOS_GinaBruno @ZOS_JessicaFolsom this is a giant problem that needs fix asap above all else. security should be priority 1 why was this taken out?
    Edited by DuskMarine on August 15, 2018 6:51PM
  • Raraaku
    Raraaku
    ✭✭✭✭
    What exactly do you mean when you say access code? If we're talking about login/account passwords then yes, that is worrisome. I don't follow you, I apologize if I'm wrong, but I'm guessing English is not your native language?

    Could you elaborate further?

    Also, if it's a serious security flaw/breach directly contacting customer support and/or direct e-mail with evidence (screenshots) and a detailed explanation of the vulnerability would be a much better route to go rather than a semi-cryptic public message on an official forum where anyone can read.
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • DuskMarine
    DuskMarine
    ✭✭✭✭✭
    Raraaku wrote: »
    What exactly do you mean when you say access code? If we're talking about login/account passwords then yes, that is worrisome. I don't follow you, I apologize if I'm wrong, but I'm guessing English is not your native language?

    Could you elaborate further?

    Also, if it's a serious security flaw/breach directly contacting customer support and/or direct e-mail with evidence (screenshots) and a detailed explanation of the vulnerability would be a much better route to go rather than a semi-cryptic public message on an official forum where anyone can read.

    if someone attempts to log into your account on another computer you have to confirm whether its you or not through a email. this stopped people who just guessed your password from getting into your account by confirming if its you or not.
  • SiegeMerchant
    SiegeMerchant
    ✭✭✭
    obvioisly im talking about only one access code game asked you when you login from new place/hardware
    its not working after new dlc - you just can login now without this extra security check
    smthing is very wrong
  • BuddyAces
    BuddyAces
    ✭✭✭✭✭
    If someone gets your password and tries to login from their comp, an access code is emailed to you. Entering the code allows you to log into your account from a new comp.

    He's saying there's no more access code. You can log into any account on any comp.
    They nerfed magsorcs so hard stamsorcs felt it,lol - Somber97866

    I'm blown away by the utter stupidity I see here on the daily. - Wrekkedd
  • essi2
    essi2
    ✭✭✭✭✭
    ✭✭
    @Raraaku The Access Code is ESOs two-factor system, it sends a code to your email (very slowly!) when it detects you are logging in from a 'New' device.
    "The Heritance are racists yes? Idiots. But dangerous, destabilizing racist idiots." - Razum-dar

    "Wood Elves aren't made of wood, Sea Elves aren't made of water. M'aiq still wonders about High Elves" - M'aiq the Liar

    ** Leyawiin Layabouts (PC-EU) - Leyawiin Layabouts (PC-NA) **

    *** https://www.youtube.com/@essi2 - https://www.twitch.tv/essi2 ***
  • Sovjet
    Sovjet
    ✭✭✭
    you dont need access code anymore
    you can login from any account to any new PC/IP and game will not ask you about access code
    tested many times with few accounts and friends

    i think its major issue because alot account will be easily stolen...

    I'm on vacation atm, and every time I login I use a VPN, thus a different IP when I restart the laptop. And every time I got a email with a access code.
    For every player that quits, more will join in my name - Molag Bal 2E 583
  • SiegeMerchant
    SiegeMerchant
    ✭✭✭
    Sovjet wrote: »
    you dont need access code anymore
    you can login from any account to any new PC/IP and game will not ask you about access code
    tested many times with few accounts and friends

    i think its major issue because alot account will be easily stolen...

    I'm on vacation atm, and every time I login I use a VPN, thus a different IP when I restart the laptop. And every time I got a email with a access code.

    and when was your last login attempt with access code? my bet before Wolfhunter
  • Raraaku
    Raraaku
    ✭✭✭✭
    essi2 wrote: »
    @Raraaku The Access Code is ESOs two-factor system, it sends a code to your email (very slowly!) when it detects you are logging in from a 'New' device.

    That's what I was thinking.

    Has anyone tried to reset their two-factor and see if it works afterwards? It could be something overlooked during maintenance, particularly account/crown store maintenance.
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • SiegeMerchant
    SiegeMerchant
    ✭✭✭
    easiest way to reset two-factor imho - swap your RAM sticks
  • Raraaku
    Raraaku
    ✭✭✭✭
    Sovjet wrote: »
    you dont need access code anymore
    you can login from any account to any new PC/IP and game will not ask you about access code
    tested many times with few accounts and friends

    i think its major issue because alot account will be easily stolen...

    I'm on vacation atm, and every time I login I use a VPN, thus a different IP when I restart the laptop. And every time I got a email with a access code.

    and when was your last login attempt with access code? my bet before Wolfhunter

    I'm guess since he is currently on vacation right now chances are he's signed in since DLC dropped, and he's still obtaining the two-factor authentication code.

    I could be wrong though.
    Edited by Raraaku on August 15, 2018 7:03PM
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • Raraaku
    Raraaku
    ✭✭✭✭
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...
    Edited by Raraaku on August 15, 2018 7:08PM
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • SiegeMerchant
    SiegeMerchant
    ✭✭✭
    Raraaku wrote: »
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...

    PC NA or EU?
  • OrdoHermetica
    OrdoHermetica
    ✭✭✭✭✭
    Raraaku wrote: »
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...

    Or just unplug your monitor's power cable and then plug it back in. Seriously - it's super sensitive about hardware changes.
    Edited by OrdoHermetica on August 15, 2018 7:40PM
  • Raraaku
    Raraaku
    ✭✭✭✭
    Raraaku wrote: »
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...

    PC NA or EU?

    Website and PC NA. I don't believe it matters what servers you're logging into since the two-factor authentication is tied to your account and any device your account is attempting to login from rather than the client/server it's trying to access. Any time it detects the account trying to login from a different/unknown source it should trigger the two-factor authentication; not what particular server you're trying to use.

    Basically, if it's broken, it shouldn't be only localized to a particular server such as NA/EU/Website. It should either recognize the attempt from any server it's trying to access or none of them.
    Edited by Raraaku on August 15, 2018 7:44PM
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • SiegeMerchant
    SiegeMerchant
    ✭✭✭
    Raraaku wrote: »
    Raraaku wrote: »
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...

    PC NA or EU?

    Website and PC NA. I don't believe it matters what servers you're logging into since the two-factor authentication is tied to your account and any device your account is attempting to login from rather than the client/server it's trying to access. Any time it detects the account trying to login from a different/unknown source it should trigger the two-factor authentication; not what particular server you're trying to use.

    Basically, if it's broken, it shouldn't be only localized to a particular server such as NA/EU/Website. It should either recognize the attempt from any server it's trying to access or none of them.
    website
    it explain everything
    website codes is DIFFERENT
    they coming with small letters and space

    try ingame codes
  • Sheezabeast
    Sheezabeast
    ✭✭✭✭✭
    ✭✭✭✭✭
    Yikes....
    Grand Master Crafter, Beta baby who grew with the game. PC/NA. @Sheezabeast if you have crafting needs!
  • cheops
    cheops
    ✭✭✭
    I've always found this to be a bit hit and miss anyway. I often log in using previously unseen hotel wifi and by cellular means and get no prompt to enter the code.
  • Raraaku
    Raraaku
    ✭✭✭✭
    Raraaku wrote: »
    Raraaku wrote: »
    I just tested, and my two-factor authentication is working, prompts me for the authentication code.
    easiest way to reset two-factor imho - swap your RAM sticks

    Or just clear your caches...

    PC NA or EU?

    Website and PC NA. I don't believe it matters what servers you're logging into since the two-factor authentication is tied to your account and any device your account is attempting to login from rather than the client/server it's trying to access. Any time it detects the account trying to login from a different/unknown source it should trigger the two-factor authentication; not what particular server you're trying to use.

    Basically, if it's broken, it shouldn't be only localized to a particular server such as NA/EU/Website. It should either recognize the attempt from any server it's trying to access or none of them.
    website
    it explain everything
    website codes is DIFFERENT
    they coming with small letters and space

    try ingame codes

    I've already stated I've tested both.
    Back from a much needed break. || I like having too many projects and working on them all at once.

    Tank Enthusiast || CP: 445 || Stormproof

    Tanks
    Karsaak gro-Ursa: DC || Orc || Stamina Dragonknight || Tank || Level: CP 445
    Sir Leopold Stotch: DC || Breton || Magicka Templar || Tank || Level: 445
    Protects-Squishy-Ones: EP || Argonian || Magicka Sorcerer || Tank/CC || Level: CP 445
    Björn Shadow-Walker: EP || Nord || Stamina Nightblade || Tank || Level: 15
    Tiberius Valerion: AD || Imperial || Stamina Warden || Tank || Level: 15

    Damage Dealers
    Morrigan Ravyn-Cloak: AD || Altmer || Magicka Nightblade || DPS || Level: CP 445
    Ra'Zahkara: AD || Khajiit || Stamina Dragonknight || DPS || Level: CP 445
    Ezra al-Khazir: DC || Redguard || Stamina Templar || DPS || Level: 40
    Erryndril Telvaux: EP || Dunmer || Magicka Dragonknight || DPS || Level: 25
    Uzara gra-Khalari: DC || Orc || Stamina Nightblade || DPS [2H/DW] || Level: 15
    Solomon Motierre: DC || Breton || Magicka Sorcerer || DPS || Level: 20
    Ragnar the Wulf: EP || Nord || Stamina Warden || DPS || Level: 30
    Ra'Rahku: AD || Khajiit || Stamina Nightblade || DPS [Bow/Bow] || Level: 15

    Healers
    Sees-through-Hist: EP || Argonian || Magicka Warden || Healer/CC || CP 445
    Daedalus the Artificer: AD || Altmer || Magicka Templar || Healer || Level: 15
  • ajm1946
    ajm1946
    ✭✭✭
    I've just tried logging into my account - PC NA and it asked for access code, tried 6 times every time access code was asked for.
  • Nestor
    Nestor
    ✭✭✭✭✭
    ✭✭✭✭✭
    With my gaming laptop, I dont have to do 2 Step when I go from place to place. Been that way for about a year.
    Edited by Nestor on August 15, 2018 8:43PM
    Enjoy the game, life is what you really want to be worried about.

    PakKat "Everything was going well, until I died"
    Gary Gravestink "I am glad you died, I needed the help"

  • burglar
    burglar
    ✭✭✭✭
    Raraaku wrote: »
    What exactly do you mean when you say access code? If we're talking about login/account passwords then yes, that is worrisome. I don't follow you, I apologize if I'm wrong, but I'm guessing English is not your native language?

    Could you elaborate further?

    Also, if it's a serious security flaw/breach directly contacting customer support and/or direct e-mail with evidence (screenshots) and a detailed explanation of the vulnerability would be a much better route to go rather than a semi-cryptic public message on an official forum where anyone can read.

    Quote for emphasis.
    Bosmer Melee Magicka Nightblade
  • Radinyn
    Radinyn
    ✭✭✭✭✭
    maybe your IP doesnt change
  • Saturn
    Saturn
    ✭✭✭✭✭
    I literally just today had to confirm my "new device" which has never changed. How exactly are you testing it? To my knowledge it's only if the IP is different or not already approved.
    "Madness is a bitter mercy, perhaps, but a mercy nonetheless."

    Fire and Ice
  • ADarklore
    ADarklore
    ✭✭✭✭✭
    ✭✭✭✭✭
    Strange... I think only ONCE did I have to do the two-step authentication to access the GAME... but I have to do it every week or so when accessing my ACCOUNT. Think the Account has to do with cookies and when they expire... but as far as the PC, nope, haven't had to do the two step since the one time long ago. But I also haven't changed my hardware or anything that would warrant triggering a 'new device' issue.
    CP: 2078 ** ESO+ 2025 Content Pass ** ~~ ***** Strictly a solo PvE quester *****
    ~~Started Playing: May 2015 | Stopped Playing: July 2025~~
  • Sylvermynx
    Sylvermynx
    ✭✭✭✭✭
    ✭✭✭✭✭
    Saturn wrote: »
    I literally just today had to confirm my "new device" which has never changed. How exactly are you testing it? To my knowledge it's only if the IP is different or not already approved.

    This. My IP is infinitely variable, due to wildblue not allowing anything but business customers to have a static IP. I had to wait on the access code yesterday after downloading and installing the update - same computer, same mac addy, but wildblue changed my IP at some point yesterday and the game wouldn't let me log in without the access code.

    PC/NA

  • Darcwolf
    Darcwolf
    ✭✭✭
    Lol @ people thinking ip actually matters. There 2 step is a broken joke, I can use a VPN, or take my laptop to another city and it never triggers it, but I can overclock my PC and suddenly it wants a code and says I'm on a new IP. Apparently zenimax doesn't know what a ip address is.
  • ssorgatem
    ssorgatem
    ✭✭✭✭
    Moved to a different town last week: no code required (before update 19)

    Today: I reboot my PC: code required.

    It seems to be working as always.

    That is, quite randomly.
Sign In or Register to comment.