Name and Location are now required?

Post/Author/DateTimePost
#1

jacobi289

Oct 03, 2008 20:26:50
Any reason we need to give up such personal information?

I'd like to know what it's being used for.
#2

propane

Oct 03, 2008 20:45:07
Your name is now Mr. Squiggle, and you are from the moon.

If you don't want personal info out, lie about it.
#3

wrecan

Oct 03, 2008 20:46:27
With whom does Wizards share my personal information?
Wizards may share your personal information with outside entities hired to assist with internal web site support operations (e.g., online product fulfillment, e-mail services, or technical support). These web sites will not use your personal information for any other purpose, and have agreed to maintain confidentiality, surveys, security, and integrity of all the personal information they obtain from us.

We may disclose personal information in the good faith belief that we are required to do so by law, including but not limited to disclosure to law enforcement or other government officials in connection with an investigation of fraud, intellectual property infringements, or other activity that is illegal or may expose you or us to legal liability.

Wizards, as a subsidiary of Hasbro, Inc. does not sell, rent, or otherwise disclose personal information collected from and about its users (including children under 13) to third parties. However, in the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, Wizards' customer information may be transferred to Wizards' successor or assign, if permitted by and done in accordance with applicable law.

-Privacy Statement
#4

Dargurd

Oct 04, 2008 2:20:17
Well I suppose its could simply be used for marketing purposes. If they know where the majority of forum users are and treat that as microfragment of the gaming community at large they will have a good idea where to target releases, conventions etc.

On the other hand it could be an attempt by the sinister WOTC to identify potential targets in an underhand covert operation of brain washing...:D
#5

WolfStar76

Oct 04, 2008 6:20:13
We were told that the last couple days of downtime for the forums was to upgrade all the login systems across the board to integrate with the upcoming DDI subscription system - which will be handled by a 3rd party (Digital River).

I'm guessing adding that information might be to give data verification points between these sub-systems.

It could also be used to verify account information if you call customer service.

These are all speculative, but that's my hunch.
#6

umbralknight

Oct 04, 2008 14:05:13
So, at my second log in of the day, I was asked a brand new set of questions. I sincerely hope that I don't have to fill out a questionarre every time I decide to post on these boards.
#7

Angel_Black

Oct 04, 2008 16:36:24
Long explanation:

Boards are going Worksafe/ESRB/...other
(stuff that is made by montures and other creatures after eating and is not liquid and have a non pleasant odor and texture)

It is sacrifice we all must to do in order to allow little children come into the boards and enlighten us in the creative uses of daggers in conflict resolutions.
#8

ace_of_time

Oct 04, 2008 19:35:38
It is simple. We use the same type of tactic in the grocery store. It helps keep unwanted people out. Most people don't mind saying who they are. Most of the ones that are causing trouble for fun, (IE greenish people) will not want to give that up and will just stop opening accounts if they know they have to tell who they are first or will lie about it. It will not stop the hard core greenish people but it will help some.

Also helps if you have to go with legal actions if you know who and where.
#9

mead

Oct 04, 2008 20:55:03
Anon McAnony, at your service.

Anyone got a problem with that? Guess you'll get over it or die frustrated.
#10

-Arry

Oct 05, 2008 5:35:52
Well, if it'll reduce the greenish people somewhat I don't mind a bit. ;)
#11

Ra-Tiel

Oct 05, 2008 5:50:04
And while where at it... what's with that stupid set of "security" questions whose only purpose is to make dictionary attacks trivially easy?
#12

Ra-Tiel

Oct 05, 2008 7:28:30
In my opinion anyone with a few more brain-cells should be able to know the questions are totally worthless and answer them with non-fitting answers that are easy to remember for you.

I mean, seriously, if anyone does a bit search he can probably find a lot of the answers others use with these "security" questions.

My full agreement on that one. This is exactly the reason why I so far evaded answering them.

Speaking of "security", is it a "feature" that you can get around the form and enter the boards without having to fill out the form?
#13

Zherog

Oct 05, 2008 19:56:58
At first I was really annoyed that I had to give my name in order to log in. Then i remembered the information was already in my sig, and I went from "really annoyed" to just "annoyed."
#14

Webster

Oct 05, 2008 20:27:51
My full agreement on that one. This is exactly the reason why I so far evaded answering them.

That's actually a mistake. It's how CS will be able to verify the account is yours if you ever need to recover it.
#15

Ra-Tiel

Oct 06, 2008 0:34:17
That's actually a mistake. It's how CS will be able to verify the account is yours if you ever need to recover it.

And why would I need to recover my account? It's not that as a B.Sc. in computer science I would accidentally forget my password or something, even more since I don't allow cookies in my browser and log in manually for each session.

The problem with "security" questions is that if you answer them honestly and don't put any garbage strings as answers, it makes guessing or dictionary attacks trivially easy - especially since the digital striptease also known as social networks came up. Finding out your first pet's name or the make of your first car is really easy for some people.
#16

zammm

Oct 06, 2008 5:17:23
That's why I use trick questions whenever possible--questions whose answers seem straightforward to an outsider, but which actually refer to something completely different and nonintuitive that only I would know, or which actually have no answer but jog my memory for where I can go to remember the password.

Of course, that's only if the site allows custom security questions. "Standard" security questions are just all around worthless for almost anyone.
#17

rhialto

Oct 06, 2008 12:50:52
Assuming Wizbro has any office at all within the EU (quite likely, but I don't know for sure), they are breaking EU law in requesting this data, as it is (I would assume) going to be stored in a US-based server, and the appropriate notifications on the forms are not in place.

Has the legal department been notified yet?

ETA: If they have no EU-based office, no EU laws are being broken. It's legal for a foreign-based company to ask for this information, but an EU-based company (even if just satellite offices) must clearly declare where the information is being sent if it is going outside the EU.
#18

christopher_rowe

Oct 06, 2008 13:05:57
A friend of mine who took a cycling vacation through the Savoy a couple of years ago tells a story about meeting a Wizards employee in a café who noticed the D&D sticker on his Orbea, so I suppose it's possible they have an office in the EU.

I'm sure it's all on the up and up, though. Transparency's proven to be a better defense against internet shenanigans than anonymity for most folks who are even marginally careful, anyhow.

Cheers,

Christopher Rowe
Lexington, KY
#19

kursk

Oct 06, 2008 13:18:29
Assuming Wizbro has any office at all within the EU (quite likely, but I don't know for sure), they are breaking EU law in requesting this data, as it is (I would assume) ...

Only a VERY small percentage of traffic to the boards comes from outside the US & Canada. There would be no real damage if that traffic stopped.
#20

christopher_rowe

Oct 06, 2008 13:43:48
Only a VERY small percentage of traffic to the boards comes from outside the US & Canada. There would be no real damage if that traffic stopped.

I'm sure that the people who make up that traffic want to keep frequenting the boards, though. I've seen several posts that I found useful or entertaining or provocative or what-have-you from people who identify themselves as being from various nations other than Canada and the US. I'd hate to see them go, and I sure there's no reason to think that they will. Nor any reason to think that the moderators are all going to get dragged to the Hague for high crimes against the internet, either.
#21

kursk

Oct 06, 2008 13:47:05
I'm sure that the people who make up that traffic want to keep frequenting the boards, though. I've seen several posts that I found useful or entertaining or provocative or what-have-you from people who identify themselves as being from various nations other than Canada and the US.

Well, unless those people live in some authoritarian country no one is going to stop them from typing http://forums.gleemax.com/ into their browsers...
#22

rhialto

Oct 06, 2008 14:30:01
Only a VERY small percentage of traffic to the boards comes from outside the US & Canada. There would be no real damage if that traffic stopped.

Its not the traffic that's the issue. It's the punitive fines the EU may decide to enforce if it comes to their attention. Most Europeans are smart enough to lie when faced with intrusive questioning, so the traffic won't actually stop.
#23

axetank

Oct 06, 2008 14:35:43
Anon McAnony, at your service.

Anyone got a problem with that? Guess you'll get over it or die frustrated.

Ever heard of Ben Dover? Wanna know where he lives?
#24

kursk

Oct 06, 2008 14:44:45
Its not the traffic that's the issue. It's the punitive fines the EU may decide to enforce if it comes to their attention. Most Europeans are smart enough to lie when faced with intrusive questioning, so the traffic won't actually stop.

Individual users get fined for visiting a commercial website?
#25

wrecan

Oct 06, 2008 15:23:45
Assuming Wizbro has any office at all within the EU (quite likely, but I don't know for sure), they are breaking EU law in requesting this data

As far as I know, WotC has one office in Renton, Washington, USA. It has no offices in Europe, as it acts internationally completely through independent distributors.
#26

rhialto

Oct 06, 2008 16:20:37
Individual users get fined for visiting a commercial website?

No, the providor (wizbro in this case) would be fined, for data-farming visitors without informing those visitors that teh data would be leaving the EU.
#27

rhialto

Oct 06, 2008 16:22:18
As far as I know, WotC has one office in Renton, Washington, USA. It has no offices in Europe, as it acts internationally completely through independent distributors.

http://www.wizards.com/magic/advanced/5e/Fifth_Ed_Rulebook/Section_IV.html

"If you're in the United Kingdom, you can call our UK office at 0345-125599 or email us at [email]uk@wizards.com[/email]. You can also write us Wizards of the Coast UK Ltd., P.O. Box 1562, Glasgow, G2 8BW, SCOTLAND, attn: Magic Customer Service. "

They have an EU-based office.
#28

wrecan

Oct 06, 2008 16:58:02
Ha! I guess you learn something new every day.
#29

kursk

Oct 06, 2008 19:26:04
No, the providor (wizbro in this case) would be fined, for data-farming visitors without informing those visitors that teh data would be leaving the EU.

Hmm, good reason to not have a physical presence & employees in the EU.
#30

lord_karsus

Oct 06, 2008 21:39:47
-I found a way around this. I don't know if, by doing so, I'm being a bad boy or whatever, but...Discovered it completely accidentally.
#31

Ra-Tiel

Oct 06, 2008 23:12:04
Hmm, good reason to not have a physical presence & employees in the EU.

I would rather say "good reason to not attempt any stupid and possibly illegal data farming stunts". ;)

@LK: Been there, done that. :P
#32

rhialto

Oct 07, 2008 2:01:22
Well, I've done my moral duty in giving wizbro a heads-up about the possible legal situation of their data requests.

Naturally, the name I gave them on that form was Anne Onymous. My other answers will be similarly helpful in determining my real identity, yet sufficient to recover passwords etc should the need arise. And this request for information does nothing to prevent/reduce trollery, since there is no data verification (and databases that could verify this information do not even exist for EU citizens; I have "verified" my identity on high-end US-based systems with fictional data).

In other words, my answers fulfil the stated purpose of helping to recover passwords, but are useless in determining who exactly I am, which I should not be obliged to give on a board such as this.
#33

Zherog

Oct 07, 2008 7:01:45
...which I should not be obliged to give on a board such as this.

I agree completely.
#34

kursk

Oct 07, 2008 8:18:32
I would rather say "good reason to not attempt any stupid and possibly illegal data farming stunts". ;)

@LK: Been there, done that. :P

Naw. When regulations get too onerous you pull out. When France went to a 35 hour work week I shuttered our operations in Poissy France and just moved them. Lots of multinationals did the same. There is always a better country you can move operations to.
#35

rhialto

Oct 07, 2008 9:50:06
Kursk, should I assume you consider data farming a legitimate practice then?
#36

kursk

Oct 07, 2008 9:57:29
Kursk, should I assume you consider data farming a legitimate practice then?

I consider that if you give someone info you 1st read any privacy statement (http://ww2.wizards.com/Company/Default.aspx?doc=Privacy) and decide whether you then want them to have the data...

If it is covered in the privacy statement then it is legit.

Simple.
#37

wrecan

Oct 07, 2008 10:30:25
According to The US Department of Commerce, as long as Wizards isn't going to share the data with third parties and maintains its confidentiality (and according to Wizards' privacy statement, they will), then they seem to comport with the European Union Privacy Directive of 1998, which is to what I believe Rhialto references.
#38

matteblack

Oct 07, 2008 21:54:04
If adds a little more threat of accountability, I am all for it.
#39

vaalingrade_ashland_02

Oct 08, 2008 0:15:34
It doens't really matter because we're all going to lie on it anyway.
#40

emwasick

Oct 08, 2008 2:40:00
I told the truth! I guess I really am the most naive person here :'(
#41

rhialto

Oct 08, 2008 2:43:20
According to The US Department of Commerce, as long as Wizards isn't going to share the data with third parties and maintains its confidentiality (and according to Wizards' privacy statement, they will), then they seem to comport with the European Union Privacy Directive of 1998, which is to what I believe Rhialto references.

Part of the EU privacy directive requires that, if the information is to be stored outside the EU (which is apparently the case), if must say so on the form itself, not just on a privacy statement.
#42

wrecan

Oct 08, 2008 5:36:46
Not according to the US Department of Commerce.
#43

at-at_assault

Oct 08, 2008 9:24:11
Most people don't mind saying who they are.

Most, yes. I, however, do not like giving out my name to people I don't know, especially if have no real life interaction with them (heck, I don't even like saying my name, but that's just one my weird oddities). Luckily, the system didn't mind me putting my first name as AT AT and my last as Assault.
#44

rhialto

Oct 08, 2008 9:43:10
Not according to the US Department of Commerce.

I wasn't aware that the US Department of Commerce was the final authority on EU laws. I have no reason to doubt that WotC is following US law to the letter; I equally have no reason to believe it is following EU law, except in so far as EU law happens to coincide with US law, which it does not in this specific situation.
#45

kursk

Oct 08, 2008 9:48:37
I wasn't aware that the US Department of Commerce was the final authority on EU laws. I have no reason to doubt that WotC is following US law to the letter; I equally have no reason to believe it is following EU law, except in so far as EU law happens to coincide with US law, which it does not in this specific situation.

But, the whole thing doesn't matter if WotC doesn't have physical offices in the EU. EU law doesn't then apply to them...
#46

lord_karsus

Oct 08, 2008 9:57:17
EU law doesn't then apply to them...

-No, no it doesn't. According to the ToC (I was looking at it the other day), and I am paraphrasing, because WotC is based in Renton, Washington, anything that happens on this website is subject to the laws, statues, and so on, of Renton Washington, and nowhere else.
#47

wrecan

Oct 08, 2008 10:02:16
American companies can be subject to EU laws if they do business in the EU, which WotC does. Just like foreign companies can be subject to US law if they do business here. However, as set forth in the U.S. Department of Commerce website, the US and the EU have reached an accord to allow American businesses to do business in Europe and be deemed to comply with the EU's requirements about privacy. And that accord is reflected in the website that I linked.

In other words, the EU and the US have agreed that American companies will not get in trouble if they follow the guidelines set forth in the US Dept of Commerce website. I think WotC is going to be okay.
#48

kursk

Oct 08, 2008 10:05:21
American companies can be subject to EU laws if they do business in the EU, which WotC does.

Actually, only IF they have a physical presence. I did business in the EU (over internet) without a presence there. Told them to stuff their internet data privacy laws.

They were powerless. Unless they wanted to erect a firewall like China.
#49

wrecan

Oct 08, 2008 10:10:13
Actually, only IF they have a physical presence.

Actually, not necessarily.

American laws can apply to foreign companies even if they don't have a presence, if they enter the "stream of commerce". Europe could have a similar provision (I'm not a European lawyer).

They were powerless.

Or you were too small to be worth going through the Hague Convention to sue your ass in Europe.
#50

kursk

Oct 08, 2008 10:15:19
Or you were too small to be worth going through the Hague Convention to sue your ass in Europe.

Since they have no way to compel my presence & the "Hauge Convention" has nothing to do with businesses solely on US territory, futile.

You have no idea of the laws that regulate businesses in the world.
#51

Cpt_Micha

Oct 08, 2008 10:50:18
Any reason we need to give up such personal information?

I'd like to know what it's being used for.

My guess, they want to stop the puppetry. (By making it annoying to type in that info over and over again each time they need a new puppet)
#52

wrecan

Oct 08, 2008 11:18:32
Since they have no way to compel my presence & the "Hauge Convention" has nothing to do with businesses solely on US territory

Yes. Yes, they do. The Hague Convention allows foreign entities, including companies to be served with legal process so they can be sued in a foreign jurisdiction, if that foreign jurisdiction can subject you to their laws.

I have successfully sued several European companies here in the US by serving them with judicial process through the Hague Convention. Even though the companies had no office on the US.

You have no idea of the laws that regulate businesses in the world.

If somebody informed you that the Hague Convention has nothing to do with laws that regulate the business world, you need to find a new attorney. Specifically, the Convention on the Service Abroad of Judicial and Extrajudicial Documents in Civil or Commercial Matters (which is a part of the Hague Convention) expressly allows for a company not present in its borders to be served with judicial process abroad and thus subject to a lawsuit there. The Hague also compels member states (and the US is a member) to recognize the judgments asserted against a company who has been served with judicial process through the Hague Convention provisions.

Now, I don't know if Europe does allow companies to sue American companies without a physical presence. I'd be surprised if you could ship contaminated food products, for example, to Europeans and evade litigation simply by not having an office there. The Hague Convention is the means by which nations assert their jurisdiction over individuals (and entities) outside their borders.
#53

kursk

Oct 08, 2008 11:21:35
Yes. Yes, they do. The Hague Convention allows foreign entities, including companies to be served with legal process so they can be sued in a foreign jurisdiction, if that foreign jurisdiction can subject you to their laws.

It has already been ruled by in US Federal Court. No foreign presence , no jurisdiction.

Don't know about suing EU companies in US court. That'd be subject to different rulings...
#54

wrecan

Oct 08, 2008 11:48:49
It has already been ruled by in US Federal Court.

Can you give me one of the party's names or the citation? I would like to read that case.
#55

kursk

Oct 08, 2008 11:55:40
Can you give me one of the party's names or the citation? I would like to read that case.

No. Read it about a year ago with my bus atty. You can check the latest ALR.
#56

wrecan

Oct 08, 2008 12:23:59
I have. I dont' see what case you reference.

The law as I understand it it:
A foreign judgment will not be recognize if the foreign (in this case, European) court did not have personal jurisdiction over the defendant.

Personal jurisdiction can exist without physical presence. The landmark case of Asahi Metal Industry Co. v. Superior Court of California, 480 U.S. 102, 107 S.Ct. 1026 (1987) held that a Japanese company, that had no physical presence in the US can be sued in the US when one of its motorcycles injured the plaintiff, because "an action of the defendant purposefully directed toward the forum State" is sufficient to convey jurisditcion:
[indent]The placement of a product into the stream of commerce, without more, is not an act of the defendant purposefully directed toward the forum State. Additional conduct of the defendant may indicate an intent or purpose to serve the market in the forum State, for example, designing the product for the market in the forum State, advertising in the forum State, establishing channels for providing regular advice to customers in the forum State, or marketing the product through a distributor who has agreed to serve as the sales agent in the forum State. But a defendant's awareness that the stream of commerce may or will sweep the product into the forum State does not convert the mere act of placing the product into the stream into an act purposefully directed toward the forum State.[/indent]
As far as I know, the standard is identical when enforcing a foreign judgment.

Now, your attorney may have been explaining to you that you personally had not "purposefully availed" yourself of that forum state such that it would have jurisdiction over you.

But Wizards, much like Asahi, does purposely avail itself of Europe's markets. It has distributors and sales people. It ships products to Europe. I have little doubt that Wizards could be subject to jurisdiction in most European countries.

Physical pesence is not the legal touchstone for jurisdiction. It's a much more vague standard.
#57

kursk

Oct 08, 2008 12:27:30
As far as I know, the standard is identical when enforcing a foreign judgment

Nope. A doesn't equal B in case law. That's why it's called case law. You should know that.
#58

lord_karsus

Oct 08, 2008 12:30:27
-Don't you all just love international business law? As if international law wasn't complicated enough.
#59

wrecan

Oct 08, 2008 12:32:25
Nope. A doesn't equal B in case law. That's why it's called case law. You should know that.

I do. Which is why I know there are cases that say that the standard is identical.

For example, in VF Jeanswear Ltd. Partnership v. Molina, 320 F.Supp.2d 412 (M.D.N.C. 2004), the court stated "a foreign judgment is not conclusive if it was rendered by a court lacking due process protections, personal jurisdiction over the defendant, or subject matter jurisdiction." The court here is stating the general rule, and one which has been applied to recognition of foreign judgments since Asahi was decided.

I opened with "as far as I know" because perhaps, just perhaps, this mysterious case you reference is some earth-shattering landmark federal case that changed the law and said that in the area of recognition of foreign judgments, physical presence is required. I don't know on what basis such a holding might be found, but you seemed so insistent that this was the law, that I figured I'd qualify my statement in case you were able to show me that twenty years of judicial precedent on the law of recognition of foreign judgments had been overturned.

So, Kursk, could you call your lawyer and get the citation for this case he showed you, because I have a bunch of clients who would really love to hear they can continue to sell stuff to Europeans and not worry about getting sued simply by avoiding a physical presence in Europe. It would save them a lot of money as they wouldn't have to retain European counsel (what with the dollar-to-Euro exchange rate being what it is).
#60

kursk

Oct 08, 2008 12:44:21
the court stated "a foreign judgment is not conclusive if it was rendered by a court lacking due process protections, personal jurisdiction over the defendant,

See, that's the part you are missing. The case law or statue giving "personal jurisdiction over the defendant" in the US. You only have one showing foreign in US court.

Need the other I'm afraid.

If you really have a question though you should consult an international business atty firm, like I did. The one I used has offices in 20 major cities across the globe, including NYC, LA & S.F.
#61

wrecan

Oct 08, 2008 12:52:52
See, that's the part you are missing. The case law or statu[t]e giving "personal jurisdiction over the defendant" in the US.

That case law is the US case law. In the case I cited, they used Asahi and other landmark federal personal jusidiction cases when determining whether the European courts had personal jurisdiction over the party that claimed that pj did not exist. That's the law and has been for 20 years.

Kursk, please stop opining on what the law is on recognizing foreign judgments. Your company probably is not subject to jurisdiction in whatever European country you were worried about, but it almost definitely wasn't solely because you lacked a physical presence there. It may have to do with a specific statute in that specific country. It may have been that your company did not purposefully avail itself of that country's markets. Whatever the reason your counsel gave (and I'm sure they gave you good counsel), it's not a lesson that can be applied generally or to Wizards of the Coast.

If you really have a question though you should consult an international business atty firm, like I did. The one I used has offices in 20 major cities across the globe, including NYC, LA & S.F.

Well it might be the firm where I started my legal career. I am fairly certain you are misremembering or misunderstanding the advice they gave you, because I have never seen any case law that made a blanket statement that a lack of physical presence was sufficient to avoid personal jurisdiction in a foreign market. Which, of course, is why I'd like to see that case you reviewed with your attorneys that you think stated such a remarkable principle.
#62

rhialto

Oct 08, 2008 13:10:54
As I understand it, the physical presence criterion is the standard used when the goods in question consist purely of digital data, which is what this thread originally discussed. I have no doubt that the criteria are different if the issue involves actual physical goods moving across borders.
#63

wrecan

Oct 08, 2008 14:03:38
Except Wizards sells books, which makes them subject to the rules about those who move actual physical goods across borders.
#64

Webster

Oct 08, 2008 21:01:02
Are people really that paranoid? I mean, it really doesn't matter what your first pet's name is. You could give the name of your third pet for all WotC cares. It's just a verification question/answer to prove you are the owner of account in question if there's ever an issue with your account.

They're not collecting data about your personal life. They're giving you a question to remind you of whatever "answer" you give to prove the account it yours.
#65

vaalingrade_ashland_02

Oct 08, 2008 22:56:17
Actually, you'd be pretty surprised what you can extrapolate by taking people's First and Last names in conjunction with thier IP. And Pet's Name is not just a common as dirt security question (meaning it can be used against other accounts), but a common password.

It's just good sense to be wary aobut any information going out into the web because not only are you giving it to the people who know, but anyone nasty enough to pry for the information, sold or hacked.
#66

Ra-Tiel

Oct 09, 2008 0:23:41
Actually, you'd be pretty surprised what you can extrapolate by taking people's First and Last names in conjunction with thier IP. And Pet's Name is not just a common as dirt security question (meaning it can be used against other accounts), but a common password. [...]

To add to this: the main problem is that answers to such questions are guessable, which means there is basically zero security gained from it. While a good password looks like 8K%sD?f=1, the answer to a security question often looks like Rocky or something like that.

To remove the weakness against guessing and dictionary attacks from these "security" questions, you'd have to fill in values that are just as strong as your ordinary password - which completely undermines the purpose of this "feature".

Several years ago "security" questions were a good idea, but since social networks have seen wide spread use, finding personal information - personal information like used to answer these questions - is sometimes trivially easy, especially when someone filled out his/her whole profile on Facebook/StudiVZ/whatyouvegot.

"Security" questions are like Caesar's Cipher - they were useful some time ago, but now have completely outlived their purpose.
#67

Zherog

Oct 09, 2008 9:15:26
They're not collecting data about your personal life.

Sure they are. They're collecting my first and last name. They're collecting my zip code. They're collecting my IP address with every post I make, which tells them my employer as well as my ISP.

Quite frankly, if my name weren't already in my sig I would've either entered false information or not reactivated my account, and completely left the forum. As it is, the zip code I entered isn't the correct one. WotC doesn't need that information about me.
#68

aotrscommander

Oct 10, 2008 8:09:36
And it says something when Zherog is getting ticked off. I mean, seriously. That's a warning light if ever there was one.

I was considering for a good few minutes as whether to shout "stuff you, WotC" and bugger off myself. It's becoming more and more tiresome to come to these boards, when every other bloody forum I go gives me no signing in problems or personal questions or faffing about. It says something when I have less trouble with the EA forums! Frickin' paranoid, DRM-mad EA, which I haven't used since C&C 3 came out and which I just logged into without batting an eyeglow.

WotC really doesn't have any excuse for this kind of crap.

I wonder how many more prior forum-goers will leave now this has started.
#69

Zherog

Oct 10, 2008 9:54:44
And it says something when Zherog is getting ticked off. I mean, seriously. That's a warning light if ever there was one.

Nah, not really. I get angry a lot. And usually don't have any issues with telling management why I'm angry. In fact, I originally put my real name in my sig because I didn't want to hide my criticisms of a certain former employee behind an anonymous mask.

That said, there's really no reason for WotC to collect personal information such as name and where I live. While my location field has my hometown, that's entirely optional; while my sig has my real name, that's entirely optional. I don't mind the security questions. I actually like the "you write the question for us, then provide the answer" one -- that seems like much better "security" than "what's your mother's maiden name?"

I would love to hear from somebody within the company explain to us why they think they need to know our real names and locations.
#70

feyberry

Oct 10, 2008 10:26:00
Just lie. Are you that naive about the internet?
#71

mead

Oct 10, 2008 16:01:32
Are people really that paranoid? I mean, it really doesn't matter what your first pet's name is. You could give the name of your third pet for all WotC cares. It's just a verification question/answer to prove you are the owner of account in question if there's ever an issue with your account.

They're not collecting data about your personal life. They're giving you a question to remind you of whatever "answer" you give to prove the account it yours.

We're not talking about the security question, we're talking about them suddenly requiring names, locations, etc. That's personal information.

What's your name, your address? Oh, getting a bit uneasy? Don't want to give that out? Take a moment to consider your reaction to that is exactly the same as our reaction to WotC in this thread.

Desiring privacy is not paranoia, and saying everyone who doesn't want to give out their real name and address is paranoid is just being insulting.
#72

eric_anondson

Oct 10, 2008 21:30:25
Myself, I was just peeved over them asking about my location. I was a bit dumbfounded they asked for my name. I mean, really!
#73

frostwolf

Oct 11, 2008 8:55:53
Dear wizards: I'll show you mine if you'll show me yours.
#74

solaris

Oct 14, 2008 2:49:58
I wasn't bothered by the requirement, but then my name is pretty common -- Hi, I'm John Smith. Many of you are probably the same yourselves.
#75

axetank

Oct 14, 2008 3:28:37
I wasn't bothered by the requirement, but then my name is pretty common -- Hi, I'm John Smith. Many of you are probably the same yourselves.

Harbormaster: Hold up there, you. It's a shilling to tie up your boat at the dock... and I shall need to know your name.
Jack Sparrow: What do you say to three shillings and we forget the name.
Harbormaster: Welcome to Port Royal, Mr. Smith.

From IMDB.