Sage Advice

Post/Author/DateTimePost
#1

jeff-heikkinen

Nov 28, 2008 15:07:24
I can't seem to submit a question for Sage Advice. It keeps asking me to answer my security questions. I don't have any and refuse to set them up, because they are
  • yet another point at which it's possible for me to be accidentally locked out of my account, and
  • more importantly, likely to make my account less, not more, secure, because anyone who knows me well will know the answers to them.
This doesn't stop me from accessing the forums, but apparently it does stop me from getting to the e-mail form for Sage Advice.

Please drop this wholly unnecessary and unreasonable requirement.
#2

mycroftb

Nov 28, 2008 17:05:24
I agree. I can understand some security questions for things like my bank, but I hate when they're inappropriately applied. In many cases like this, the questions might be ambiguous enough for me to forget what I answer the first time, too. So I have to write the security questions and answers down, and therefore have something else I have to keep track of and not lose.

Also, no offense to WotC, but I don't trust the asker enough to give out correct answers. With all the information they're collecting, they're halfway to accessing my bank account.

I join the OP in disagreeing with this security policy.
#3

ORC_Wyvern

Nov 28, 2008 22:34:17
Hey,
I can understand that the security questions are a bit of a hassle. But the reason that we have them now is because of single sign on. That means that all your accounts (forums, KB, DDI) have the same sign on, and the security questions are to protect the paid for part of your account.

However, if you want to make different security suggestions, you can contact Support at http://www.wizards.com/customerservice and suggest different security measures. I can't promise that they will change them, but they will review your suggestions.
#4

Shiftkitty

Nov 29, 2008 10:15:09
They can ask me whatever security questions I want. I don't have to register a truthful answer, all I have to do is remember what I did list. The, uh, side of my computer tower is covered in post-its.
#5

jeff-heikkinen

Nov 29, 2008 14:20:03
They can ask me whatever security questions I want. I don't have to register a truthful answer, all I have to do is remember what I did list. The, uh, side of my computer tower is covered in post-its.

This just underscores my point, though, since those post-it notes are an even bigger security liability than the questions themselves!
#6

Shiftkitty

Nov 29, 2008 16:33:54
Well, this is in my home, and I can trust my husband not to abuse my accounts (not sure about the cats, though). For sites that we genuinely want secure, we both have a formula that we use for answers to the questions and we rotate it. He works as an IT lead for a major defense contractor and knows just how leaky a lot of systems are (and there's always the human element). We're not fool-proof, but we're better than most home networks. At work I keep no notes and I don't visit any "sensitive" sites. The people I work with are cool enough to ask if they can use my accounts for non sensitive sites (like Pogo and other online non-gambling game sites, 'cause they know if they win anything, it will come to me!). My boss has used my Amazon account to order books, but I never never store bank or credit card information anywhere, regardless of how convenient it would make it for me, not even on my home computer.
#7

rmn498

Nov 29, 2008 19:49:11
However, if you want to make different security suggestions, you can contact Support at http://www.wizards.com/customerservice and suggest different security measures. I can't promise that they will change them, but they will review your suggestions.

Correct me if I'm wrong, but doesn't that require answering the very same security questions that this thread is referring to? Catch-22, eh?
#8

Shiftkitty

Nov 29, 2008 20:39:38
You want them to fix things up before you make your suggestions to the right place? Eh, how does that work? You have to go there and make the suggestions and then they get to see if they want to change things.

I'm just not sure what's on here that's so confidential or critical that it's that big of a deal. Diff'rent strokes, I guess.
#9

jeff-heikkinen

Nov 30, 2008 4:36:59
Well, this is in my home, and I can trust my husband not to abuse my accounts (not sure about the cats, though). For sites that we genuinely want secure, we both have a formula that we use for answers to the questions and we rotate it. He works as an IT lead for a major defense contractor and knows just how leaky a lot of systems are (and there's always the human element). We're not fool-proof, but we're better than most home networks. At work I keep no notes and I don't visit any "sensitive" sites. The people I work with are cool enough to ask if they can use my accounts for non sensitive sites (like Pogo and other online non-gambling game sites, 'cause they know if they win anything, it will come to me!). My boss has used my Amazon account to order books, but I never never store bank or credit card information anywhere, regardless of how convenient it would make it for me, not even on my home computer.

Never mind whether the cats are trustworthy; I was thinking more of having a party or something where someone wants to show someone else something from YouTube or somesuch and seeing something they shouldn't.
#10

Shiftkitty

Nov 30, 2008 23:16:16
Well, ya kinda got me there. I'm not a great party hoster, although I don't mind helping a friend set up and clean up from a party at their house. (Especially right now, this place is soooooo small.) For myself, I've never felt free to mess with someone else's stuff without invitation, so I really couldn't fathom what would tell someone else it's okay to do so. Like my mom and dad always said, "If it's not yours, don't touch it." (Gee, who'd have thought the old folks would have such great advice, eh? ;) )

I was just thinking, although it might be a bit of a hassle, when you've got people over who might mess with your comp, like during a party, can you turn on some parental controls and restrict access to sensitive sites? That way they could go ahead and watch certain sites without you having to worry about personal information?
#11

legdiwena

Dec 01, 2008 7:49:59
Just lock comp so no one can use it while company is over.
#12

jeff-heikkinen

Dec 01, 2008 12:34:23
Just lock comp so no one can use it while company is over.

That misses my point. If they have the passwords, they don't have to use them on the spot. Most Web sites can be accessed from any computer with an Internet connection; that's rather the point of them.
#13

legdiwena

Dec 02, 2008 11:39:01
Ah, forgot about the post-its. Could do what dad does and keep a printout in a binder. Easier to put away than all the post-its.