| Post/Author/DateTime | Post |
|---|---|
| #1deimosrahlOct 13, 2010 0:20:33 | I recently attempted to make a request in order to get a refund/extension of my D&DI subscription after what happened last month. I got a reply within two days asking that I reply with as much information as I could about my account, including the answer to my security question. I have not yet replied to this email, and one of my friends informed me that Wizards would never ask me for such information. So, I'm wondering if the email I received is normal fare for this sort of request or not. |
| #2totemenschOct 13, 2010 0:37:26 | From what other people have said about their refunds, this appears to be normal. joe |
| #3WebsterOct 13, 2010 1:26:52 | The answer to your security question is the point of the security question; to verify the account is yours. |
| #4cathakOct 13, 2010 7:48:39 |
I did not need to provide such information, there is no need to ask that question. Why should DeimosRahl answer it? After all, we were both logged into our accounts when initiating the Customer Service incident. Also, from what I can see there is no encryption on the communication from CS which is quite bad. |
| #5rhianni32Oct 13, 2010 7:59:19 | I agree that there shouldn't be a need to prove you are the account owner in this case. Wotc charged for a product that was not delivered. They are now offering a refund. A user with an active account is requesting to fullfill a second offer (a refund if asked). Why in the world do they have to prove they are the owner? Is there some scam out there I am not aware of where hackers use accounts to give owners refunds? |
| #6asmodeusloreOct 13, 2010 8:25:55 | I suspect there have been isolated incidents where one or two users were not properly queried for their secret question answer. I suspect that is what happened with Carthak. WotC will confirm your identity anytime you have an issue with billing. This include questions about your account, secret question, address, etc. But NOT your password. Never your password. NEVER. |
| #7KerrusOct 13, 2010 16:54:29 | To clarify on what's already been said, most online account-based sites use a security question in order to let you reset your password. IN REAL LIFE, most businesses use a security question SO THEY KNOW YOU ARE WHO YOU SAY YOU ARE. WotC does the latter. The Security Question has nothing to do with your password, with resetting your password, with gaining access to your account. It's there specifically so that when you talk to them you can tell them the answer (for the record, they already have it sitting on their computer monitor) so that they know you are who you say you are. Remember. They already have the answer to your security question sitting on their monitor. They just need to hear it from you to know you are who you say you are. |
| #8caerinOct 13, 2010 20:29:38 | ...except in the email messages we receive from customer service, they specifically say they are asking you to answer all of the information they request (first name, last name, address, zip code, security question) because of account-based security. Providing that information over unencrypted email strikes me as odd. When you hit "Update Question" if you try to make the response using the browser, the "Update Question" interface defaults to http. I found out that you can type https:// and connect using encryption to respond that way. Unfortunately, I then received a response over unencrypted email that contained all of the information that I had submitted. :P |