One time password madness

04.16.2013 , 05:10 AM | #211
Hi Bioware,

Please fix this ASAP.

One time password arrived later and later until by the time it gets into e-mail, it expires already.

Else people are going to be lock out of the game.

04.16.2013 , 05:16 AM | #212
this is nonsence what are we paying for if these problems keep happening

04.16.2013 , 05:17 AM | #213
It would help if the passwords did not contain 1 and I, to my eyes reading it in the email I am forever mistaking one for the other and having to wait to get yet another password I can read to use.

04.16.2013 , 05:24 AM | #214
Please dont make us check e-mail to play, just please. Make another 5 security questions, they are just a matter of memory
Im very upset, my mates are raging at this issue, let us have fun playing.
04.16.2013 , 05:28 AM | #215

This One Time Password "feature" is not functioning correctly:

1. The email you are sending is coming 20 minutes later than it should. This is unacceptable. If you put such a system in place, make sure your delivery systems deliver the emails fast. Otherwise you are gonna lose customers (I believe you can read through this thread), because maybe some customers do not have the time to wait around for the email, and during this time you may encourage them looking somewhere else. In this "Internet business" time is of the essence, because there is competition out there that can steal your customers.

2. The email you are sending is incorrectly formatted. It lacks the text version alternative. I would like to receive that too, in compliance to email standards.

3. The entire concept is flawed and useless. The only single thing you are doing is annoying your customers. If someone wants to get access to my account they can still do it, One time password or not. FYI it is called IP Spoofing: .
Allow me to quote: "IP spoofing can also be a method of attack used by network intruders to defeat network security measures, such as authentication based on IP addresses." So, if they can spoof my IP (once it is registered by your systems) then they will not have the One Time Password prompt, would they? And btw it does not require the attacker to be the god of hackers either.

4. Please do not immediately invalidate the previous "security code" once you send another, allow it at least a 20-30 minutes grace period if you are not able to send emails promptly. At the current time I have 5 emails with passwords (all 20+ minutes late) and none of the passwords work. By extending a password "time to live" you would solve this madness with relative ease. Please relay this to your developers, it's a freebie.

5. The entire concept is flawed. You may be aware of it or not, but most of your customers do not have a static IP allocated. And that will probably be true as long as we are on IPv4, for the very simple reason that there are NOT enough IP addresses to use anymore, so service providers must make do.
Yes, it's true, usually ISPs are trying to reallocate the same IP to the customer IF available, sometimes it happens, sometimes it does not.

6. "We don't recognize the computer you are using. We have sent a One-Time Password to the email address associated with your account. Please enter the One-Time Password to continue. "
Trust me, it's the same computer, the only difference is my public IP address (which is not even on this computer, rather on the router). So at least have the respect to properly inform me what your systems are not recognizing, do not try to confuse your customers.

And now, it's literally 50 minutes since I, your paying customer, am trying to get in and I, the entitled account user, am not able to do it. I think an attacker will take less time to spoof my IP address...

I am thoroughly disappointed by this. At this point I gave up trying to get in...

PS: I am 100% sure nobody will reply, consider or even read this post. No idea why I even bothered.... (maybe just to give myself one more reason why I should give up the game?)

A very unhappy customer at this time, with I believe at least one valid point above...

04.16.2013 , 05:32 AM | #216
Spent last half hour trying to log-in without success. I type in one-time password and get error notification over and over. Is this a new game?

04.16.2013 , 05:35 AM | #217 Click here to go to the next staff post in this thread. Next  
Hi all,

Sorry for the delay in response, but unfortunately I don't have any fresh info on this. We are well aware that some players are seeing issues here and as soon as we have more information on how these issues will be addressed, we will make an announcement.

Thank you for the posts, and sorry for any inconvenience caused by these issues.

04.16.2013 , 05:50 AM | #218
Umm... Sorry to ask but... How about just flush that "security" into the Black Hole and restore good old "question" system?

P.S. Also we want to know - how you gonna compencate those days of subscription we lost becouse of this problem?
Becouse its obviosly not OUR problem.

04.16.2013 , 05:53 AM | #219
I think bee is basically saying that there's nothing much that they can personally do about it apart from apologise and say that the people who can do something about it are looking into alternatives.

Apart from going on a BP inspired apology session, there's little they can do.

04.16.2013 , 05:57 AM | #220
I have no words for this ****, really. Here is how it goes:
Launch swtor.exe
Type ID/PW
Read the ****** <insert one time password> (wich means "U wanna login? :trollface: now wait trololol)
*wait several minutes*
Eventually the e.mail arrives
Type it in the box
*error, incorrect code*

....and now it begins. Trying to login again, with the "old" one-time password, it is considered invalid (to me at least) for a new login, while it has been already dispatched another request for one more one-time password. And the cycle continues, until you sit down and wait 20mins or so to get the last e.mail, trying to login with that one.

Isn't that madness? Have we to WAIT this long, being frustrated this much all the times, in order to play? Are you gone crazy or have u build this.....this...thing..only to compel us buying an authenticator?

This IS madness, "dear" BW/EA
