I think there are a few misconceptions to address here that may provide a bit of context behind what Jagex is trying to do here.
The RuneScape Account System has its flaws. While its been working for the past 20+ years, the system itself is exactly that, a 20 year old system. When it was first created, there weren't that many examples or standards when it came to online accounts so it was very simple. It has had a number of changes over the years, but the core of the system has remained the same. Sometimes to fix the flaws of a very old system the best thing to do is to start fresh, which is what Jagex is doing.
Some of the current flaws of the system include (but are not limited to):
- No support for more complex passwords - given this hadn't been changed sooner, it is safe to assume there is some kind of technical limitation as to why they couldn't (which in itself shows the system as is had flaws).
- Manual recovery is a thing - people have gamed that system over the years to get into accounts that aren't theirs, and that isn't a good thing.
- 2 Factor Auth can be bypassed if a hijacker gets access to the email address registered to the account. They can recover the account through the email, and then receive an email to disable the RuneScape Authenticator.
- Logins go through a number of different places and each acts differently (RuneScape client, Old School client, website). Example, up until a few years ago the website was not protected by the authenticator. The website was never protected by JAG, nor were Jagex's other products that used RuneScape accounts at the time (e.g., Old School, Funorb and RSC). Not all login portals can employ the same type of protections against malicious individuals and attacks.
31-Oct-2023 01:41:34