Saying "convenience and security are on opposite sides of the spectrum" isn't defending SE, take a step back, you're attacking someone who isn't against you.
Printable View
The authentication method may be one you prefer, but it is not the be-all-and-end-all you assume.
The major problem with OAuth as used by Blizzard is that it requires you to have a cell phone or tablet in order to use it. If you don't have one (and it appears to be required for the 'instant' authentication you appear to be pushing), it becomes much more cumbersome to use than a physical authenticator.
OAuth has nothing to do with the authentication, you can do OAuth with username and password, it's merely a framework for exchanging temporary tokens to KNOWN devices. The fact that I even need to explain this, shows your way out of depth and shouldn't be arguing this. It's used on every single mobile app you have that doesn't require login every time, most bank websites, and a lot of other companies. I guess you guys know more Microsoft, Okta, Apple, Google, and thousands of others who use this technology every day, apparently Sony is the leader in technology according to your standards.
This is why hardly participate on these forums, SE can do wrong to most posters here, no matter the facts stacked against them.
Blizzard couldnt..sorry make that WOULDNT....implement the appear offline feature they promised for five years ( the fact that they blatantly LIED to their players about it didnt help ), have pathetic privacy controls ingame, have a system that allows ANYONE to add you as a friend and track you anywhere, cant or wont implement an account wide ignore system, ties all games to their launcher and FORCED a mandatory voice app on the launcher that CANT be turned off and until a huge uproar, then fixed that voice app to NOT screw with global volume settings, said app was also tied into the entire system sound settings, caused massive system errors because it was a resource hog.Quote:
apparently Blizzard can implement this
The fact they they had a/ not tested it to prevent that issue and b/ did not allow players to opt OUT of having it installed in the first place says it all.
my long time friend is otp he protects my account from harm.
OTP tokens are great. I'm a proponent of the physical token. My original FFXI token from 2008(?) was just replaced a few months ago. One of the original tokens that my wife got from the FFXIV 1.0 release is still working just fine. I have it on a badge pull connected to my monitor. I'll never use it away from my PC, so I keep it there. Doesn't get lost. None of those "I replaced my cell phone and didn't disconnect the app from my FFXIV account" problems either.
I don't like the app since my cell phone leaves the house. I could see that being misplaced, dropped, broken, etc. However, NOT using the OTP is asking for trouble.