Forum Discussion

Re: Two months to get my hacked and banned account back. No refund on wasted s pass.

@DarthValtrex
I see only one mistake user can do => use same password everywhere (for email, and Origin) and use email for 2FA.
You want to say there is more?

4 Replies

  • DarthValtrex's avatar
    DarthValtrex
    Hero (Retired)
    5 years ago

    @SlivPTS I don't want to give anyone ideas and contribute to a problem. But yeah there are ways around it. 2FA simply makes it more difficult to hack an account. No security is going to full proof, the idea behind security is to make it such a hassle to get into your account that hackers move on and find easier targets.

  • SlivPTS's avatar
    SlivPTS
    5 years ago
    @DarthValtrex
    So it's hole in 2FA? Then maybe you should report this to EA?

    Or it's something what user can do? But in this case, why do you hide it? Such note should be on 2FA info page.
  • DarthValtrex's avatar
    DarthValtrex
    Hero (Retired)
    5 years ago

    @SlivPTS It's not really a hole in their system. There are multiple ways you can get around 2FA. Most people would not know how to do it or want to spend the time doing it. the idea behind security and cyber security is to make your system such a hassle to get into that hackers just pass it up for easier targets.

    Cyber security involves ALL of your technology.. You have to have security on your email, your computer and so on. If you leave gaps in that security it leaves openings for hackers to work around the security you do have.

    The best analogy I can give you is to imagine it like your home. You invest a ton of money on the front door and making the front door extremely secure. But leave the window next to the front door open. What good is a secure front door if you leave your windows open?

  • SlivPTS's avatar
    SlivPTS
    5 years ago

    @DarthValtrex
    If it's not hole in 2FA and user is not dumb (uses unique/strong passwords and thinks what he is doing online), then it can be done only by fooling support.
    Let's say i am using email 2FA, so to hack my Origin account hacker must find out my Origin password and then somehow guess my email password. To me it sounds pretty impossible.