Rather than focus on who is or is not to blame for the various compromised PSN accounts I think it would be better and far more productive to create a thread for suggestions on how Sony might improve account security on their platforms. So, here we are.
In today's world of shared logins and constant data breaches its clear its no longer enough to ensure that your individual service is secure you must also seek to protect people from themselves by providing them with every opportunity to make a corrective action after their account may have been compromised. Its clear that a lot more could be done to help keep user's accounts secure. So in the interest of improving their service here are a few suggestions I think would be very beneficial to all parties involved:
If they were to implement two or three of these I'm sure it would help reduce the recently rampant run of compromised accounts.
Please use this thread to submit any suggestions or ideas you have on how account security could be improved going forward. Hopefully, given enough participation, we can get their attention and get some improvements made.
In today's world of shared logins and constant data breaches its clear its no longer enough to ensure that your individual service is secure you must also seek to protect people from themselves by providing them with every opportunity to make a corrective action after their account may have been compromised. Its clear that a lot more could be done to help keep user's accounts secure. So in the interest of improving their service here are a few suggestions I think would be very beneficial to all parties involved:
- Send users an email anytime someone logs into their account from a new device with links to immediately reset their password and set up 2FA
- Notify users by email when a new system is activated on their account and provide two links one to deactivate said system and change their password if they did not add said system and another to set up 2FA on the account.
- Allow for the creation of a unique pin for use on all account purchases both via dedicated HW and online. Cross reference PIN with existing account password to make sure there are no shared values
- When setting up 2FA automatically deactivate all existing consoles on an account, provide user with a one time use master key for account access in case they misplace their phone and prompt user to activate main system as primary with instructions on how to do so.
- Allow the registration and use of various third party 2FA programs to make the service more convenient and promote wider adoption. Alternatively allow for the use of email 2FA or provide an option to use the Playstation App as a 2FA service for smartphones.
- Provide users utilizing a password reset link with tips on how to create a secure password and enforce stricter password requirements on their new passwords demanding the use of at least 15 characters with at least 2 symbols, 2 numbers and 2 upper case letters.
If they were to implement two or three of these I'm sure it would help reduce the recently rampant run of compromised accounts.
Please use this thread to submit any suggestions or ideas you have on how account security could be improved going forward. Hopefully, given enough participation, we can get their attention and get some improvements made.