Best practices in account safety
Posted by Tobold's Blog [HTML][XML][PERM][FULL] on 2 April 2013, 1:01 pm
I got a mail today from EA about my Star Wars: The Old Republic login:
Beginning today, April 2, 2013, you are only able to log in to the Star Wars: The Old Republic game or web site with your Display Name – Your email address will no longer be accepted from this point forward. ... These changes increase the security of our game authentication system, which helps to keep the game protected from many security threats including account takeovers.
Which was somewhat funny, because I just recently got another mail from Ubisoft:
The login process for Ubisoft’s Uplay service will undergo a few modifications on April 3rd. Past this date, if you connect to a Uplay Account, you will need to log in using your email address. Using the Uplay account name to login to your game will no longer be possible.
Of course Ubisoft is also claiming that this change will help account security. EA thinks that a display name is safer for login, reversing a previous decision to have people login with their email address. Ubisoft does the reverse, changing from login with a display name to login with an email address.

That pretty much tells me that there is no agreement on which method is safer. And frankly, I believe neither is any good. Both you displayed name and your email address are easy enough to find out, so potential hackers only ever need to guess your password. What would be safer would be a UserID and password for the account, with the UserID being *different* from both you displayed name and your email address.
