Posted June 10, 2016
![fortune_p_dawg](https://images.gog.com/32214ee58455817349c6427bd0b765a6aec34b0ed2d7a87249021790f7ef22fa_forum_avatar.jpg)
fortune_p_dawg
constipationisbad
Registered: Aug 2011
From United States
![HypersomniacLive](https://images.gog.com/fc4a1abc37a5fe68e4e7fe666d87976d9900b9f928128c087fa9bbdf2e3e4bc4_forum_avatar.jpg)
HypersomniacLive
The Reluctant Voter
Registered: Sep 2011
From Vatican City
Posted June 10, 2016
high rated
![avatar](http://images.gog.com/2b1be91f2916b44cfa1ebc2d95e92056db86db4e25fd513f9669b7e73a6c8207_avm.jpg)
![Breja](https://images.gog.com/e5ad41d5686d009d9f3c4c651d6e66bcc79cf6f38c2ac94e627274817f20a70b_forum_avatar.jpg)
Breja
You're in my spot
Registered: Apr 2012
From Poland
Posted June 10, 2016
Hillary, is that you?
![Fairfox](https://images.gog.com/d24039124b6deacfcf61e5fcac0b94053f1dc4b69f96a2c229a7d4e5f9e44995_forum_avatar.jpg)
Fairfox
New User
Registered: Sep 2010
From United States
Posted June 10, 2016
deleted
![Nighthunter101](https://images.gog.com/c62a1b8b7c10ee696067891b49860635730292f4dc0d4f82ae1497baf45dc3cd_forum_avatar.jpg)
Nighthunter101
New User
Registered: Aug 2009
From Australia
Posted June 10, 2016
So I still haven't heard anything, sorry if I sound pushy I just want to try and fix this as soon as possible,
![MartinDueif](https://images.gog.com/48689112ea1e614b099a281ef23c76087e1a1a94bbdba2492dbd59b7ce1fa560_forum_avatar.jpg)
MartinDueif
New User
Registered: Jun 2016
From Denmark
Posted June 15, 2016
Hi, I just received the very same email, and I've wrote to the support mail.
Hope I can get my account back ASAP.
Hope I can get my account back ASAP.
![Midoryu](https://images.gog.com/46ce75fc7a99b9c729570aeff9b76a8d9bd12d1b9bc06e22538c3e811c8f415f_forum_avatar.jpg)
Midoryu
is watching you
Registered: Aug 2012
From Germany
Posted June 15, 2016
high rated
![avatar](http://images.gog.com/734aeae7a4916aefed2dc8d56e75dc49b5dfd478fbf779ff55c1a00f62a318b9_avm.jpg)
Midoryu
Edited 11:12: Fixed typing error.
Edit 2 13:41: Another one... sigh.
Post edited June 15, 2016 by Midoryu
![dewtech](https://images.gog.com/94fb8b02cafe2c31fc40eef94a561faccc68e71e3188c307fb5018513ddb47ed_forum_avatar.jpg)
dewtech
Jaded grognard
Registered: Aug 2011
From Estonia
Posted June 15, 2016
![avatar](http://images.gog.com/2b1be91f2916b44cfa1ebc2d95e92056db86db4e25fd513f9669b7e73a6c8207_avm.jpg)
![avatar](http://images.gog.com/57964887e6620f0e2653f91ab74cc14153e0d506320886e97a9902bdb5e38483_avm.jpg)
Better would be to start supporting Google Authenticator
![vsr](https://images.gog.com/f19db97f5a9b73769be104e355f0f708497f9b79a5d552db8b68362d90d60952_forum_avatar.jpg)
vsr
⭐⭐⭐⭐⭐
Registered: Jun 2012
From Russian Federation
Posted June 15, 2016
![avatar](http://images.gog.com/2b1be91f2916b44cfa1ebc2d95e92056db86db4e25fd513f9669b7e73a6c8207_avm.jpg)
![avatar](http://images.gog.com/57964887e6620f0e2653f91ab74cc14153e0d506320886e97a9902bdb5e38483_avm.jpg)
![blotunga](https://images.gog.com/bd1dd49e8b8de444fa1bf1d00e469b404b26acd6a37d4780cdaf3307642c90c2_forum_avatar.jpg)
blotunga
GrumpyOldGamers.CyringOutMiserably
Registered: Apr 2012
From Other
Posted June 15, 2016
Imho the benefits of 2FA outweigh the downsides. Everyone should use it, else they risk exactly this, loosing access to their account.
![Wishbone](https://images.gog.com/0955f36b801ddb313007a0b17fb322b8854562f12948c53db5b83bc890de168f_forum_avatar.jpg)
Wishbone
Red herring
Registered: Oct 2008
From Denmark
![Midoryu](https://images.gog.com/46ce75fc7a99b9c729570aeff9b76a8d9bd12d1b9bc06e22538c3e811c8f415f_forum_avatar.jpg)
Midoryu
is watching you
Registered: Aug 2012
From Germany
Posted June 15, 2016
high rated
![avatar](http://images.gog.com/0955f36b801ddb313007a0b17fb322b8854562f12948c53db5b83bc890de168f_avm.jpg)
Personally, I agree it would be nice to have the two separated, with account change authentication being opt-out, and login authentication being opt-in.
"Hi Midoryu, your e-mail address was changed" and ends with "If your email address was changed without your knowledge please contact our support team."
So it seems like two-factor authentication doesn't trigger on this one.
Also GOG states this on the ORDERS & SETTINGS/LOGIN AND SECURITY page:
"Two-step login is an optional extra layer of protection for your GOG.com account. With two-step login enabled, your identity will be verified through your email address whenever you log in from a new device, browser and/or location." Only used for login apparently, nothing else.
And yes, I understood what PaterAlf was suggesting and I'm all for it, because having more options is always better than having less. It should not be the main concern, however.
While this fixes a convenience issue, what HypersomniacLive brought more insistently to the table is a glaring security issue. Since he quoted a Blue, he obviously wanted to bring this to GOG's attention (again) and I just chimed in on that, because, like him, I believe it needs to be fixed and to be focused on above all else. I myself didn't knew about it beforehand, though. (So thanks for that.)
I hope I provided a better insight of what my intentions were with that earlier post.
(and for it to appear less confusing now)
Midoryu
PS: Gonna change my e-mail back now... And don't even get to confirm it!
_________________________________________________________________________
Edited 13:48: Added GOG two-step login explanation.
Edit 2 15:04: Rephrased the text to make it more obvious that PaterAlf mentioned the whole idea, already.
(Also typing errors.)
Post edited June 15, 2016 by Midoryu
![HypersomniacLive](https://images.gog.com/fc4a1abc37a5fe68e4e7fe666d87976d9900b9f928128c087fa9bbdf2e3e4bc4_forum_avatar.jpg)
HypersomniacLive
The Reluctant Voter
Registered: Sep 2011
From Vatican City
Posted June 15, 2016
high rated
![avatar](http://images.gog.com/46ce75fc7a99b9c729570aeff9b76a8d9bd12d1b9bc06e22538c3e811c8f415f_avm.jpg)
This is how it works on other places I have accounts. And this is how it should work here too, especially since the current "two-step login" works the way it works, which, from my understanding, doesn't affect the way account changes work.
But even if I have it wrong, since it's optional, the way account changes work should be fixed to offer protection to people that opt-out from the "two-step login" system.
![Wishbone](https://images.gog.com/0955f36b801ddb313007a0b17fb322b8854562f12948c53db5b83bc890de168f_forum_avatar.jpg)
Wishbone
Red herring
Registered: Oct 2008
From Denmark
Posted June 15, 2016
![avatar](http://images.gog.com/46ce75fc7a99b9c729570aeff9b76a8d9bd12d1b9bc06e22538c3e811c8f415f_avm.jpg)
![avatar](http://images.gog.com/734aeae7a4916aefed2dc8d56e75dc49b5dfd478fbf779ff55c1a00f62a318b9_avm.jpg)
This is how it works on other places I have accounts. And this is how it should work here too, especially since the current "two-step login" works the way it works, which, from my understanding, doesn't affect the way account changes work.
But even if I have it wrong, since it's optional, the way account changes work should be fixed to offer protection to people that opt-out from the "two-step login" system.
![HereForTheBeer](https://images.gog.com/a57f0bf54f93d6b7efe2ae73abc89cbd222c7bc556b25a2c8b0b32e12b8a9f75_forum_avatar.jpg)
HereForTheBeer
Positive Patty
Registered: Oct 2009
From United States
Posted June 15, 2016
Also GOG states this on the ORDERS & SETTINGS/LOGIN AND SECURITY page:
"Two-step login is an optional extra layer of protection for your GOG.com account. With two-step login enabled, your identity will be verified through your email address whenever you log in from a new device, browser and/or location."
So I got my 'XP' by turning on 2SA - thanks for the reminder, gOg. I regularly login from three devices: my fingerprint-locked phone, our kitchen PC, and my work laptop. Only the phone login required 2SA after turning it on, and that was only the first time I visited the site. The other two simply let me in like always. Granted, I did save the log-in credentials in the browser so I previously did not need to log in each time, but shouldn't it have required authentication at least the first time I visited the site on each device after turning on the feature? Or are those other logins getting a pass because the system recognizes the location by IP address?"Two-step login is an optional extra layer of protection for your GOG.com account. With two-step login enabled, your identity will be verified through your email address whenever you log in from a new device, browser and/or location."