It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
An extra layer of protection for you and your account.

Today, we bring you two-step login: an optional extra layer of protection for your GOG.com account. In the coming weeks, we'll also be making all communication between you and GOG encrypted by default with HTTPS everywhere — both methods often requested on our wishlist, but also simply pretty smart to offer.




Two-Step Login
Two-step login is an extra layer of protection for your GOG.com account. Every once in a while, we'll ask you to verify your identity with a 4-character security code sent to your email. Simple stuff.

Two-step login is optional, but we really recommend it. It's designed to bug you only when we notice something unusual — like logging in from a new browser or location. By doing this, we make sure that there's no way to gain unauthorized access to your GOG.com account without both your GOG password and your email account. When used to its full potential with unique passwords for every account, two-step login can be virtually impenetrable.

To enable two-step login, simply head to your Login & Security settings, verify your email address, and enjoy the extra peace of mind. For more information, check out the FAQ.




Additionally, you can now end all of your active GOG.com sessions in one click — this includes every device or browser you ever logged in through. It's a handy feature if you've recently used a public computer, or if you simply want to be sure no device is still logged in to your account.







HTTPS everywhere
GOG Galaxy has already supported HTTPS everywhere for some time, and now we're beginning to roll it out globally. That means HTTPS support for every connection between you and GOG.com — all secured with industry-standard encryption. Every bit (and byte) of data that travels between you, us, and everyone on GOG.com will be encrypted, including the store, forum, chat, downloads and even all of GOG Galaxy. It truly is HTTPS everywhere.
Nice feature, but I found a small, quite annoying bug... Happened to me in browser and in Galaxy too (Windows 10 64bit):
entered password, so code request form appeared...
So I opened my e-mail client to check the code, and then I switched back to browser/Galaxy window (but by mouse clicking, not by alt-tabbing from e-mail client)... And that code request form disappeared....
So I had to click "connect now" button again, enter password, check the e-mail and remember to alt-tab...
Will there be support for google authenticator or a GOG mobile app so we don't have to worry about emails all the time?
God damn it, Gog you did this all wrong :(

You should've used universal TOTP stantard the one that works with Google Authenticator and other authenticators.

http://tools.ietf.org/html/rfc6238
avatar
songoqu: We think that covering all cases is much safer then only chosen ones, and don't forget that to do those actions you need to re-enter your password.
Yes, and if somebody could figure out the PW and e-mail gone is the protection. Not the case if you need to confirm such thing with replying to an e-mail like it is done virtally everywhere else.
Great news. Thanks, GOG. Considering the amount of money I've spent here over the years, I'm always happy to see my security options improve.
avatar
catpower1980: Oh yeah, it works now! I think the Web team can go on vacation for a month now :o)
Only after they fix the broken/missing FAQ, or rename the link to F4Q (Frequently 404'd Questions) :)
Why is the two-step system based on something that can still be broken into (email), and not more robust like using a cell phone to send a text to? Or both, even.
avatar
JudasIscariot: I believe that's been fixed :) Note I don't use any HTTPS plugins in Chrome :)
avatar
haydenaurion: I still don't get any https when going to the front main page first, I still have to navigate to the forums first to get https like before. Using Chrome.
Not sure what you can do, log out, clear cookies and cache, log in and see where that gets you?
avatar
fiiij: I hope the "two-step login" keeps optional. They use it over at Humble Bundle and it annoys the hell out of me, when I switch between my notebook and my desktop.
avatar
Johny.: We won't bug you for entering code when switching browsers - we will when accessing from new browser for the first time, or when the cookies were cleared (unfortunately, you could trust our cookies though), or session expires.

Try it. :)
Sadly, due to the rampant abuse of cookies for user tracking and such, many people have resorted to tools like this: https://addons.mozilla.org/en-US/firefox/addon/self-destructing-cookies/. Like the Phoenix rising from the ashes, my browser is born anew many times.

Trust. No. One. :-)
avatar
Johny.: or when the cookies were cleared (unfortunately, you could trust our cookies though)
And there the problems are starting. I only allow session cookies on all web browser for privacy reasons. On my main system I keep a list of exception, of sites that are allowed to store long lived cookies. But I won't be bothered to make these exceptions on all systems/browser.

So please keep it optional, there is at least one customer who will appreciate it.
avatar
catpower1980: Oh yeah, it works now! I think the Web team can go on vacation for a month now :o)
avatar
skeletonbow: Only after they fix the broken/missing FAQ, or rename the link to F4Q (Frequently 404'd Questions) :)
And properly secure the Mantis bug tracker and fix *that* FAQ. :-)
avatar
haydenaurion: I still don't get any https when going to the front main page first, I still have to navigate to the forums first to get https like before. Using Chrome.
avatar
JudasIscariot: Not sure what you can do, log out, clear cookies and cache, log in and see where that gets you?
I do that every time and it does nothing. Not sure if it's on my end or not.
avatar
JPaterson84: Why is the two-step system based on something that can still be broken into (email), and not more robust like using a cell phone to send a text to? Or both, even.
Why not use an email service that not can be broken into?
avatar
JudasIscariot: Not sure what you can do, log out, clear cookies and cache, log in and see where that gets you?
avatar
haydenaurion: I do that every time and it does nothing. Not sure if it's on my end or not.
Chrome version?
Thank you for listening to us GoG :)