The issue is, anyone's account is at risk of being stolen if one other person gets a glimpse at their 'Support ID`. Which is openly displayed when starting the app and also displayed right inside the menu tab, at the top of the page. For such sensitive information, it's openly displayed carelessly.
There is an option to create a password and a transfer ID. Which in the 'Terms Of Use` section, states that one would need BOTH to recover an account or transfer the account to a different device. As this game only allows one account to be accessed from one device at a time.
It's never mentioned just how important the actual 'Support ID` is and is literally the ONLY thing one needs for recovering/transferring an account. One can just contact support with the 'Support ID` and request a new 'Transfer ID`. As this is mainly an issue for content creators, anyone who lets someone play their account can secretly get the 'Support ID' & steal the account if they want. It's never even mentioned how important it is to keep the 'Support ID` secret & is openly displayed carelessly. No one would even know to keep it secret or how important it is to do so.
This whole system is outdated & very weak when it comes to security, and for this type of game, it can also be very expensive. There are a lot of accounts people have invested hundreds of dollars, some even thousands! Over the lifetime of the account. We need more security for our accounts! As these accounts are worth a lot of money & not to mention the hundreds of hours we invest in them.
There's currently no 2-step verification, or any kind of unique or personal info tied to the account. So anyone can provide a 'Support ID` & claim an account for their own; just by contacting support. No way to authorize a transfer or prevent 'Pokémon Duel Support` from issuing a new 'Transfer ID` to some random person who emails them with a 'Support ID`.
Initial Ideas for fixing these issues.
1.) They could allow us to register 1-2 email adresses to our unique account and only issue new 'Transfer IDs`or account specifics to emails from those specific emails.
2.) Do away with this transfer/Support ID system & allow us to link our account with any of the many methods: Google, Facebook, Game Center, or sign in/link with an email.
Giving us the option to link an email to our account would solve these issues I believe. We would no longer fear losing our account if a transfer ID doesn't work. We could authorize any transfer before it happens by being notified through email that someone is trying to issue a new transfer ID or support would know to not issue account information to any email but the ones we linked. We could literally just login with our email if they wanted to change their current login system.
We need change! Many many people have had their account lost or stolen. We have been begging for more account security and a better login system but not a single public response to these issues. Support denies any request to keep an email on file for a specific account & claims they don't keep any personal info on file. We as a community need this change to happen. ASAP!
By signing, you accept Care2's Terms of Service.
You can unsub at any time here.
Having problems signing this? Let us know.