Page 1 of 1

Major security concern

Posted: 13 July 2021, 10:45
by Antigeol
I tried to post this on bugs but that section only allows for game related bugs.
I play on and off on this website every few weeks/months and have some friends who do that on longer periods of time. One friend forwarded me a mail he received recently which was how its been a while since he last logged in and it suggested a game to try. He forwarded it to me cause its a gmae we both enjoy irl. The problem is that when I clicked on try the game instead of logging into my account it logged into my friends account. Mind you he has never had any access to my pc.
I think this is something that needs a major change and fast cause it seems to me that user credentials are getting accessed by people that shouldn't.

Re: Major security concern

Posted: 13 July 2021, 11:38
by MoiMagnus
I can confirm. I've just tried to look at one of my emails, and clicked on the link and it connected me to my account without even asking me my password.

Re: Major security concern

Posted: 13 July 2021, 12:36
by KongKing123
You can submit general bugs under "main website, not related to a game". No similar report seems to exist yet: https://boardgamearena.com/bugs?game=0

Can you post a redacted version of the link? There must be a parameter in there that causes this.

Re: Major security concern

Posted: 13 July 2021, 13:00
by sourisdudesert
Thanks for this message.

The intention was to make it easy for you to get back on BGA after a while, but as you stated it should not be done this way.

We will immediately fix this and find another way to achieve this goal.

Re: Major security concern

Posted: 13 July 2021, 13:47
by el cosimo
sourisdudesert wrote: 13 July 2021, 13:00 Thanks for this message.

The intention was to make it easy for you to get back on BGA after a while, but as you stated it should not be done this way.

We will immediately fix this and find another way to achieve this goal.
Never enable a system to add auto login.. still ask user / password. Or it must be with a token to use once… then maybe but still dangerous