30 Nov 2009 at 12:44 - 5
Additional ingame passwords (such like a pin) are weak workarounds for the general security problem. Another password that can get lost: additional load on the support.
The worst design flaw in the Guild Wars authentication scheme is that the username is an email address. Email addresses are made for the public. You are known by your email address. You use it all over the internet. But if your email address is known, already half of the login information to your game account is exposed. If you connected your game account to an Ncsoft account, it became impossible to change your game login name. One simple mistake from my side (using the same password for some shady forum login as my ingame login) and I am screwed. Being able to change the game login name and being forced to not use an email address would be a bigger security improvement, in my opinion.
A touchpad that must be clicked on (i know them from pda/smartphones) is an interesting idea, but be aware that keyloggers also can intercept mouseclicks and would be able to record mouse click positions. If you know "the next 4 clicks are on a 9-dot pad that is 300x300 pixels", you can easily guess the clicked dots. And if you shuffle the numbers, many people will not be able to enter their pin any more. I, for example, don't really remember my pin numbers for my bank's automated teller machine. I remember the positions on the numpad instead. If my pin were "1234", I would not remember "1234" but something like "top left, next, right, first down".