Password recovery Question

6 replies [Last post]
AGTRigorMortis
Offline
Joined: 08/09/2015
Posts: 49

Hi everyone, I have been wondering because this issue got me worried recently.

Is it possible to use Visa or Paypal information to recover a Microsoft, gmail or Steam profile password?
If it isn’t, it should be IMO because credit info is something normally only the rightful account owner would know.

But I know you can use phone numbers and alternate email addresses to do such a thing.

By the way, I understand that it is our responsibility to remember passwords and to write them down, but life isn’t that black and white and sometimes we forget information that is important. Due to a mishap after creating a media creation tool for Windows 10 on my USB flash device, the notepad containing my old passwords got wiped without me knowing, which is strange seeing as you can make a bootable OS installation media for PS4 and PS3 on an external device and still keep your personal files. Luckily I had both email addresses on auto sign in on my other computer. I have since wrote my passwords down on pieces of paper and put phone numbers on both my email addresses for future reference.

eire1274
eire1274's picture
Offline
Joined: 09/12/2003
Posts: 1309

As far as I know, you need to be able to access an associated email address, or answer security questions in order to change the password. No system will tell you the existing password, as that is too easy to be intercepted online.

I know Steam does have additional options to recover stolen accounts, but you have to speak directly with their customer service folks.

Have fun, be safe! Sláinte!

Nick McDermott – 3dGM Admin

AGTRigorMortis
Offline
Joined: 08/09/2015
Posts: 49

I think accounts such as Steam, Gmail or Microsoft where you purchase stuff that is tied to your own account, these things aught to be directly tied to your personal information and your IP address. And if they are not, this needs fixing because I can imagine it being infuriating to forget passwords or worse, have them stolen.

I know Valve wants to keep accounts secure, but I do think it is a bit unfair that you cannot use credit info in conjunction with tracking your whereabouts to recover accounts when this is information that can be used to identify a person. They should be keeping records where all this stuff is coming from, such as your exact location then it would be nearly impossible for them to make a mistake then, surely. You bought the stuff digitally, it is rightfully yours only, that is the contract of the EULA.

Yes, I managed to recover my Steam and my emails, but only because of 2 things. 1) because I remembered my login on my other PC and 2) because I had my emails on auto login. I have taken this as my final warning so I wrote the passwords down on bits of paper and gave a copy to a trusted family member to keep safe and hidden for me.

Here’s the thing about stolen accounts, if they suspect your account is stolen, they can contact the police as hacking is illegal. Detectives aren’t stupid, they are paid to do a very important job. 🙂

Manic Mouse
Manic Mouse's picture
Offline
Joined: 02/01/2007
Posts: 139

Roboform and LastPass have been by go-to utilities for managing my passwords. Both have been solid as a rock for me.

Just don’t forget the master password you use for them or you are toast.

Mark Baker

Asus Maximus VIII Hero, Intel i7 6700K @4.2Ghz (stock speed), 32gb Corsair Vengeance Black 3200MHZ, MSI 970 Gaming 4G, Samsung 840 Evo, Vertex 4, Intel 510 & Adata SX900 SSDs, wrapped in a CoolerMaster HAF XM case. Monitor 27″ Samsung SyncMaster SA850 2560 x 1440

AGTRigorMortis
Offline
Joined: 08/09/2015
Posts: 49

I’ve been told there is a Norton utility that can be used to store passwords but I’m going to use a more direct and reliable way. I ordered an address book from Amazon and I am going to write it all down.

This is much more secure than say storing passwords on a flash key and having it plugged in all the time just to risk someone’s spyware app allowing them to look at your word files.

Manic Mouse your method is good too.

Manic Mouse
Manic Mouse's picture
Offline
Joined: 02/01/2007
Posts: 139

The address book idea is ok, but has a few shortcomings:

  • If you work in a high-security job your company may have a policy in effect forcing you change your password to something unique every 60-90 days. You will find that your little black book fills up pretty fast since you can’t really replace an old password in it with a new ‘current’ one multiple times without erasing a hole into the paper. Some password vaults keep a log of the passwords you have used for a particular site/application.
  • Anybody that gets their hands on your little black book can read the passwords without effort. Most password apps encrypt your password file with a master password (you are S.O.L. if you forget it).
  • It is really cumbersome to write down nonsense, non-dictionary passwords like “KEmHy~:GFck265wj”. With a password vault you can save logins as you create them and never have to actually type them in except for the once.
  • You have to physically type in those passwords every time you log into a site. I am personally a lazy bugger so I like having password vaults like roboform, lastpass and KeePass type them in for for me. I never have to bother with typing in a long, incomprehensible password.
  • Some vault apps like roboform will actually generate passwords for you like the one i used as an example. No brain-burn trying to think up nice unguessable passwords.
Sure a low tech way is reliable and simple, but consider where you would use passwords. On a computer. So it kinda makes sense to use something a computer can interact with to deal with application security. It is letting the computer do the work for you 🙂

AGTRigorMortis
Offline
Joined: 08/09/2015
Posts: 49

I am a home user and nobody else in the house will misuse my stuff, if it were at work in a business environment then you are right, it would matter, a heck of a lot more. I have them written down on my address book and trust me my accounts are secure, I’ll keep a 4tb Western Digital Green hard drive for backing up other stuff. I just got a 4tb Hitachi deskstar drive for my new gaming PC, the photos of the finished system are in the Hardware section.

Having a password vault is a good idea but like you said, if you forget your master password you are screwed. Unless your emails are on auto login that is, then you have a chance of recovering everything. The black book is old fashioned but it works and that is the main thing, besides you can use the book for a lot more than just passwords.