Bug of Account Management

Bug of Change Email Address

https://www.stardock.com/accounts/accountinfo

I find a very important Bug about 'Changing E-mail address' in Account management !

When I want to change my E-mail address, one confirmation E-mai will be sent to the new E-mail address, then I confirm it to change to use new E-mail address to sign in your website.

Do you find something wrong with the function flow above?

The confirmation E-mail should be sent to the old E-mail address to assure the changes were made by the Users ,not by others.

If someone else use my user name to sign in your web, then change the E-mail address to his,how can I get my account back?

I have not seen website which allow members to change their User Name, and this is very very dangerous! Especially change E-mail address which is used as user name.

Please fix the bug ,ASAP!

12,250 views 3 replies
Reply #1 Top

There is little value in sending a confirmation email to the 'old' address as typically the reason for changing an email address is because the old one is no longer relevant and/or accessible by the User.

If you have logged into your account in order to change/update email details, etc.  then your access is 'protected' by your login Password.

The facility to change a User Name is valuable, particularly when one chosen is too similar to another's and is thus confusing, or is perhaps inappropriate and 'needs' to be changed.

In your scenario 'someone else' needs BOTH your user name AND your access password...something identical with any other website access protection, ergo this is not a 'bug'...;)

Reply #2 Top

If someone use my user name and password to log in website,then change the  E-mail to his, how can I get my account back?

Reply #3 Top

Quoting xueld, reply 2

If someone use my user name and password to log in website,then change the  E-mail to his, how can I get my account back?

As with any site - you would contact the site's Administrators with the notification that your User ID had been 'hacked'/stolen and the culprit would have his IP blocked.

On commercial sites it is all about the protection of Identity with regards to sales/purchases...;)