• We have updated our Community Code of Conduct. Please read through the new rules for the forum that are an integral part of Paradox Interactive’s User Agreement.

konbendith

Sergeant
137 Badges
Oct 8, 2018
76
843
  • Europa Universalis IV: Call to arms event
  • Europa Universalis IV: Third Rome
  • Surviving Mars: First Colony Edition
  • Victoria: Revolutions
  • Impire
  • King Arthur II
  • Knights of Pen and Paper +1 Edition
  • Cities: Skylines
  • The Kings Crusade
  • Cities: Skylines Deluxe Edition
  • Majesty 2
  • Majesty 2 Collection
  • March of the Eagles
  • Europa Universalis IV: El Dorado
  • Hearts of Iron III
  • Rome Gold
  • Semper Fi
  • Sengoku
  • Ship Simulator Extremes
  • Sword of the Stars
  • Sword of the Stars II
  • Supreme Ruler 2020
  • Teleglitch: Die More Edition
  • The Showdown Effect
  • Victoria 2
  • Victoria 2: A House Divided
  • Victoria 2: Heart of Darkness
  • Europa Universalis IV: Common Sense
  • Ancient Space
  • Arsenal of Democracy
  • Cities in Motion
  • Cities in Motion 2
  • War of the Roses
  • Warlock: Master of the Arcane
  • Pillars of Eternity
  • Warlock 2: The Exiled
  • Warlock 2: Wrath of the Nagas
  • Magicka 2
  • Rome: Vae Victis
  • Heir to the Throne
  • Crusader Kings II: Horse Lords
  • Darkest Hour
  • Hearts of Iron IV: No Step Back
  • Divine Wind
  • Europa Universalis IV
  • Crusader Kings II: Way of Life
  • Magicka 2: Ice, Death and Fury
  • For The Glory
  • For the Motherland
  • A Game of Dwarves
We have recently tracked attempts to maliciously access data from Paradox accounts. While no actual security breach has occurred in our systems, we’ve confirmed that a small number of accounts have been accessed, most likely without the users’ consent. As Paradox systems have not been compromised, this is likely due to the use of an externally compromised password for your account.

We have informed the users affected by email, so if you haven’t heard from us, it means your account is safe. We’ve also deployed measures to secure the affected accounts and prevent similar issues in the future. Payment information, including credit card numbers, are stored separately and have not been at risk.

If you’re using a password with a low level of complexity, or if you are using a username or password for your Paradox accounts identical to accounts on other systems this is a good opportunity for you to update your account with a stronger password.

Our recommendation is always to go with a unique password, complex enough to ensure proper security; generally, a series of multiple keywords is the most secure and easy-to-remember option. We recommend the use of a password manager and ensuring that you are not reusing passwords as a security precaution for the future.
 
Paradox should put in place 2-factor-authentication, it would greatly secure user accounts. Has there been a discussion of adding it?
 
I would not be opposed to two-factor but it really does create a bit of a hassle. I think we could benefit from it though.
 
Paradox should put in place 2-factor-authentication, it would greatly secure user accounts. Has there been a discussion of adding it?

Hi,

Adding MFA has been discussed and could be a great way to add more security to accounts. You're likely to hear more about security measures in the near future as we explore various options. We always appreciate additional input from our players.
 
Hi,

Adding MFA has been discussed and could be a great way to add more security to accounts. You're likely to hear more about security measures in the near future as we explore various options. We always appreciate additional input from our players.

Considering that my paradox login is now linked to a lot more than just this forum (payment system, paradox launcher, paradox mod platform, other linked services) it would be good to see the platform work towards industry standards such as the OWASP Application Security Verification Standard.

My personal bugbear is not being able to see my currently logged in sessions. My account could be compromised and I would have absolutely no idea.
 
Paradox should put in place 2-factor-authentication, it would greatly secure user accounts. Has there been a discussion of adding it?

Hopefully not until their system can actually remember when we’re logged in. I’m not going to do two factor authentication multiple times a day.
 
Hopefully not until their system can actually remember when we’re logged in. I’m not going to do two factor authentication multiple times a day.
Well, that's kinda my point. I can't tell if it's losing my sessions, or if someone else is logging in and expiring my sessions :)
 
Well, that's kinda my point. I can't tell if it's losing my sessions, or if someone else is logging in and expiring my sessions :)

Well, we do know that P’dox, for some reason unknown to us, has a serious issue with keeping us logged in, so its 99.99% that, rather than someone logging you out.
 
Big IT companies try to silently sweep massive data breaches under the rug.

Paradox informs you if they notice suspicious behavior they aren't even responsible/accountable for.

Bravo.
 
Hi,

Adding MFA has been discussed and could be a great way to add more security to accounts. You're likely to hear more about security measures in the near future as we explore various options. We always appreciate additional input from our players.
keep in mind that not everyone has a cell phone, and that any plan should be designed in a way as to not lock longtime legitimate people out of their accounts.
 
Thanks for the information.
 
Thanks for letting us know. For some reason, I picture an attempted hack attack triggering flashing red lights and a WW2 air raid siren in the Paradox offices:).
 
Thanks for the heads up.