Uploaded image for project: 'Mojang Web Services'
  1. Mojang Web Services
  2. WEB-5629

Missing necessary info about migration requiring phone number

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Invalid
    • Icon: Normal Normal
    • Migration
    • None

      One day after migrating my account (i made a new Microsoft account for it) my account got locked because of """suspicious activity""" and i had to add a phone number to unlock or lose access to the account forever.

      This is problematic in multiple ways.

      First, because people have multiple minecraft accounts and alts. You need to make a new Microsoft account per alt, but you can not use the same phone number for multiple Microsoft accounts (and if you manage to do it, you raise more flags and get your account locked even sooner). If i have five minecraft accounts, i am supposed to own five phones now?

      Second, because a phone number in that context does not provide security for the user. If someone guessed or stole my password, he can add his own burner phone number and own my account. A phone number is also not necessary for 2FA (which isn't even enabled by default), TOTP is a more secure form of 2FA and doesn't need a phone.

      Third, because people lose phones or change phone numbers.

      While the second point is an issue with Microsofts false sense of security, the first one is an issue for minecraft specific migration.

      It should be mentioned in the Migration help and especially on the migration page, that a Microsoft account may require a phone number. This is the very minimum you should do.

            Unassigned Unassigned
            Doyeon Ayy LMAO (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: