Solid Theory

Step 3 of 5

Making an account and confirming your email address

Nearly every online game begins with a registration form and an email you have to confirm. Doing that part deliberately, once, gives you a routine you can reuse for every account you ever open.

Why there is an account at all

An online game keeps your progress on its own servers rather than on your computer, so it needs a way to recognise you when you come back. That is the honest technical reason for the account. There is a commercial reason as well: a registered, confirmed account is a person the studio can reach later.

Confirming an email address serves both purposes at once. It proves the address exists and belongs to whoever is holding the account, which helps with password recovery, and it gives the studio a working channel for notices and offers.

Knowing both reasons is useful because it tells you what to be careful about. The account itself is ordinary. The thing worth thinking about is which address you attach to it and what you do with the mail that follows.

Which email address to use

You have three reasonable options, and they suit different people.

Your everyday address is the simplest. You will see confirmation and recovery messages without checking anywhere else, which matters if you ever lose access to the account. The cost is that game-related mail lands in the same place as everything else.

A second address kept for accounts of this kind separates the mail cleanly and makes it obvious where a message came from. If a message about a game arrives in your main inbox and the account was registered to the other address, something is off, and that is a genuinely useful signal. The cost is remembering to check it.

A disposable or temporary address is the third option, and it is the one to avoid here. If you lose the address, you lose the ability to recover the account, and most recovery processes begin and end with email.

On shared computers

If the computer is shared, decide whose address the account uses before anyone fills in a form. An account registered to a housemate's address is that housemate's account to recover, whatever everyone intended at the time.

Passwords, and the one rule that matters

The single most valuable habit is not reusing passwords. A password that exists in only one place can only ever cost you that one account. A password you have used elsewhere turns any breach anywhere into a problem everywhere.

Length matters more than exotic characters. A passphrase of four or five unrelated words is easy to type and hard to guess. A password manager, which generates and stores long random passwords for you, removes the memory problem entirely and is worth the afternoon it takes to set up.

Current, detailed guidance on passphrases and on multi-factor authentication for individuals is published by the Australian Cyber Security Centre. Following a national body's published advice is a sounder basis than following any single website, including this one.

The sign-up routine

Seven steps, in order

  1. Decide the address first. Write it down before you open the form, so the decision is not made under pressure halfway through.
  2. Reach the sign-up page from an address you typed yourself. Typing the vendor's address into the browser means you know whose form you are filling in. This matters more than it sounds.
  3. Set a password used nowhere else. Generate it, or build a passphrase, and save it somewhere you trust.
  4. Fill in the required fields and leave the rest empty. Optional fields are optional. If something about location or date of birth is genuinely required, answer it accurately, because inaccurate answers cause trouble later with classification and with account recovery.
  5. Read what you are agreeing to, at least in outline. You are looking for two things: what the service may do with your details, and what happens to your account if you stop using it.
  6. Confirm the email address. The next section covers how to do that without being caught by an imitation.
  7. Log in once, straight away. An account you have never signed into is an account you cannot be sure works. Logging in is also the point at which most games consider the registration complete.

Reading a confirmation email properly

A genuine confirmation message arrives within a few minutes of your filling in the form, refers to the account you just created, and comes from a domain that belongs to the vendor. The domain is the part after the @ symbol, and it is the only part of a sender's address that is hard to fake convincingly.

Before using a link in such a message, look at where it goes. Most email programs show the destination when you hover over a link, or when you press and hold on a touch screen. The destination should be the vendor's own domain. If it is a string of characters on an unrelated domain, treat the message as unverified.

There is a method that avoids the question entirely. If the confirmation can be completed by typing a code into the vendor's site, do that instead of clicking. Open the site from an address you typed, log in, and finish the confirmation there. It takes thirty seconds longer and removes the entire category of problem.

When a message is not what it claims

Messages that imitate a service in order to collect your password are common, and gaming accounts are a frequent target because they can hold purchased items. The signals are consistent: urgency, a threat that the account will be closed, a link to a domain that is nearly but not exactly right, and a request to log in through that link.

The defence is simple and does not require you to judge any individual message. Never log in through a link in an email. Go to the site the way you normally would, by typing the address, and if there is a genuine problem with your account you will see it there.

Scamwatch, run by the National Anti-Scam Centre, publishes current information about scams reported in Australia and provides a way to report them. If you are unsure whether a message is genuine, that is the place to look rather than a search engine.

Two-factor authentication

Two-factor authentication means the account needs something beyond the password — typically a code from an app on your phone. It is the single change that most improves the security of an account, because a stolen password alone is then not enough.

If a game offers it, turn it on during setup rather than later. Store the recovery codes somewhere you will still have them if the phone is lost, which for most people means printed and filed rather than saved on the same phone.

If a game does not offer it, that is worth noting but is not in itself a reason to avoid the game. It does make the no-reuse rule more important, because the password is then the only thing protecting the account.

What happens to the details you hand over

When you register with a game, the vendor becomes the holder of your details, and their privacy policy — not this site's — governs what happens next. Many game vendors are based outside Australia, which means your details may be stored and processed overseas.

The Office of the Australian Information Commissioner is the body responsible for privacy regulation in Australia and publishes material on the Australian Privacy Principles and on how to make a privacy complaint. Reading how a vendor describes its own handling of personal information, before you register rather than after, is a reasonable five minutes.

The practical version of this is short. Give the minimum the form requires, use an address you control, and know that the details are leaving your computer.

The worked example, continued

The game used as the running example in this course sets out exactly this sequence. By the vendor's description, getting in means creating an account, confirming the email address attached to it, and then logging in to the game. There is nothing unusual in that: it is the ordinary shape of free-to-play registration, which is why it serves as the illustration.

Applying the routine above to it looks like this. Decide the address. Reach the sign-up form from the vendor's own site. Use a password that exists nowhere else. Complete the confirmation, preferring a typed code over a clicked link where that is offered. Log in once to check the account works. If a second factor is available in the account settings, switch it on.

Visit the Crossout website

Paid affiliate link. ISWORK s.r.o. may be paid a commission if you register an account after following it. The routine on this page is the same whether or not you use the link.

One honest note about that link and this course. Because the commission depends on a registration, you are entitled to read this step sceptically. The test to apply is whether the advice would change if the commission did not exist, and here it would not: the sequence above is the same one a security-minded person would use for a banking site.

The share house, at Step 3

Hypothetical example

A made-up household, used to show the method. No real people, no results claimed.

The three housemates hit the shared-computer problem immediately. The account cannot be "the house's" account, because recovery works through one mailbox. They settle it in a minute: the housemate who wants to play registers it to their own address, and the others accept that it is that person's account.

The password goes into a password manager rather than onto the whiteboard by the fridge. The confirmation email arrives, and the housemate who was once stung by a subscription insists on checking the sending domain before anyone touches the link — which is a sensible instinct, even though the message turns out to be exactly what it claims.

Before you move on

Before you move on

  • Decide which email address the account uses before you open the form, especially on a shared computer.
  • Never reuse a password. Length beats complexity, and a password manager removes the memory problem.
  • Reach sign-up and log-in pages by typing the address, not by following a link in a message.
  • Check the sending domain of a confirmation email, and prefer typed codes over clicked links.
  • Turn on two-factor authentication wherever it is offered, and keep the recovery codes off the phone.
  • The vendor's privacy policy governs what happens to your details, and the vendor may be overseas.

Step 3 checklist

Work through these before Step 4

  • Choose the email address this account will use, and write the choice down.
  • Confirm you can still receive mail at that address today.
  • Create a password that is not in use anywhere else, and store it in a password manager or somewhere equally safe.
  • Open the sign-up page by typing the vendor's address into the browser.
  • Complete only the fields marked as required, and answer any required age or location field accurately.
  • Before using a confirmation link, check the sender's domain and the link's destination.
  • Where a typed confirmation code is offered, use it instead of the link.
  • Log in once to confirm the account works.
  • Turn on two-factor authentication if the account settings offer it, and store the recovery codes away from your phone.
  • Note the vendor's privacy page so you can find it again.

The same list, in printable form, is on the All checklists page.