Step 4 of 5

Step 4 — Setting up the account and checking the privacy settings

This is the step where something is actually created. Seven decisions are made in about twenty minutes, and six of them are far easier to make now than to change in a year's time.

The order the decisions come in

A sign-up form asks for things in the order that suits the vendor. The order that suits you is slightly different, and it is worth having it written down before you open the page, because form fields are persuasive and a blank text box invites you to fill it.

  1. Choose the mailbox that will own the account.
  2. Create a password that exists nowhere else.
  3. Record it somewhere you will find it again.
  4. Complete activation from the vendor's confirmation email.
  5. Turn on a second factor if one is offered, and keep the recovery codes.
  6. Review the privacy, chat and marketing settings before playing.
  7. Decide about payment details, which for most households means storing none.

Everything below expands one of those seven. They are written in general terms that apply to any online game account, because every vendor's screens look different and will have been redesigned by the time you read this.

Choosing the mailbox

The account's email address is its recovery route. If you lose the password, the reset message goes there; if someone else tries to change the account, the warning goes there too. An address nobody reads is therefore not neutral, it is a gap.

Three practical rules cover most households. Use an address that will still exist in five years, which rules out an address supplied by a school, a university or an employer. Use one a responsible adult reads if a young person will play. And do not use the same address with the same password you use for that mailbox itself; the mailbox password should be unique even among unique passwords, because it can reset everything else.

Some people keep one mailbox for games and hobby accounts and another for banking and official matters. That is a reasonable arrangement and costs nothing, provided the hobby mailbox is still checked.

A password used nowhere else

The single most useful property of a password is that it is used in one place only. Length matters more than punctuation: a passphrase of four or five unrelated words is both easier to remember and harder to guess than a short word with symbols substituted into it. The Australian Cyber Security Centre publishes general guidance for home users on passphrases and password managers, and it is the right source to read rather than any rule of thumb repeated here.

A password manager is the most practical way to achieve uniqueness across many accounts, because it removes the need to remember any of them. If you would rather not use one, writing a passphrase on paper and keeping that paper away from the computer is an old method that still works, and is better than reusing a password you already use for email or banking.

What to avoid is short: anything you have used elsewhere; anything built from a name, a birthday or a team; and anything you would be willing to type into a page you reached from a link in a message.

The second factor

Two-factor authentication means that signing in needs the password plus one other thing, usually a code from an app on a phone. Where a vendor offers it, switching it on is a few minutes of work and makes a stolen password insufficient by itself.

The part people skip is the recovery codes. When two-factor is switched on, most services show a short list of one-time codes to use if the phone is lost. Save them somewhere that is not the phone — printed, or in a password manager — because a lost phone with no recovery codes is the most common way people lock themselves out of their own accounts.

If the vendor does not offer a second factor, that is not a reason to panic and not a reason this course will tell you to buy anything. It simply means the password is doing all the work, so its uniqueness matters more.

Activation and the email that arrives

After the form is submitted, the vendor normally sends a confirmation message with a link. Following it proves the address is yours and finishes creating the account. If it has not arrived in a few minutes, look in the junk or spam folder before requesting another, and check the address you typed for a transposed letter.

Open that link from the message itself rather than from any other page offering to help you confirm an account. This is the one moment in the whole process when you are expecting an email with a link in it, which is exactly the moment an imitation is most likely to be believed.

The settings worth changing on day one

Account settings are easier to adjust before habits form. Five are worth opening immediately, and all five exist in some form on most online games.

Profile visibility
Who can see your profile, your statistics and your activity. Narrowing this costs you nothing on the first day.
Chat and voice
Whether strangers can message or speak to you, and whether chat is on by default. For a young player this is usually the most consequential setting in the game.
Friend and group invitations
Whether anyone may send a request, or only people you have played with. Unsolicited invitations are a common first move in both nuisance and fraud.
Marketing preferences
Whether the vendor may email you about offers. If a young person's account exists, this one is worth turning off deliberately.
Linked accounts
Whether the game is connected to a social account. Each link is a second door to the same room, and each should be a deliberate choice.

If something goes wrong between players — harassment, threats, unwanted contact with a child — the game's own reporting tool is the first route, and the eSafety Commissioner sets out what can be reported to it and how. Reading that before it is needed takes ten minutes and saves a bad evening.

Payment details

The limit written down in Step 3 survives or fails here. An account with no stored payment method requires a deliberate act for every purchase, and that friction is the point. If a card must be stored, keep it off any account a young person signs into, and check the receipts that arrive in the mailbox you chose at the start of this step.

Any account that holds a payment method deserves the second factor more, not less.

Messages that pretend to be the vendor

Popular games attract imitation. The common forms are a message saying an account will be suspended unless you confirm it, an offer of in-game currency from a site unconnected to the vendor, and a friend request followed by a link. All three work the same way: they move you to a page that looks like the sign-in screen and collect what you type.

The general defence does not require any product. Reach the vendor's sign-in page by typing the address yourself or using your own bookmark, never from a link you were sent. Treat any message creating time pressure as suspect on that basis alone. Scamwatch publishes current examples and takes reports, and it is worth a look when something feels wrong.

The product named in this course

If you want to carry the seven decisions above through to a real sign-up, one product is named here. The affiliate network that operates the link states that World of Warships runs an affiliate program paying commission on a single opt-in, a download, and the creation and activation of an account. It is offered for desktop computers running Windows or Mac, and Linux is not included. Its own site is the place to read what the product is, what it requires and what, if anything, it costs; those are not restated here.

Visit the World of Warships website

A worked example

The invented household from the homepage uses an adult's long-standing mailbox rather than the teenager's school address. The password is a four-word passphrase stored in a password manager, used for nothing else. Two-factor is switched on and the recovery codes are printed and kept in a drawer. Before the first session they open the settings and narrow profile visibility, limit chat to people already on the friend list, and turn marketing email off. No card is stored. The household is hypothetical and no result is claimed for it; what is being shown is that all of this happened before anyone played, which is the only time it is easy.

Before you move on

You should now have, or know exactly how to create, an account owned by a mailbox someone reads, protected by a password used nowhere else and a second factor if one exists, with its visibility and chat settings deliberately set and no card stored. Step 5 is about what happens over the following months.

Checklist for Step 4

  • Use an email address that will still exist in five years and that someone reads.
  • Do not use a school, university or employer address for the account.
  • Create a passphrase of several unrelated words, used for this account only.
  • Store it in a password manager, or on paper kept away from the computer.
  • Check that the mailbox's own password is unique as well.
  • Follow the activation link from the vendor's own email, checking junk if it has not arrived.
  • Switch on two-factor authentication if the vendor offers it.
  • Save the two-factor recovery codes somewhere that is not the phone.
  • Narrow profile visibility before the first session.
  • Set chat and voice to suit the person playing, especially if that person is young.
  • Restrict who may send friend or group invitations.
  • Turn marketing email off unless you want it.
  • Review any linked social accounts and remove links you did not intend.
  • Store no payment method unless you have decided otherwise deliberately.
  • Reach the sign-in page by bookmark or typed address, never from a link in a message.