#0 - Nov. 20, 2007, 10:30 p.m.
Scenario: Large guild places many valuable guild assets in their bank, but restricts the access to certain trusted officers of the guild. Through great misfortune, the account of one of these trusted officers is hacked. While selling all the assets of the account, the hacker notices the guild bank, and then proceeds to sell off all the assets of the guild as well.
Blizzard, please implement a password option for the guild bank. Players with withdrawal rights to the guild bank would be required to enter the password before they could withdraw any items from the guild bank. Thus, a hacker only in possession of a player's account information would not be able to devastate the entire guild as well.
Guild leaders, I strongly recommend limiting the total daily withdrawals of any member so that no more than a few items would be lost this way, and the transaction log would be long enough to serve as proof of loss so items could be reinstated.
It is only a matter of time before this occurs with the current unsecure implementation.