With all these security problems concerning illegal access - is it possible to insert a seconday tier of security when logging in????
Perhaps freezing the account after three unsuccessful logins and emailing the player a new password??? Just a suggestion.
LOGIN SECURITY
-
D00ML0RD
- Fledgling Forumer
- Posts: 223
- Joined: Sat Oct 29, 2005 8:57 am
- ID: 0
LOGIN SECURITY
********MASTER of comebacks********
-
MAsterp
- Forum Intermediate
- Posts: 759
- Joined: Sun Sep 18, 2005 4:34 pm
- ID: 0
- Location: New York, USA
Re: LOGIN SECURITY
DOOM LORD wrote:With all these security problems concerning illegal access - is it possible to insert a seconday tier of security when logging in????
Perhaps freezing the account after three unsuccessful logins and emailing the player a new password??? Just a suggestion.
A great suggestion! I believe they have this on paypal

-
Sleipnir
- Merriest Mod in the West
- Posts: 2340
- Joined: Tue Feb 15, 2005 11:16 pm
- ID: 0
- Location: Off-world
-
Honours and Awards
-
The Dalek Empire
- Fledgling Forumer
- Posts: 248
- Joined: Fri May 13, 2005 1:31 am
- Wolf359
- The Big Bad Admin
- Posts: 5208
- Joined: Sat Feb 19, 2005 2:40 am
- Alliance: EPA
- Race: Tauri
- ID: 0
- Location: Omnipresent
- Contact:
-
Honours and Awards
But where will it all end? Until recently people have complained that they would like the email details removed from the login procedure - but now people are asking for another level of security.
Sleip is correct - having a lockout is the wrong way to go as someone could just maliciously enter your name and then other details incorrectly, just to freeze you out.
A two password system? How would that work? You have to enter 2 passwords each time? This goes back to people previously being annoyed about having to put the email in - and, when somebody is hacked under the two password system, what do we do then, go to three?
Or you might mean that we have to select 2 passwords, but when we login the game asks us for one of them randomly. If this is what you mean - why not take it a stage further.
We keep the current level of 3 pieces of information being required to login. These would be:
1. Name (Wolf359)
2. Email (mailto:abc@123.com)
3. Any 1 additional piece of information from a list of 3, including a password.
for 3. what you would have to do when you register is supply a passwrod, plus the answers to 2 other questions that you already know the answer to (i.e. Mother's maiden name etc). Then, you are randomly asked one of these questions as part of the login process.
An alternative may be to keep login as it is, but to ask for an additional confirmation password if it looks like something dodgy may be happening to the account. i.e. to confirm account deletion, or if multiple (3?) trades and or transfers are set up, or a certain level of resources is being moved to someone else.
A further alternative may be to ask for an additional confirmation password if the account is accessed from an IP other than the usual one (although this would mean that 'the usual one' would somehow have to be determined).
Just a few ideas for the pot.
Sleip is correct - having a lockout is the wrong way to go as someone could just maliciously enter your name and then other details incorrectly, just to freeze you out.
A two password system? How would that work? You have to enter 2 passwords each time? This goes back to people previously being annoyed about having to put the email in - and, when somebody is hacked under the two password system, what do we do then, go to three?
Or you might mean that we have to select 2 passwords, but when we login the game asks us for one of them randomly. If this is what you mean - why not take it a stage further.
We keep the current level of 3 pieces of information being required to login. These would be:
1. Name (Wolf359)
2. Email (mailto:abc@123.com)
3. Any 1 additional piece of information from a list of 3, including a password.
for 3. what you would have to do when you register is supply a passwrod, plus the answers to 2 other questions that you already know the answer to (i.e. Mother's maiden name etc). Then, you are randomly asked one of these questions as part of the login process.
An alternative may be to keep login as it is, but to ask for an additional confirmation password if it looks like something dodgy may be happening to the account. i.e. to confirm account deletion, or if multiple (3?) trades and or transfers are set up, or a certain level of resources is being moved to someone else.
A further alternative may be to ask for an additional confirmation password if the account is accessed from an IP other than the usual one (although this would mean that 'the usual one' would somehow have to be determined).
Just a few ideas for the pot.
Mod SpeakSeverian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.
-
D00ML0RD
- Fledgling Forumer
- Posts: 223
- Joined: Sat Oct 29, 2005 8:57 am
- ID: 0
LOGIN SECURITY
Hey Wolf thanks for the input. I like your ideas - 
********MASTER of comebacks********
-
agapooka
- Semper Ubi Sub Ubi
- Posts: 2607
- Joined: Thu Mar 31, 2005 4:34 am
- ID: 0
-
Honours and Awards
The game is just weakly coded. I had my SD co-admin (Streamdown.NET co-admin) check around. According to him, everything should be rewritten. He offers to do it, but anyways, I haven't received anything from admin on the matter.
-Jason
-Jason
Agapooka wrote:The argument that because a premise cannot be proven false, it must be true, is known as a Negative Proof Fallacy in logic.
Pooka's UU Market Loyalty Card:Mister Sandman wrote:Nothing at all near the negative proof fallacy in logic. If it cannot be proven false, it has to be true.
Rudy Pena: 1 stamp!
A Spider: 1 stamp!
-
eggsalad
- Forum Grunt
- Posts: 61
- Joined: Tue Feb 14, 2006 6:32 pm
- ID: 0
ya i just thot of sumting sorta lik wat wolf said. lik wen u create ur account. u put in the 3 stuff. ur name,email, and password. then it could hav u make up a question and u answer the question. then wen u log on u put ur question and answer. for example: ur question- who was the first president of the united states of america. ur answer- george washington. sorta lik wat they hav u do wen u make ur email address.
"ive never backed down from a fight before and id be danmed if i start now"
"i do wat i want, wen i want, were i want"
"i do wat i want, wen i want, were i want"
- Wolf359
- The Big Bad Admin
- Posts: 5208
- Joined: Sat Feb 19, 2005 2:40 am
- Alliance: EPA
- Race: Tauri
- ID: 0
- Location: Omnipresent
- Contact:
-
Honours and Awards
eggsalad wrote:ya i just thot of sumting sorta lik wat wolf said. lik wen u create ur account. u put in the 3 stuff. ur name,email, and password. then it could hav u make up a question and u answer the question. then wen u log on u put ur question and answer. for example: ur question- who was the first president of the united states of america. ur answer- george washington. sorta lik wat they hav u do wen u make ur email address.
or even exactly like I said!
Mod SpeakSeverian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.
-
eggsalad
- Forum Grunt
- Posts: 61
- Joined: Tue Feb 14, 2006 6:32 pm
- ID: 0
o ya i just noticed. i red it then i made my post. then i red ur thing again and noticed dat it was exactly wat u said. plz dont mind me im a little off today. ( actually im always off but dats besides the point)
"ive never backed down from a fight before and id be danmed if i start now"
"i do wat i want, wen i want, were i want"
"i do wat i want, wen i want, were i want"
-
pianomutt20000
- Forum Zombie
- Posts: 5018
- Joined: Mon Oct 17, 2005 1:26 am
- Race: Tauri
- ID: 0
- Location: Saving lives in the desert of CA.
Wolf359 wrote:But where will it all end? Until recently people have complained that they would like the email details removed from the login procedure - but now people are asking for another level of security.
Sleip is correct - having a lockout is the wrong way to go as someone could just maliciously enter your name and then other details incorrectly, just to freeze you out.
A two password system? How would that work? You have to enter 2 passwords each time? This goes back to people previously being annoyed about having to put the email in - and, when somebody is hacked under the two password system, what do we do then, go to three?
Or you might mean that we have to select 2 passwords, but when we login the game asks us for one of them randomly. If this is what you mean - why not take it a stage further.
We keep the current level of 3 pieces of information being required to login. These would be:
1. Name (Wolf359)
2. Email (mailto:abc@123.com)
3. Any 1 additional piece of information from a list of 3, including a password.
for 3. what you would have to do when you register is supply a passwrod, plus the answers to 2 other questions that you already know the answer to (i.e. Mother's maiden name etc). Then, you are randomly asked one of these questions as part of the login process.
An alternative may be to keep login as it is, but to ask for an additional confirmation password if it looks like something dodgy may be happening to the account. i.e. to confirm account deletion, or if multiple (3?) trades and or transfers are set up, or a certain level of resources is being moved to someone else.
A further alternative may be to ask for an additional confirmation password if the account is accessed from an IP other than the usual one (although this would mean that 'the usual one' would somehow have to be determined).
Just a few ideas for the pot.
Wolf, man I hadn't thought about that.....I could lock someone out, then mass him when he's locked out. He get's logged back in.....NOTHING LEFT hahahahaha. I agree, bad idea. hmmm I like your idea about if it's accessed from another IP. It should have another layer, like a question..
What is your favorite pet or somesuch.
Sometimes some of the mods will try to step on you, or even mod your section. My advice is to fill a sock with marbles and hit them repeatedly until they stop. - Pianomutt2000.urban assault wrote: Bill? Hey, I said I was kidding! Bill, don't push that red button!
-
_Predator_
- Forum Irregular
- Posts: 398
- Joined: Sun Jun 05, 2005 6:16 am
- ID: 0
-
Groupthink
- Forum Grunt
- Posts: 50
- Joined: Sat Oct 15, 2005 8:21 pm
- ID: 0
- Location: The sun is directly above me....now!
For a start, what about not requiring the email address each time (since it's easy to find) and instead requiring a second password in that spot. It would allow the page setup to stay the same but would increase the security.
The problem I'd see with getting banned long term for 3 failed logins, is when I try to log into main using my Chaos password. Sometimes the old brain cramps up on me, and it's a few tries before I realize I selected the wrong page from favorites... I'd hate to be harassing admin for days while I tried to get access to my account again.
The problem I'd see with getting banned long term for 3 failed logins, is when I try to log into main using my Chaos password. Sometimes the old brain cramps up on me, and it's a few tries before I realize I selected the wrong page from favorites... I'd hate to be harassing admin for days while I tried to get access to my account again.
My feedback thread - http://herebegames.com/StarGateWars/vie ... highlight=
- Wolf359
- The Big Bad Admin
- Posts: 5208
- Joined: Sat Feb 19, 2005 2:40 am
- Alliance: EPA
- Race: Tauri
- ID: 0
- Location: Omnipresent
- Contact:
-
Honours and Awards
I think we can safely rule out the 'locking out' option - even for particular IPs - remember some people play from school or work, so someone could maliciously lock them out on purpose from the same location.
Mod SpeakSeverian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.

