LOGIN SECURITY

D00ML0RD
Fledgling Forumer
Posts: 223
Joined: Sat Oct 29, 2005 8:57 am
ID: 0

LOGIN SECURITY

With all these security problems concerning illegal access - is it possible to insert a seconday tier of security when logging in????

Perhaps freezing the account after three unsuccessful logins and emailing the player a new password??? Just a suggestion.
********MASTER of comebacks********
~not telling~

that would be interesting. and good for the security.
MAsterp
Forum Intermediate
Posts: 759
Joined: Sun Sep 18, 2005 4:34 pm
ID: 0
Location: New York, USA

Re: LOGIN SECURITY

DOOM LORD wrote:With all these security problems concerning illegal access - is it possible to insert a seconday tier of security when logging in????

Perhaps freezing the account after three unsuccessful logins and emailing the player a new password??? Just a suggestion.


A great suggestion! I believe they have this on paypal :D
Image
Sleipnir
Merriest Mod in the West
Posts: 2340
Joined: Tue Feb 15, 2005 11:16 pm
ID: 0
Location: Off-world

Honours and Awards

One problem. You can do this to someone just to annoy them, having their password changed.
Image

As soon as you build an idiot proof system, somebody else builds a better idiot.

If it moves, kill it. If it doesn't move, kick it until it does move, and then kill it.
The Dalek Empire
Fledgling Forumer
Posts: 248
Joined: Fri May 13, 2005 1:31 am

A two password system perhaps?
User avatar
Wolf359
The Big Bad Admin
Posts: 5208
Joined: Sat Feb 19, 2005 2:40 am
Alliance: EPA
Race: Tauri
ID: 0
Location: Omnipresent
Contact:

Honours and Awards

But where will it all end? Until recently people have complained that they would like the email details removed from the login procedure - but now people are asking for another level of security.

Sleip is correct - having a lockout is the wrong way to go as someone could just maliciously enter your name and then other details incorrectly, just to freeze you out.

A two password system? How would that work? You have to enter 2 passwords each time? This goes back to people previously being annoyed about having to put the email in - and, when somebody is hacked under the two password system, what do we do then, go to three?

Or you might mean that we have to select 2 passwords, but when we login the game asks us for one of them randomly. If this is what you mean - why not take it a stage further.

We keep the current level of 3 pieces of information being required to login. These would be:

1. Name (Wolf359)
2. Email (mailto:abc@123.com)
3. Any 1 additional piece of information from a list of 3, including a password.

for 3. what you would have to do when you register is supply a passwrod, plus the answers to 2 other questions that you already know the answer to (i.e. Mother's maiden name etc). Then, you are randomly asked one of these questions as part of the login process.

An alternative may be to keep login as it is, but to ask for an additional confirmation password if it looks like something dodgy may be happening to the account. i.e. to confirm account deletion, or if multiple (3?) trades and or transfers are set up, or a certain level of resources is being moved to someone else.

A further alternative may be to ask for an additional confirmation password if the account is accessed from an IP other than the usual one (although this would mean that 'the usual one' would somehow have to be determined).

Just a few ideas for the pot.
Image
Severian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.
Mod Speak
D00ML0RD
Fledgling Forumer
Posts: 223
Joined: Sat Oct 29, 2005 8:57 am
ID: 0

LOGIN SECURITY

Hey Wolf thanks for the input. I like your ideas - :D
********MASTER of comebacks********
agapooka
Semper Ubi Sub Ubi
Posts: 2607
Joined: Thu Mar 31, 2005 4:34 am
ID: 0

Honours and Awards

The game is just weakly coded. I had my SD co-admin (Streamdown.NET co-admin) check around. According to him, everything should be rewritten. He offers to do it, but anyways, I haven't received anything from admin on the matter.

-Jason
Agapooka wrote:The argument that because a premise cannot be proven false, it must be true, is known as a Negative Proof Fallacy in logic.
Mister Sandman wrote:Nothing at all near the negative proof fallacy in logic. If it cannot be proven false, it has to be true.
Pooka's UU Market Loyalty Card:

Rudy Pena: 1 stamp!

A Spider: 1 stamp!
eggsalad
Forum Grunt
Posts: 61
Joined: Tue Feb 14, 2006 6:32 pm
ID: 0

ya i just thot of sumting sorta lik wat wolf said. lik wen u create ur account. u put in the 3 stuff. ur name,email, and password. then it could hav u make up a question and u answer the question. then wen u log on u put ur question and answer. for example: ur question- who was the first president of the united states of america. ur answer- george washington. sorta lik wat they hav u do wen u make ur email address.
"ive never backed down from a fight before and id be danmed if i start now"
"i do wat i want, wen i want, were i want"
User avatar
Wolf359
The Big Bad Admin
Posts: 5208
Joined: Sat Feb 19, 2005 2:40 am
Alliance: EPA
Race: Tauri
ID: 0
Location: Omnipresent
Contact:

Honours and Awards

eggsalad wrote:ya i just thot of sumting sorta lik wat wolf said. lik wen u create ur account. u put in the 3 stuff. ur name,email, and password. then it could hav u make up a question and u answer the question. then wen u log on u put ur question and answer. for example: ur question- who was the first president of the united states of america. ur answer- george washington. sorta lik wat they hav u do wen u make ur email address.


or even exactly like I said!
Image
Severian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.
Mod Speak
eggsalad
Forum Grunt
Posts: 61
Joined: Tue Feb 14, 2006 6:32 pm
ID: 0

o ya i just noticed. i red it then i made my post. then i red ur thing again and noticed dat it was exactly wat u said. plz dont mind me im a little off today. ( actually im always off but dats besides the point)
"ive never backed down from a fight before and id be danmed if i start now"
"i do wat i want, wen i want, were i want"
pianomutt20000
Forum Zombie
Posts: 5018
Joined: Mon Oct 17, 2005 1:26 am
Race: Tauri
ID: 0
Location: Saving lives in the desert of CA.

Wolf359 wrote:But where will it all end? Until recently people have complained that they would like the email details removed from the login procedure - but now people are asking for another level of security.

Sleip is correct - having a lockout is the wrong way to go as someone could just maliciously enter your name and then other details incorrectly, just to freeze you out.

A two password system? How would that work? You have to enter 2 passwords each time? This goes back to people previously being annoyed about having to put the email in - and, when somebody is hacked under the two password system, what do we do then, go to three?

Or you might mean that we have to select 2 passwords, but when we login the game asks us for one of them randomly. If this is what you mean - why not take it a stage further.

We keep the current level of 3 pieces of information being required to login. These would be:

1. Name (Wolf359)
2. Email (mailto:abc@123.com)
3. Any 1 additional piece of information from a list of 3, including a password.

for 3. what you would have to do when you register is supply a passwrod, plus the answers to 2 other questions that you already know the answer to (i.e. Mother's maiden name etc). Then, you are randomly asked one of these questions as part of the login process.

An alternative may be to keep login as it is, but to ask for an additional confirmation password if it looks like something dodgy may be happening to the account. i.e. to confirm account deletion, or if multiple (3?) trades and or transfers are set up, or a certain level of resources is being moved to someone else.

A further alternative may be to ask for an additional confirmation password if the account is accessed from an IP other than the usual one (although this would mean that 'the usual one' would somehow have to be determined).

Just a few ideas for the pot.






Wolf, man I hadn't thought about that.....I could lock someone out, then mass him when he's locked out. He get's logged back in.....NOTHING LEFT hahahahaha. I agree, bad idea. hmmm I like your idea about if it's accessed from another IP. It should have another layer, like a question..

What is your favorite pet or somesuch. :D
Image
urban assault wrote: Bill? Hey, I said I was kidding! Bill, don't push that red button!
Sometimes some of the mods will try to step on you, or even mod your section. My advice is to fill a sock with marbles and hit them repeatedly until they stop. - Pianomutt2000.
_Predator_
Forum Irregular
Posts: 398
Joined: Sun Jun 05, 2005 6:16 am
ID: 0

wat if it locks an ip out after trying to log in 3 times
I got banned...well now isnt that nice :)
Groupthink
Forum Grunt
Posts: 50
Joined: Sat Oct 15, 2005 8:21 pm
ID: 0
Location: The sun is directly above me....now!

For a start, what about not requiring the email address each time (since it's easy to find) and instead requiring a second password in that spot. It would allow the page setup to stay the same but would increase the security.

The problem I'd see with getting banned long term for 3 failed logins, is when I try to log into main using my Chaos password. Sometimes the old brain cramps up on me, and it's a few tries before I realize I selected the wrong page from favorites... I'd hate to be harassing admin for days while I tried to get access to my account again.
User avatar
Wolf359
The Big Bad Admin
Posts: 5208
Joined: Sat Feb 19, 2005 2:40 am
Alliance: EPA
Race: Tauri
ID: 0
Location: Omnipresent
Contact:

Honours and Awards

I think we can safely rule out the 'locking out' option - even for particular IPs - remember some people play from school or work, so someone could maliciously lock them out on purpose from the same location.
Image
Severian wrote:So I say as a last resort, splice Semper & Wolf359 for a good balance, Clone said unholy abomination a hundred times, let loose on forums and problem solved.
Mod Speak
Locked

Return to “Suggestions Archive”