| Pages: 1 [2] 3 :: one page |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |

WCPistolPete
Gallente MacroIntel
|
Posted - 2010.01.07 00:16:00 -
[31]
Originally by: Lady Aja mean while at the house of a guy who has 10 pc's and 20 accounts...
"WHICH ****ING ONE IS FOR WHAT ACCOUNT!???.. damn that wife for swapping them on aprils fools day"
I lol'd at this. Every day is April Fool's day when you have aggro to the significant other. +1 {WC}PistolPete "...going to take a lot of fireworks to clean this place up..." Homer Simpson |

Vaal Erit
Science and Trade Institute
|
Posted - 2010.01.07 01:16:00 -
[32]
Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
Originally by: Jim Raynor EVE needs danger, EVE needs risks, EVE needs combat, even piracy, without these things, the game stagnates to a trivial game centering around bloating your wallet with no purpose.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 01:21:00 -
[33]
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
|

Zeba
Minmatar Honourable East India Trading Company
|
Posted - 2010.01.07 02:45:00 -
[34]
Edited by: Zeba on 07/01/2010 02:46:29
No need for a device to do the secure password thingy. All ccp needs to do is make some sort of onscreen keyboard that uses non-ascii codes to tell the client what you just inputed. Only way to read the codes would be to make a custom eve only keylogger which could be easily defeated with something as simple as a random change to what code represents what character when your client downloads the bulk data when you first login.
Originally by: Akita T We don't hate people like you, we look at you with mostly pity and a hint of disgust balled up in a big wad of "notto disu shi'tto agen".
|

WCPistolPete
Gallente MacroIntel
|
Posted - 2010.01.07 02:50:00 -
[35]
Edited by: WCPistolPete on 07/01/2010 02:51:45 Originally by: Vaal Erit --------------------------------------------------------------------------------
Originally by: ChronoSphere -------------------------------------------------------------------------------- Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token. --------------------------------------------------------------------------------
Wrong. Completely and utterly wrong. --------------------------------------------------------------------------------
Steh Ruin:How so?
Here's how:
You go afk to get a b33r when your aggro'd significant other self-destructs your set of Snake implants along with your pod then gives aways all yours stuffs in locals "i have 10 billion isk and am quitting eve i'll give you 100x the isk back for whatever you send me."
And this happened with all of your anti-hack baubles hanging from every orifice on your computer. You must have forgotten the garlic clove, Holy water, silver bullets and wooden stake. {WC}PistolPete "...going to take a lot of fireworks to clean this place up..." Homer Simpson |

Zeba
Minmatar Honourable East India Trading Company
|
Posted - 2010.01.07 02:58:00 -
[36]
Originally by: WCPistolPete Edited by: WCPistolPete on 07/01/2010 02:51:45 Originally by: Vaal Erit --------------------------------------------------------------------------------
Originally by: ChronoSphere -------------------------------------------------------------------------------- Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token. --------------------------------------------------------------------------------
Wrong. Completely and utterly wrong. --------------------------------------------------------------------------------
Steh Ruin:How so?
Here's how:
You go afk to get a b33r when your aggro'd significant other self-destructs your set of Snake implants along with your pod then gives aways all yours stuffs in locals "i have 10 billion isk and am quitting eve i'll give you 100x the isk back for whatever you send me."
And this happened with all of your anti-hack baubles hanging from every orifice on your computer. You must have forgotten the garlic clove, Holy water, silver bullets and wooden stake.
Sounds moar like you forgot "insert random anniversery for first date, first kiss, first pet, first emoikilluallperiod from hell, first whatevah" one time too many and the significant other is no longer amused.
Single ftw. \o/
Originally by: Akita T We don't hate people like you, we look at you with mostly pity and a hint of disgust balled up in a big wad of "notto disu shi'tto agen".
|

Boomershoot
Caldari Suddenly Ninjas
|
Posted - 2010.01.07 02:58:00 -
[37]
Originally by: Seth Ruin
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
Machine Takeover.
|

Takseen
|
Posted - 2010.01.07 11:15:00 -
[38]
Originally by: Vaal Erit Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
Well I'm glad you've presented those facts defeating his argument. Oh wait.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 11:30:00 -
[39]
Originally by: Boomershoot
Originally by: Seth Ruin
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
Machine Takeover.
Hmm. I wouldn't say that makes the original claim "completely and utterly wrong," though I suppose for the EVE-O forum's Pedantic Parade, it could be clarified by saying "impossible to log in without ..." 
|

Tallaran Kouros
Caldari
|
Posted - 2010.01.07 11:41:00 -
[40]
No, no, no and no.
I am familiar with such systems (in particular RSA SecurID) from both a user and a support perspective and these would be highly inappropriate.
The licensing fees and support burden for these is pretty high and if you issued tokens out to users then you would need to have someone next to a phone 24/7 in order to reset tokens and issue new PINs.
The money for this staff would have to come from somewhere (in other words, increased subscription fees) and I really don't want to have to call Iceland whenever I need my token resynched or my PIN reset.
To be perfectly honest, nobody gets their account hacked - it just doesn't happen. People either use weak/guessable passwords, share their accounts or they fall for scams. Why pay money for a technical solution to what is an educational problem?
Security tokens have their uses, but this is not one of them.
As someone who has used, set up and administered such systems you can take my word - these are not really appropriate in this scenario and the return on investment just isn't there.
|

Elena Laskova
|
Posted - 2010.01.07 11:47:00 -
[41]
"Machine Takeover" is almost meaningless in this context.
If you use a method that generates one-time codes (this is what OP means by "physical login token", even a machine that's being actively controlled by someone else can't log on to the remote site (for EvE, that means they can't log the client onto the server).
Of course you could log in and then a remote program could take over and try to steal your stuff. Or perhaps you'd notice and power off the machine /lol.
"While both are silent, a wise man and a fool are intellectual equals".
|

Tallaran Kouros
Caldari
|
Posted - 2010.01.07 12:46:00 -
[42]
Originally by: Elena Laskova
Tallaran - I think you are significantly over-estimating the relative operating costs. Blizzard/WoW implemented badly (of course /lol) but they sold/sell authenticators for USD 6:50 IIRC.
I'm not.
In a previous position I was involved with administering RSA SecurID.
I know exactly how much the tokens cost even *with* a volume discount and whilst I can't tell you exactly how much we paid (I'm still bound by confidentiality), I can say that it's many times the $6.50 you quoted, so it's clear the Blizzard must have been subsidising the cost to a large extent.
That's fine for Blizzard, as they have the staffing, resources and playerbase to do that but I don't believe that the same is true for CCP.
On top of the cost of the tokens, you also have to pay for the authentication framework, the physical hardware on the back end, the cost of writing custom software to interface with the existing authentication system and the staffing costs to support token desyncs, forgotton PINs and so on and so forth.
Even if Blizzard used a company other than RSA and were able to buy cheaper tokens, the rest of the integration and support costing is still going to be true and that means they need to raise the money from subscribers.
Nobody gets hacked - people get their accounts compromised because they are idiots who respond to phishing emails or install key loggers. It's much cheaper for CCP to handle these cases within the existing GM/billing structure than it would be to invest in a two-factor authentication system.
I'm really not over-estimating the operating costs and for what it's worth, the infrastructure I supported previously had around 10,000 fobs issued to the user base.
|

Sidus Isaacs
Gallente
|
Posted - 2010.01.07 14:18:00 -
[43]
Originally by: Leaving Eve
I'd certainly pay five bucks or so for an eve branded USB token though.
Bleh, no.
I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Be smart, don't buy isk = be very safe. --------------------------------------------------------------------------------
http://desusig.crumplecorn.com/sigs.html |

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 14:20:00 -
[44]
Edited by: Seth Ruin on 07/01/2010 14:22:26 (grr thought I replied earlier, but it appears the forums ate my post... Or, more likely, I closed the tab before I hit "Post Reply" )
Originally by: Tallaran Kouros
Originally by: Elena Laskova
Tallaran - I think you are significantly over-estimating the relative operating costs. Blizzard/WoW implemented badly (of course /lol) but they sold/sell authenticators for USD 6:50 IIRC.
I'm not.
In a previous position I was involved with administering RSA SecurID.
I know exactly how much the tokens cost even *with* a volume discount and whilst I can't tell you exactly how much we paid (I'm still bound by confidentiality), I can say that it's many times the $6.50 you quoted, so it's clear the Blizzard must have been subsidising the cost to a large extent.
That's fine for Blizzard, as they have the staffing, resources and playerbase to do that but I don't believe that the same is true for CCP.
On top of the cost of the tokens, you also have to pay for the authentication framework, the physical hardware on the back end, the cost of writing custom software to interface with the existing authentication system and the staffing costs to support token desyncs, forgotton PINs and so on and so forth.
Even if Blizzard used a company other than RSA and were able to buy cheaper tokens, the rest of the integration and support costing is still going to be true and that means they need to raise the money from subscribers.
While I hate to champion specific products or services, the YubiKey solution I mentioned earlier does not require any licensing or administrative fees. Also, the authentication is handled through their servers (located in Sweden, I believe). The libraries for integrating into new or existing solutions are readily available on their site, and the newer keys apparently have OATH support as well.
Originally by: Tallaran Kouros
Nobody gets hacked - people get their accounts compromised because they are idiots who respond to phishing emails or install key loggers.
I don't think anyone's disagreeing with that. This proposal is an additional measure to render those methods of account theft futile; without the 2FA token, you still cannot gain access.
Originally by: Tallaran Kouros
It's much cheaper for CCP to handle these cases within the existing GM/billing structure than it would be to invest in a two-factor authentication system.
I'm really not over-estimating the operating costs and for what it's worth, the infrastructure I supported previously had around 10,000 fobs issued to the user base.
I still think it is worth bringing up to CCP to look into further. There are certainly numerous other solutions other than RSA SecurID and YubiKey, each with its own advantages, disadvantages, and costs. At least they can say they considered the options and decided against 2FA for whatever issues.
Edit:
Originally by: Sidus Isaacs
Originally by: Leaving Eve
I'd certainly pay five bucks or so for an eve branded USB token though.
Bleh, no.
I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Be smart, don't buy isk = be very safe.
Computer without a USB port? What, is it from '96?
Also, if I understood the OP correctly, any 2FA token or measure would be optional.
|

Tippia
Reikoku IT Alliance
|
Posted - 2010.01.07 14:32:00 -
[45]
Originally by: Seth Ruin
Originally by: Sidus Isaacs I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Computer without a USB port? What, is it from '96?
I'd rather go the other way: use an USB port? Why? We're not in the 00's any more. A proper token will never be connected to… well, anything… once it leaves the factory. ùùù ôIf you're not willing to fight for what you have in ≡v≡à you don't deserve it, and you will lose it.ö ù Karath Piki |

Elena Laskova
|
Posted - 2010.01.07 17:16:00 -
[46]
Edited by: Elena Laskova on 07/01/2010 17:24:38
You don't need a device which is physically connected to your PC. There are a lot of different approaches to this kind of authentication, some more secure than others. Usually more secure goes with more expensive or less convenient or both.
Here are two examples (one for each bank I use). Both are good enough for internet banking. Neither is sufficient for (e.g.) military use.
1. The bank provided me with a small device with a numeric keyboard, and a 6-character display. It generates 6-digit numbers. When I log in to the bank via my browser (via a simple userid which is not secure against a keylogger), I get two 4-digit numbers on the screen. I activate the device with a 4-digit PIN, type in those two numbers, and get a 6-digit number back. A different device of the same sort would generate a different 6-digit key. The bank's program can predict which nunber I got. I type it in, and if it doesn't match I can't log in.
Each time I move money around, or do something else where they need to be sure it's me, I go through a sinmilar process.
2. A lightweight "one-time pad" My other bank has the system I described above, but I still use their original system which is primitive, but cool. They send me a plastic card with 50 numbers on it. Other customers have such cards, but each card has a unique set of 50 numbers. I log in with a userid and password (not secure against a keylogger), but I also have to enter one of my unique codes. The bank's program knows which code I should enter, and what I enter must match what's expected or I can't log in. Whenever I move money around I also have to enter a code. I never use the same code twice.
Neither of these solutions require that a special device is connected to my PC, nor do they require any software to be installed on the PC.
Either one would be good enough for EvE, though obviously regularly distributing plastic cards would not be practical for a small company like CCP.
Just so it's said: I *know* there are other approaches and I *know* there are more secure approaches. But EvE login doesn't need the same security as inter-bank transfers of USD billions :)
|

Ak'athra J'ador
Amarr Red Federation
|
Posted - 2010.01.07 17:55:00 -
[47]
Originally by: Vaal Erit Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
not secret, you can see the damn thing in your tray. You also agree to it when you accept the EULA. It does not scan the entire system, fear not dear citizens of new Eden, it is not after your ****, it does however look at the stuff you happen to be running at the moment (and only at the programs that are running). Meaning, that if you were making a bot, you wouldn't be able to just get the values of different variables, but would have to make something OCR (optical character recognition) based. Bots reading pixels however are very hard to make, and are far more inefficient.
so to answer your question, yes, I would like something like that in eve. Right now when you report someone there is no way for CCP to know if he is actually running a bot or not. With warden, you can. It is the ultimate weapon in the fight against bots (besides people not actually wanting to buy isk).
and if you really fear that its gonna go after your pron, run eve on a mac, warden doesn't work on macs 
|

Joseph Maccabi
|
Posted - 2010.01.07 18:31:00 -
[48]
The RSA token works great for Paypal, and if you don't have your token with you, it will allow you to temporarily bypass it and answer 3 questions about yourself instead.
|

Lt Forge
Pilots From Honour Aeternus.
|
Posted - 2010.01.07 18:31:00 -
[49]
Edited by: Lt Forge on 07/01/2010 18:33:22 The more people talk about this stuff, the more hazardous you think it is to play the game.
Guys, here's a [PROPOSAL] for you: Let's all just ban currency! No corruption, no greed, no this and that. It also means we finally can get into space, and since religious people depend on money they go bankrupt.
|

Callista Sincera
Amarr
|
Posted - 2010.01.07 18:45:00 -
[50]
Originally by: Sidus Isaacs I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer?
You plug the device into that computer.
Originally by: Sidus Isaacs What if I use a computer ith no USB port? Etc etc.
Wait, what? You mean that good old pentium I? EVE will surely run great on that machine....
Originally by: Sidus Isaacs Be smart, don't buy isk = be very safe.
Let me play the smartass here. Do you have any idea how many different people developed the software currently running on your computer? How OLD some of that code is? How many possible security exploits there are yet to be found? No system as aged and complex as any of our current operating systems can ever be made safe without completely breaking backwards compatibility.
You seem to think that it had to be the users fault if he got hacked. Probably true most of the time, but there are countless ways to have that happen to you to no fault of your own. Just think of all those internet explorer exploits back then when Microsoft decided to 'remove' the competition (netscape - which then released their product as opensource - you now know that browser as FireFox) and release a compeletely insecure and unfinished product for free. At one point, website hosts could simply embed an executeable and have it run on their visitors computers - usually some dialling software which would than proceed to dial some shady, 50Ç per dial-in phone-sex hotline in the hope that most people would be to embarrassed to go to their lawyer to dispute their bill. In germany this was abused to the extreme so that they even changed some laws. I think the callee now has to prove that you actually wanted to call him, or something.
So yeah, you are completely wrong if you think that you have to be a brainless fart to get hacked. That just makes it a lot more likely :) -
|

Mustata Cornel
|
Posted - 2010.01.08 07:29:00 -
[51]
Edited by: Mustata Cornel on 08/01/2010 07:31:47 Who needs tokens ... All you need is a clean partition so you can install a new windows copy on it. Then ofc install the drivers,updates and the game and disable all the useless microsoft services like : remote assistance, remote registry , secondary logon .. many others more details on xptweaks site. Also: - remove(uninstall) , file and printer sharing , and client for microsoft network from network connections - from folder options do not use simple file sharing , and go to your partition-security and add your admin user(that you use when you installed windows) and give him full rights , then remove every other user. Do the same with your other drives/partitions but from you normal windows installation , you will need to add "system" when/if you want to install something though. - use a firewall like sunbelt personal firewall free version and block everything except eve , firefox , domain name server , dynamic host configuration . - do not use this windows installation for anything else than eve or eve web site , no e-mail !!! - antivirus and some free antispyware like lavasoft may help also. - ofc for some insane extra security from your tcp/ip filtering in local area connection block all ports except the one that eve uses (you can see it in firewall).
Now can someone tell me how can i be hacked using all those ?
This is for xp , windows 7 well until eve upgrades to directx10 for me is just useless , vista is even worse .
|

Rico Lobo
|
Posted - 2010.01.08 07:57:00 -
[52]
Originally by: Magnus Nordir Edited by: Magnus Nordir on 05/01/2010 02:06:27 use a mouse and onscreen keyboard to enter the password. Problem solved.
Not realy.
I need to find back that forum thread over on CoH/CoV where one of the new ones that the developers found looks specificaly for any input to the pasword log in from about a year back including virtual keyboards and dropdowns.
As for "true entrophy" I use a old scrable tile set when I want a random password. 26 cap leters 26 smallcase leters 10 number tiles and 20 special characters for thoes systems that accept them. all generated whenever I want one.
|

Rico Lobo
|
Posted - 2010.01.08 08:07:00 -
[53]
as for bliz its either or the token or Iphone app not both.
Because the Iphone app uses GPS based time stamps it has fewer issues than the token which from what I have heard needes to be replaced after about 18 months.
|
|

Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2010.01.08 08:27:00 -
[54]
Posting the mandatory Chribba wants IP-locks post, and yeah I'd pay for a login token as well, or some sort of added security.
/c
Secure 3rd party service |
|

Rico Lobo
|
Posted - 2010.01.08 08:29:00 -
[55]
Originally by: Tallaran Kouros No, no, no and no.
I am familiar with such systems (in particular RSA SecurID) from both a user and a support perspective and these would be highly inappropriate.
The licensing fees and support burden for these is pretty high and if you issued tokens out to users then you would need to have someone next to a phone 24/7 in order to reset tokens and issue new PINs.
.
wich incidentaly doed not apply to Digipass keys wich insicentaly are made in and operated out of China and is not in any was assoceated with RSA . . . . wich should explain a lot in and of itself as to how mutch the system costs.
they are not made by/for RsA SecurID in the US and (I think) Germany.
nor the TecId( I think thats right) tokens that are made in Mexico.(wich is a fraction of the price of the RSA system but then its also only a 6 character ID number system and not the newer Alfa muneric systems that RSA offers nowdays)
According to Bliz it would be cheaper for everyone to have a token than to pay for the suport GMs who currently deal with hacked accounts. (heck they actualy give away a "premium pet" to everyone who gets one.) and considering that they dont actualy have that many Suport GMs to start with. . . it cant be too bloody expensive for them.
Granted they do expect you to pay ~40 usd for the "base" account with the current expansion set too so meh.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.08 08:36:00 -
[56]
Originally by: Chribba Posting the mandatory Chribba wants IP-locks post, and yeah I'd pay for a login token as well, or some sort of added security.
/c
This idea has been blessed by Chribba, the Space Pope of the Church of Veldspar. That's a good sign 
Should we make a formalized [Proposal] thread in the Assembly Hall to be looked at by the CSM? Possibly include it with a number of account security issues and proposals we'd like CCP to consider, such as the "lock characters to prevent theft" and the IP-lock (or IP range lock) as mentioned by Chribba.
|

AmarrettoDiAmarr
|
Posted - 2010.01.09 06:15:00 -
[57]
Originally by: Callista Sincera
So yeah, you are completely wrong if you think that you have to be a brainless fart to get hacked. That just makes it a lot more likely :)
QFT
What I read is that there are several hundred thousand machines compromised every year; I assume that much less than 1% of them play EVE let alone purchased ISK. I also assume the people who are doing malware for profit are going for many passwords: banks, brokerages, PayPal as well as any MMO large enough to have a RMT market. And your machine is compromised if someone else (sibling, parent, significant other) is careless while using it. Certainly the majority of the nine million machines infected with Conflicker/Downadup did not visit ISK sellers. For many, their only failing was not patching frequently enough.
Yes, a 2FA infrastructure would cost something. But it would avoid some existing costs: both the CCP employees who support, investigate and restore ISK, as well as the lost revenue of a hacked subscriber not giving CCP an additional year or two of revenue. E.G., the Grismar website quit being updated when the owner was not happy with CCP response to him being hacked.
The 2FA I know of does not require some hardware to be connected to the computer, USB or otherwise; safer if it is not and it avoids platform and version issues as well. And while hardware is an option, iPhone apps and printed cards of numbers are two alternatives that do not require additional hardware..
tl;dr: While the majority of people who visit bad sites may get hacked, this does not mean that a significant percentage of the people who got hacked visited a ISK RMT site.
|

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.01.11 20:31:00 -
[58]
Sweet, my thread attracted Chribba :)
It sounds like there would be a fair number of people and accounts that would be interested in a 2FA authenticator of some sort. It also recently sounds like blizzard is going to be requiring all accounts to have them - maybe that'll bring the price down since manufacturers will be making lots? -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Salena Tarra
|
Posted - 2010.01.11 20:59:00 -
[59]
Blizzard would never make it mandatory to have one of their authenticators unless they make them free. They might like money but they arent stupid.
I am also in favour of something like this being made for Eve. I think the people saying how only stupid people get their accounts hacked are right and I am have no clue how mine never has been in 6 years of playing MMOs. Unfortunately not all of us belong to the tin foil hat wearing part of society that have a military grade anti-virus system that they created running on their computers.
|

Larg Kellein
Caldari Agony Unleashed Agony Empire
|
Posted - 2010.01.11 21:06:00 -
[60]
I think people are missing an important bit here... Or have never visited the Eve store.
CCP would probably sell you a usb stick for $5, but shipping would take a few weeks at best and cost $85.
|
| |
|
| Pages: 1 [2] 3 :: one page |
| First page | Previous page | Next page | Last page |