| Pages: 1 2 3 :: [one page] |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.01.05 01:15:00 -
[1]
Account hackings seem to occur way too often. Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
I can't think it would be very hard to do this, as other MMO's have done this already. Has there been any internal discussion about doing this? I would imagine this would help reduce the workload on GM's from having to unravel so many hacked account petitions. -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Leaving Eve
Boo Hoo Federation
|
Posted - 2010.01.05 01:25:00 -
[2]
I would pay five bucks for one. I'm pretty much alright as security goes. I don't find Audrey Bittoni that attractive, and don't buy ISK.
I'd certainly pay five bucks or so for an eve branded USB token though.
|

Intense Thinker
Minmatar
|
Posted - 2010.01.05 02:04:00 -
[3]
I would gladly pay you Tuesday for a hamburger today...
Originally by: a51 duke1406 The girls just dont understand that sunday is pvp night, not cuddle on the couch watching tv night.
|

Magnus Nordir
Caldari Nordir Industries
|
Posted - 2010.01.05 02:06:00 -
[4]
Edited by: Magnus Nordir on 05/01/2010 02:06:27 Change your password to a random 16-character string twice a week. If you're paranoid about keyloggers, use a mouse and onscreen keyboard to enter the password. Problem solved.
NOTE: Hitting the keyboard blindly does NOT produce a random string. While it is high-entropy (though not as much as a dedicated random plucker), it doesn't account for caps and special characters in a meaningful way. It's best to use a dedicated encryption program like TrueCrypt or PGP/GPG, and let it run the random key generator at least overnight. Generating two to three random characters per day is the most secure way to go, since your computer is more likely to do different stuff in the background over a longer period, and that results in more entropy. --------------------------- Only those who surrender are lost |

Leaving Eve
Boo Hoo Federation
|
Posted - 2010.01.05 02:06:00 -
[5]
Originally by: Intense Thinker I would gladly pay you Tuesday for a hamburger today...
This must be above my intellect. Don't get it.
|

Aloriana Jacques
Amarr Royal Amarr Institute
|
Posted - 2010.01.05 02:12:00 -
[6]
You should be aware that the MMOs that have them are able to do it because they get huge bulk discounts that make them affordable right?
I know I'm not going to spend 50$ on a gizmo because they can only expect to sell a few thousand compared to the millions the mmos using it can. - - - Aloriana Jacques - Skill Sheet
|

Gunnanmon
Gallente The Scope
|
Posted - 2010.01.05 02:15:00 -
[7]
Please refrain from posting ideas. The Eve forum isn't the right place for such things. Signature locked for discussing moderation. Navigator
|

Intense Thinker
Minmatar
|
Posted - 2010.01.05 02:22:00 -
[8]
Originally by: Leaving Eve
Originally by: Intense Thinker I would gladly pay you Tuesday for a hamburger today...
This must be above my intellect. Don't get it.
Damn kids today...
Originally by: a51 duke1406 The girls just dont understand that sunday is pvp night, not cuddle on the couch watching tv night.
|

Kia Tor
|
Posted - 2010.01.05 03:14:00 -
[9]
Huh, I must be older than I thought. Didn't think Popeye was that long ago. 
|

Benco97
Gallente Shadow Veil Industrial
|
Posted - 2010.01.05 03:18:00 -
[10]
I have heard of these sorts of devices before but not in detail, could someone kindly explain how they work? ______________________________________________
Originally by: P'uck
You're a DUMBASS - bold italic underline at the VERY LEAST.

|

AmarrettoDiAmarr
|
Posted - 2010.01.05 03:59:00 -
[11]
Originally by: Benco97 I have heard of these sorts of devices before but not in detail, could someone kindly explain how they work?
It does not have to be a "device" - you can get it as an iPhone app - no new hardware is required.
wikipedia 2FA
Basically the iphone app/key fob generates a new password every say minute. The Server knows what fob is associated with the account so it knows the password of the moment. So if someone intercepts/keylogs the password or intercepts the network or WiFi transmission, it is no longer valid next minute.
Companies with remote logins have been using 2FA for a decade or two (e.g. from RSA) Blizzard has been offering an authenticator for a couple of years. $6.50 IIRC Authenticator for You Know Who |

Benco97
Gallente Shadow Veil Industrial
|
Posted - 2010.01.05 04:06:00 -
[12]
Originally by: AmarrettoDiAmarr
Originally by: Benco97 I have heard of these sorts of devices before but not in detail, could someone kindly explain how they work?
It does not have to be a "device" - you can get it as an iPhone app - no new hardware is required.
wikipedia 2FA
Basically the iphone app/key fob generates a new password every say minute. The Server knows what fob is associated with the account so it knows the password of the moment. So if someone intercepts/keylogs the password or intercepts the network or WiFi transmission, it is no longer valid next minute.
Companies with remote logins have been using 2FA for a decade or two (e.g. from RSA) Blizzard has been offering an authenticator for a couple of years. $6.50 IIRC Authenticator for You Know Who
Ahh, excellent explanation, thank you very much!  ______________________________________________
Originally by: P'uck
You're a DUMBASS - bold italic underline at the VERY LEAST.

|

w1ndstrike
Trans-Aerospace Industries
|
Posted - 2010.01.05 06:23:00 -
[13]
Originally by: Magnus Nordir Edited by: Magnus Nordir on 05/01/2010 02:06:27 Change your password to a random 16-character string twice a week. If you're paranoid about keyloggers, use a mouse and onscreen keyboard to enter the password. Problem solved.
NOTE: Hitting the keyboard blindly does NOT produce a random string. While it is high-entropy (though not as much as a dedicated random plucker), it doesn't account for caps and special characters in a meaningful way. It's best to use a dedicated encryption program like TrueCrypt or PGP/GPG, and let it run the random key generator at least overnight. Generating two to three random characters per day is the most secure way to go, since your computer is more likely to do different stuff in the background over a longer period, and that results in more entropy.
you do realize that the on-screen keyboard gets logged just like a regular keyboard? they are both imput sources to the keypress index .DLL file, which is what a keylogger targets. most secure way is to use a non-infected machine
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.05 06:30:00 -
[14]
Originally by: AmarrettoDiAmarr
Originally by: Benco97 I have heard of these sorts of devices before but not in detail, could someone kindly explain how they work?
It does not have to be a "device" - you can get it as an iPhone app - no new hardware is required.
wikipedia 2FA
Basically the iphone app/key fob generates a new password every say minute. The Server knows what fob is associated with the account so it knows the password of the moment. So if someone intercepts/keylogs the password or intercepts the network or WiFi transmission, it is no longer valid next minute.
Companies with remote logins have been using 2FA for a decade or two (e.g. from RSA) Blizzard has been offering an authenticator for a couple of years. $6.50 IIRC Authenticator for You Know Who
A simpler solution would be to have optional integration of third-party keys like Yubikeys. Hell they even have a relatively well-documented API and libraries in C and Java.
|

Callista Sincera
Amarr
|
Posted - 2010.01.05 08:14:00 -
[15]
Originally by: Seth Ruin A simpler solution would be to have optional integration of third-party keys like Yubikeys. Hell they even have a relatively well-documented API and libraries in C and Java.
It's not clear on the authentication though. Does it use a token+timebased salt as hash like RSA gizmos or is it just another way to enter a static username/password combo?
Anyway, given the pricing, CCP could probably offer those for less than 15$. Provided they take the time and fix their shops hilarious shipping fees. -
|

Carniflex
StarHunt Systematic-Chaos
|
Posted - 2010.01.05 08:17:00 -
[16]
Why not use just national identity cards ? Many countries have them and they are relatively standardized. It would be optional ofc for all those who love tinfoil hats.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.05 08:26:00 -
[17]
Originally by: Callista Sincera
Originally by: Seth Ruin A simpler solution would be to have optional integration of third-party keys like Yubikeys. Hell they even have a relatively well-documented API and libraries in C and Java.
It's not clear on the authentication though. Does it use a token+timebased salt as hash like RSA gizmos or is it just another way to enter a static username/password combo?
Anyway, given the pricing, CCP could probably offer those for less than 15$. Provided they take the time and fix their shops hilarious shipping fees.
True on them not being clear on the authentication. It does appear to function at least similar to a token+timebased salt. As far as I understand, it generates one-time-use codes which are sent to the server to be authenticated. From the description page: "The YubiKey generates a unique 128-bit code at each authentication event and there is no time window during which two authentication codes are equal. All of the unique codes are encrypted with AES-128 and is then encoded to "readable form", where the resulting string is transmitted in its full length."
There's more information there, but I don't want to stray too far off-topic. In any case, I'm sure there are similar solutions available, but this is the one I have experience with as an end-user (and so I'd love it if CCP implemented it, since I already have the key ).
|

Elena Laskova
|
Posted - 2010.01.05 08:41:00 -
[18]
Anything which uses the same password in your PC more than once is vulnerable to a keylogger.
Any system where a new random (or secret) key is provided outside your PC is much safer. An "authenticator" is a cheap device that supports this, but other methods are possible.
|

JordanParey
Minmatar Suddenly Ninjas
|
Posted - 2010.01.05 08:57:00 -
[19]
Originally by: Intense Thinker I would gladly pay you Tuesday for a hamburger today...
WIMPY WIN
|

Ivana Twinkle
Amarr Polytechnique Gallenteenne
|
Posted - 2010.01.05 09:47:00 -
[20]
Originally by: Intense Thinker I would gladly pay you Tuesday for a hamburger today...
oh how i lold :)
more of this!
|

RaTTuS
BIG Libertas Fidelitas
|
Posted - 2010.01.05 09:50:00 -
[21]
I don't think it is worth it then again I've not been hacked
stupid people are stupid having different passwords for the forum / game may be worth it -- | Capital |

Noun Verber
Gallente
|
Posted - 2010.01.05 09:54:00 -
[22]
Originally by: Magnus Nordir Edited by: Magnus Nordir on 05/01/2010 02:06:27 If you're paranoid about keyloggers, use a mouse and onscreen keyboard to enter the password.
Useless if there is a keylogger, because they don't just record actual keystrokes
|

Trathen
Minmatar
|
Posted - 2010.01.05 10:09:00 -
[23]
Make accounts more secure? If we do that, people who deal with ISK sellers regularly won't learn anything. Maybe they can ease GM load with an automated message, "Consider yourself lucky that they didn't take your bank account, too." _ |

Cypherous
Minmatar Liberty Rogues Rally Against Evil
|
Posted - 2010.01.06 01:42:00 -
[24]
Only silly people get their accounts hacked, never had mine hacked in 5 1/2 years i don't buy ISK i don't click dodgy **** links posted in EO forums, darwin at work TBH Rally Against Evil Site |

Niccolado Starwalker
Gallente Shadow Templars
|
Posted - 2010.01.06 02:01:00 -
[25]
Originally by: ChronoSphere Account hackings seem to occur way too often. Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
I can't think it would be very hard to do this, as other MMO's have done this already. Has there been any internal discussion about doing this? I would imagine this would help reduce the workload on GM's from having to unravel so many hacked account petitions.
I would gladly buy a login token for my EVE account. Just as a precaution. My account = my life 
Originally by: Dianabolic Your tears are absolutely divine, like a fine fine wine, rolling down your cheeks until they flow down the river of LOL.
|

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.01.06 23:13:00 -
[26]
A very kindly bump to our good friends at CCP for a response :) -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Lady Aja
Caldari
|
Posted - 2010.01.06 23:23:00 -
[27]
mean while at the house of a guy who has 10 pc's and 20 accounts...
"WHICH ****ING ONE IS FOR WHAT ACCOUNT!???.. damn that wife for swapping them on aprils fools day"
|

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.01.06 23:29:00 -
[28]
That other game allows you to link multiple accounts with one token. -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Armoured C
Gallente Noir. Noir. Mercenary Group
|
Posted - 2010.01.06 23:30:00 -
[29]
problem isnt the cost of the device , but i don't know if u seen the eve store charges for shipping such things
the item itself may only be 7 quid but they probably charge us 30 quid to ship it , and with the way dominion is going at the moment i don't think they need the hassle of something else preventing customers logging in/braking the game
they don't even have the GTC fixed yet.
so tbh it probably more hassle than it worth at the moment.
|

WCPistolPete
Gallente MacroIntel
|
Posted - 2010.01.07 00:09:00 -
[30]
Originally by: AmarrettoDiAmarrIt does not have to be a "device" - you can get it as an iPhone app - no new hardware is required.[/quote
Now I need a token AND an iPhone? Next I'll need an account for the iPhone. WHERE DOES THE MADNESS END? {WC}PistolPete "...going to take a lot of fireworks to clean this place up..." Homer Simpson
|

WCPistolPete
Gallente MacroIntel
|
Posted - 2010.01.07 00:16:00 -
[31]
Originally by: Lady Aja mean while at the house of a guy who has 10 pc's and 20 accounts...
"WHICH ****ING ONE IS FOR WHAT ACCOUNT!???.. damn that wife for swapping them on aprils fools day"
I lol'd at this. Every day is April Fool's day when you have aggro to the significant other. +1 {WC}PistolPete "...going to take a lot of fireworks to clean this place up..." Homer Simpson |

Vaal Erit
Science and Trade Institute
|
Posted - 2010.01.07 01:16:00 -
[32]
Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
Originally by: Jim Raynor EVE needs danger, EVE needs risks, EVE needs combat, even piracy, without these things, the game stagnates to a trivial game centering around bloating your wallet with no purpose.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 01:21:00 -
[33]
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
|

Zeba
Minmatar Honourable East India Trading Company
|
Posted - 2010.01.07 02:45:00 -
[34]
Edited by: Zeba on 07/01/2010 02:46:29
No need for a device to do the secure password thingy. All ccp needs to do is make some sort of onscreen keyboard that uses non-ascii codes to tell the client what you just inputed. Only way to read the codes would be to make a custom eve only keylogger which could be easily defeated with something as simple as a random change to what code represents what character when your client downloads the bulk data when you first login.
Originally by: Akita T We don't hate people like you, we look at you with mostly pity and a hint of disgust balled up in a big wad of "notto disu shi'tto agen".
|

WCPistolPete
Gallente MacroIntel
|
Posted - 2010.01.07 02:50:00 -
[35]
Edited by: WCPistolPete on 07/01/2010 02:51:45 Originally by: Vaal Erit --------------------------------------------------------------------------------
Originally by: ChronoSphere -------------------------------------------------------------------------------- Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token. --------------------------------------------------------------------------------
Wrong. Completely and utterly wrong. --------------------------------------------------------------------------------
Steh Ruin:How so?
Here's how:
You go afk to get a b33r when your aggro'd significant other self-destructs your set of Snake implants along with your pod then gives aways all yours stuffs in locals "i have 10 billion isk and am quitting eve i'll give you 100x the isk back for whatever you send me."
And this happened with all of your anti-hack baubles hanging from every orifice on your computer. You must have forgotten the garlic clove, Holy water, silver bullets and wooden stake. {WC}PistolPete "...going to take a lot of fireworks to clean this place up..." Homer Simpson |

Zeba
Minmatar Honourable East India Trading Company
|
Posted - 2010.01.07 02:58:00 -
[36]
Originally by: WCPistolPete Edited by: WCPistolPete on 07/01/2010 02:51:45 Originally by: Vaal Erit --------------------------------------------------------------------------------
Originally by: ChronoSphere -------------------------------------------------------------------------------- Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token. --------------------------------------------------------------------------------
Wrong. Completely and utterly wrong. --------------------------------------------------------------------------------
Steh Ruin:How so?
Here's how:
You go afk to get a b33r when your aggro'd significant other self-destructs your set of Snake implants along with your pod then gives aways all yours stuffs in locals "i have 10 billion isk and am quitting eve i'll give you 100x the isk back for whatever you send me."
And this happened with all of your anti-hack baubles hanging from every orifice on your computer. You must have forgotten the garlic clove, Holy water, silver bullets and wooden stake.
Sounds moar like you forgot "insert random anniversery for first date, first kiss, first pet, first emoikilluallperiod from hell, first whatevah" one time too many and the significant other is no longer amused.
Single ftw. \o/
Originally by: Akita T We don't hate people like you, we look at you with mostly pity and a hint of disgust balled up in a big wad of "notto disu shi'tto agen".
|

Boomershoot
Caldari Suddenly Ninjas
|
Posted - 2010.01.07 02:58:00 -
[37]
Originally by: Seth Ruin
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
Machine Takeover.
|

Takseen
|
Posted - 2010.01.07 11:15:00 -
[38]
Originally by: Vaal Erit Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
Well I'm glad you've presented those facts defeating his argument. Oh wait.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 11:30:00 -
[39]
Originally by: Boomershoot
Originally by: Seth Ruin
Originally by: Vaal Erit
Originally by: ChronoSphere Having a physical login token would make those accounts impossible to access by unauthorized people unless they knew the account name, password and had the physical token.
Wrong. Completely and utterly wrong.
How so? 
Machine Takeover.
Hmm. I wouldn't say that makes the original claim "completely and utterly wrong," though I suppose for the EVE-O forum's Pedantic Parade, it could be clarified by saying "impossible to log in without ..." 
|

Tallaran Kouros
Caldari
|
Posted - 2010.01.07 11:41:00 -
[40]
No, no, no and no.
I am familiar with such systems (in particular RSA SecurID) from both a user and a support perspective and these would be highly inappropriate.
The licensing fees and support burden for these is pretty high and if you issued tokens out to users then you would need to have someone next to a phone 24/7 in order to reset tokens and issue new PINs.
The money for this staff would have to come from somewhere (in other words, increased subscription fees) and I really don't want to have to call Iceland whenever I need my token resynched or my PIN reset.
To be perfectly honest, nobody gets their account hacked - it just doesn't happen. People either use weak/guessable passwords, share their accounts or they fall for scams. Why pay money for a technical solution to what is an educational problem?
Security tokens have their uses, but this is not one of them.
As someone who has used, set up and administered such systems you can take my word - these are not really appropriate in this scenario and the return on investment just isn't there.
|

Elena Laskova
|
Posted - 2010.01.07 11:47:00 -
[41]
"Machine Takeover" is almost meaningless in this context.
If you use a method that generates one-time codes (this is what OP means by "physical login token", even a machine that's being actively controlled by someone else can't log on to the remote site (for EvE, that means they can't log the client onto the server).
Of course you could log in and then a remote program could take over and try to steal your stuff. Or perhaps you'd notice and power off the machine /lol.
"While both are silent, a wise man and a fool are intellectual equals".
|

Tallaran Kouros
Caldari
|
Posted - 2010.01.07 12:46:00 -
[42]
Originally by: Elena Laskova
Tallaran - I think you are significantly over-estimating the relative operating costs. Blizzard/WoW implemented badly (of course /lol) but they sold/sell authenticators for USD 6:50 IIRC.
I'm not.
In a previous position I was involved with administering RSA SecurID.
I know exactly how much the tokens cost even *with* a volume discount and whilst I can't tell you exactly how much we paid (I'm still bound by confidentiality), I can say that it's many times the $6.50 you quoted, so it's clear the Blizzard must have been subsidising the cost to a large extent.
That's fine for Blizzard, as they have the staffing, resources and playerbase to do that but I don't believe that the same is true for CCP.
On top of the cost of the tokens, you also have to pay for the authentication framework, the physical hardware on the back end, the cost of writing custom software to interface with the existing authentication system and the staffing costs to support token desyncs, forgotton PINs and so on and so forth.
Even if Blizzard used a company other than RSA and were able to buy cheaper tokens, the rest of the integration and support costing is still going to be true and that means they need to raise the money from subscribers.
Nobody gets hacked - people get their accounts compromised because they are idiots who respond to phishing emails or install key loggers. It's much cheaper for CCP to handle these cases within the existing GM/billing structure than it would be to invest in a two-factor authentication system.
I'm really not over-estimating the operating costs and for what it's worth, the infrastructure I supported previously had around 10,000 fobs issued to the user base.
|

Sidus Isaacs
Gallente
|
Posted - 2010.01.07 14:18:00 -
[43]
Originally by: Leaving Eve
I'd certainly pay five bucks or so for an eve branded USB token though.
Bleh, no.
I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Be smart, don't buy isk = be very safe. --------------------------------------------------------------------------------
http://desusig.crumplecorn.com/sigs.html |

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.07 14:20:00 -
[44]
Edited by: Seth Ruin on 07/01/2010 14:22:26 (grr thought I replied earlier, but it appears the forums ate my post... Or, more likely, I closed the tab before I hit "Post Reply" )
Originally by: Tallaran Kouros
Originally by: Elena Laskova
Tallaran - I think you are significantly over-estimating the relative operating costs. Blizzard/WoW implemented badly (of course /lol) but they sold/sell authenticators for USD 6:50 IIRC.
I'm not.
In a previous position I was involved with administering RSA SecurID.
I know exactly how much the tokens cost even *with* a volume discount and whilst I can't tell you exactly how much we paid (I'm still bound by confidentiality), I can say that it's many times the $6.50 you quoted, so it's clear the Blizzard must have been subsidising the cost to a large extent.
That's fine for Blizzard, as they have the staffing, resources and playerbase to do that but I don't believe that the same is true for CCP.
On top of the cost of the tokens, you also have to pay for the authentication framework, the physical hardware on the back end, the cost of writing custom software to interface with the existing authentication system and the staffing costs to support token desyncs, forgotton PINs and so on and so forth.
Even if Blizzard used a company other than RSA and were able to buy cheaper tokens, the rest of the integration and support costing is still going to be true and that means they need to raise the money from subscribers.
While I hate to champion specific products or services, the YubiKey solution I mentioned earlier does not require any licensing or administrative fees. Also, the authentication is handled through their servers (located in Sweden, I believe). The libraries for integrating into new or existing solutions are readily available on their site, and the newer keys apparently have OATH support as well.
Originally by: Tallaran Kouros
Nobody gets hacked - people get their accounts compromised because they are idiots who respond to phishing emails or install key loggers.
I don't think anyone's disagreeing with that. This proposal is an additional measure to render those methods of account theft futile; without the 2FA token, you still cannot gain access.
Originally by: Tallaran Kouros
It's much cheaper for CCP to handle these cases within the existing GM/billing structure than it would be to invest in a two-factor authentication system.
I'm really not over-estimating the operating costs and for what it's worth, the infrastructure I supported previously had around 10,000 fobs issued to the user base.
I still think it is worth bringing up to CCP to look into further. There are certainly numerous other solutions other than RSA SecurID and YubiKey, each with its own advantages, disadvantages, and costs. At least they can say they considered the options and decided against 2FA for whatever issues.
Edit:
Originally by: Sidus Isaacs
Originally by: Leaving Eve
I'd certainly pay five bucks or so for an eve branded USB token though.
Bleh, no.
I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Be smart, don't buy isk = be very safe.
Computer without a USB port? What, is it from '96?
Also, if I understood the OP correctly, any 2FA token or measure would be optional.
|

Tippia
Reikoku IT Alliance
|
Posted - 2010.01.07 14:32:00 -
[45]
Originally by: Seth Ruin
Originally by: Sidus Isaacs I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer? What if I use a computer ith no USB port? Etc etc.
Computer without a USB port? What, is it from '96?
I'd rather go the other way: use an USB port? Why? We're not in the 00's any more. A proper token will never be connected to… well, anything… once it leaves the factory. ùùù ôIf you're not willing to fight for what you have in ≡v≡à you don't deserve it, and you will lose it.ö ù Karath Piki |

Elena Laskova
|
Posted - 2010.01.07 17:16:00 -
[46]
Edited by: Elena Laskova on 07/01/2010 17:24:38
You don't need a device which is physically connected to your PC. There are a lot of different approaches to this kind of authentication, some more secure than others. Usually more secure goes with more expensive or less convenient or both.
Here are two examples (one for each bank I use). Both are good enough for internet banking. Neither is sufficient for (e.g.) military use.
1. The bank provided me with a small device with a numeric keyboard, and a 6-character display. It generates 6-digit numbers. When I log in to the bank via my browser (via a simple userid which is not secure against a keylogger), I get two 4-digit numbers on the screen. I activate the device with a 4-digit PIN, type in those two numbers, and get a 6-digit number back. A different device of the same sort would generate a different 6-digit key. The bank's program can predict which nunber I got. I type it in, and if it doesn't match I can't log in.
Each time I move money around, or do something else where they need to be sure it's me, I go through a sinmilar process.
2. A lightweight "one-time pad" My other bank has the system I described above, but I still use their original system which is primitive, but cool. They send me a plastic card with 50 numbers on it. Other customers have such cards, but each card has a unique set of 50 numbers. I log in with a userid and password (not secure against a keylogger), but I also have to enter one of my unique codes. The bank's program knows which code I should enter, and what I enter must match what's expected or I can't log in. Whenever I move money around I also have to enter a code. I never use the same code twice.
Neither of these solutions require that a special device is connected to my PC, nor do they require any software to be installed on the PC.
Either one would be good enough for EvE, though obviously regularly distributing plastic cards would not be practical for a small company like CCP.
Just so it's said: I *know* there are other approaches and I *know* there are more secure approaches. But EvE login doesn't need the same security as inter-bank transfers of USD billions :)
|

Ak'athra J'ador
Amarr Red Federation
|
Posted - 2010.01.07 17:55:00 -
[47]
Originally by: Vaal Erit Hey, these "other MMO's" also use secret programs to scan your entire system to see what else your computer is running. Would you like that as well? Just because WoW does it doesn't mean everyone should.
not secret, you can see the damn thing in your tray. You also agree to it when you accept the EULA. It does not scan the entire system, fear not dear citizens of new Eden, it is not after your ****, it does however look at the stuff you happen to be running at the moment (and only at the programs that are running). Meaning, that if you were making a bot, you wouldn't be able to just get the values of different variables, but would have to make something OCR (optical character recognition) based. Bots reading pixels however are very hard to make, and are far more inefficient.
so to answer your question, yes, I would like something like that in eve. Right now when you report someone there is no way for CCP to know if he is actually running a bot or not. With warden, you can. It is the ultimate weapon in the fight against bots (besides people not actually wanting to buy isk).
and if you really fear that its gonna go after your pron, run eve on a mac, warden doesn't work on macs 
|

Joseph Maccabi
|
Posted - 2010.01.07 18:31:00 -
[48]
The RSA token works great for Paypal, and if you don't have your token with you, it will allow you to temporarily bypass it and answer 3 questions about yourself instead.
|

Lt Forge
Pilots From Honour Aeternus.
|
Posted - 2010.01.07 18:31:00 -
[49]
Edited by: Lt Forge on 07/01/2010 18:33:22 The more people talk about this stuff, the more hazardous you think it is to play the game.
Guys, here's a [PROPOSAL] for you: Let's all just ban currency! No corruption, no greed, no this and that. It also means we finally can get into space, and since religious people depend on money they go bankrupt.
|

Callista Sincera
Amarr
|
Posted - 2010.01.07 18:45:00 -
[50]
Originally by: Sidus Isaacs I desire no hardware to be implemented in order for me to log in to EVE, what if I am at another computer?
You plug the device into that computer.
Originally by: Sidus Isaacs What if I use a computer ith no USB port? Etc etc.
Wait, what? You mean that good old pentium I? EVE will surely run great on that machine....
Originally by: Sidus Isaacs Be smart, don't buy isk = be very safe.
Let me play the smartass here. Do you have any idea how many different people developed the software currently running on your computer? How OLD some of that code is? How many possible security exploits there are yet to be found? No system as aged and complex as any of our current operating systems can ever be made safe without completely breaking backwards compatibility.
You seem to think that it had to be the users fault if he got hacked. Probably true most of the time, but there are countless ways to have that happen to you to no fault of your own. Just think of all those internet explorer exploits back then when Microsoft decided to 'remove' the competition (netscape - which then released their product as opensource - you now know that browser as FireFox) and release a compeletely insecure and unfinished product for free. At one point, website hosts could simply embed an executeable and have it run on their visitors computers - usually some dialling software which would than proceed to dial some shady, 50Ç per dial-in phone-sex hotline in the hope that most people would be to embarrassed to go to their lawyer to dispute their bill. In germany this was abused to the extreme so that they even changed some laws. I think the callee now has to prove that you actually wanted to call him, or something.
So yeah, you are completely wrong if you think that you have to be a brainless fart to get hacked. That just makes it a lot more likely :) -
|

Mustata Cornel
|
Posted - 2010.01.08 07:29:00 -
[51]
Edited by: Mustata Cornel on 08/01/2010 07:31:47 Who needs tokens ... All you need is a clean partition so you can install a new windows copy on it. Then ofc install the drivers,updates and the game and disable all the useless microsoft services like : remote assistance, remote registry , secondary logon .. many others more details on xptweaks site. Also: - remove(uninstall) , file and printer sharing , and client for microsoft network from network connections - from folder options do not use simple file sharing , and go to your partition-security and add your admin user(that you use when you installed windows) and give him full rights , then remove every other user. Do the same with your other drives/partitions but from you normal windows installation , you will need to add "system" when/if you want to install something though. - use a firewall like sunbelt personal firewall free version and block everything except eve , firefox , domain name server , dynamic host configuration . - do not use this windows installation for anything else than eve or eve web site , no e-mail !!! - antivirus and some free antispyware like lavasoft may help also. - ofc for some insane extra security from your tcp/ip filtering in local area connection block all ports except the one that eve uses (you can see it in firewall).
Now can someone tell me how can i be hacked using all those ?
This is for xp , windows 7 well until eve upgrades to directx10 for me is just useless , vista is even worse .
|

Rico Lobo
|
Posted - 2010.01.08 07:57:00 -
[52]
Originally by: Magnus Nordir Edited by: Magnus Nordir on 05/01/2010 02:06:27 use a mouse and onscreen keyboard to enter the password. Problem solved.
Not realy.
I need to find back that forum thread over on CoH/CoV where one of the new ones that the developers found looks specificaly for any input to the pasword log in from about a year back including virtual keyboards and dropdowns.
As for "true entrophy" I use a old scrable tile set when I want a random password. 26 cap leters 26 smallcase leters 10 number tiles and 20 special characters for thoes systems that accept them. all generated whenever I want one.
|

Rico Lobo
|
Posted - 2010.01.08 08:07:00 -
[53]
as for bliz its either or the token or Iphone app not both.
Because the Iphone app uses GPS based time stamps it has fewer issues than the token which from what I have heard needes to be replaced after about 18 months.
|
|

Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2010.01.08 08:27:00 -
[54]
Posting the mandatory Chribba wants IP-locks post, and yeah I'd pay for a login token as well, or some sort of added security.
/c
Secure 3rd party service |
|

Rico Lobo
|
Posted - 2010.01.08 08:29:00 -
[55]
Originally by: Tallaran Kouros No, no, no and no.
I am familiar with such systems (in particular RSA SecurID) from both a user and a support perspective and these would be highly inappropriate.
The licensing fees and support burden for these is pretty high and if you issued tokens out to users then you would need to have someone next to a phone 24/7 in order to reset tokens and issue new PINs.
.
wich incidentaly doed not apply to Digipass keys wich insicentaly are made in and operated out of China and is not in any was assoceated with RSA . . . . wich should explain a lot in and of itself as to how mutch the system costs.
they are not made by/for RsA SecurID in the US and (I think) Germany.
nor the TecId( I think thats right) tokens that are made in Mexico.(wich is a fraction of the price of the RSA system but then its also only a 6 character ID number system and not the newer Alfa muneric systems that RSA offers nowdays)
According to Bliz it would be cheaper for everyone to have a token than to pay for the suport GMs who currently deal with hacked accounts. (heck they actualy give away a "premium pet" to everyone who gets one.) and considering that they dont actualy have that many Suport GMs to start with. . . it cant be too bloody expensive for them.
Granted they do expect you to pay ~40 usd for the "base" account with the current expansion set too so meh.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.08 08:36:00 -
[56]
Originally by: Chribba Posting the mandatory Chribba wants IP-locks post, and yeah I'd pay for a login token as well, or some sort of added security.
/c
This idea has been blessed by Chribba, the Space Pope of the Church of Veldspar. That's a good sign 
Should we make a formalized [Proposal] thread in the Assembly Hall to be looked at by the CSM? Possibly include it with a number of account security issues and proposals we'd like CCP to consider, such as the "lock characters to prevent theft" and the IP-lock (or IP range lock) as mentioned by Chribba.
|

AmarrettoDiAmarr
|
Posted - 2010.01.09 06:15:00 -
[57]
Originally by: Callista Sincera
So yeah, you are completely wrong if you think that you have to be a brainless fart to get hacked. That just makes it a lot more likely :)
QFT
What I read is that there are several hundred thousand machines compromised every year; I assume that much less than 1% of them play EVE let alone purchased ISK. I also assume the people who are doing malware for profit are going for many passwords: banks, brokerages, PayPal as well as any MMO large enough to have a RMT market. And your machine is compromised if someone else (sibling, parent, significant other) is careless while using it. Certainly the majority of the nine million machines infected with Conflicker/Downadup did not visit ISK sellers. For many, their only failing was not patching frequently enough.
Yes, a 2FA infrastructure would cost something. But it would avoid some existing costs: both the CCP employees who support, investigate and restore ISK, as well as the lost revenue of a hacked subscriber not giving CCP an additional year or two of revenue. E.G., the Grismar website quit being updated when the owner was not happy with CCP response to him being hacked.
The 2FA I know of does not require some hardware to be connected to the computer, USB or otherwise; safer if it is not and it avoids platform and version issues as well. And while hardware is an option, iPhone apps and printed cards of numbers are two alternatives that do not require additional hardware..
tl;dr: While the majority of people who visit bad sites may get hacked, this does not mean that a significant percentage of the people who got hacked visited a ISK RMT site.
|

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.01.11 20:31:00 -
[58]
Sweet, my thread attracted Chribba :)
It sounds like there would be a fair number of people and accounts that would be interested in a 2FA authenticator of some sort. It also recently sounds like blizzard is going to be requiring all accounts to have them - maybe that'll bring the price down since manufacturers will be making lots? -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Salena Tarra
|
Posted - 2010.01.11 20:59:00 -
[59]
Blizzard would never make it mandatory to have one of their authenticators unless they make them free. They might like money but they arent stupid.
I am also in favour of something like this being made for Eve. I think the people saying how only stupid people get their accounts hacked are right and I am have no clue how mine never has been in 6 years of playing MMOs. Unfortunately not all of us belong to the tin foil hat wearing part of society that have a military grade anti-virus system that they created running on their computers.
|

Larg Kellein
Caldari Agony Unleashed Agony Empire
|
Posted - 2010.01.11 21:06:00 -
[60]
I think people are missing an important bit here... Or have never visited the Eve store.
CCP would probably sell you a usb stick for $5, but shipping would take a few weeks at best and cost $85.
|

Seth Ruin
Minmatar Ominous Corp Cult of War
|
Posted - 2010.01.11 21:25:00 -
[61]
Originally by: Larg Kellein I think people are missing an important bit here... Or have never visited the Eve store.
CCP would probably sell you a usb stick for $5, but shipping would take a few weeks at best and cost $85.
So then implement an existing solution instead of developing their own? You can then buy the existing solution from the OEM.
|

Mara Rinn
|
Posted - 2010.01.13 01:23:00 -
[62]
Or make the authenticator an app to run on mobile phones (such as the Blizzard Authenticator for the iPhone).
[Aussie players: join channels ANZAC or AUSSIES] |

Mara Rinn
|
Posted - 2010.01.13 02:16:00 -
[63]
Edited by: Mara Rinn on 13/01/2010 02:22:19
Originally by: Tallaran Kouros In a previous position I was involved with administering RSA SecurID.
The Blizzard authenticator is not a RSA SecurID. The system choses by Blizzard is much simpler (though not as simple as a Yubikey).
Quote: Nobody gets hacked - people get their accounts compromised because they are idiots who respond to phishing emails or install key loggers.
So responding to phishing emails or installing key loggers is not getting hacked?
Damn! That makes my job as IT security officer so much easier. Suddenly I no longer have to defend against all these threats, just by defining them as no longer being threats!
Quote: It's much cheaper for CCP to handle these cases within the existing GM/billing structure than it would be to invest in a two-factor authentication system.
This is based on your experience with the most expensive and resource intensive multifactor authentication system on the planet, combined with your assumptions about GM/billing salaries being lower than the RSA SecurID infrastructure.
Originally by: Mustata Cornel Now can someone tell me how can i be hacked using all those?
DNS poisoning. Social engineering. Zero day exploit. Windows machine without an air-gap firewall. Weak password on EVE account.
QED. [Aussie players: join channels ANZAC or AUSSIES] |

Mara Rinn
|
Posted - 2010.01.13 02:22:00 -
[64]
Edited by: Mara Rinn on 13/01/2010 02:22:38 double post [Aussie players: join channels ANZAC or AUSSIES] |

ChronoSphere
Sturmgrenadier Inc Gentlemen's Club
|
Posted - 2010.02.21 21:27:00 -
[65]
Only a little bit of necro here - looks like there's a lot of support for using 2FA for logins on an optional basis. I know its too much to ask, but it would be nice for some blue bars to comment on this thread :) -------------- ~Admiral, Commanding Officer Sturmgrenadier, Inc. Join Sturmgrenadier today! |

Mara Rinn
|
Posted - 2010.02.21 23:18:00 -
[66]
You could take your discussion over to the thread "[url=http://www.eveonline.com/ingameboard.asp?a=topic&threadID=1249341]Provide services to improve account security[/url]" in the Assembly Hall forum :)
[Aussie players: join channels ANZAC or AUSSIES] |

Epicbeardman
|
Posted - 2010.02.22 00:53:00 -
[67]
I have one of these. It came free with the "human being" package. It's called an occipital lobe and it automatically identifies dodgy links and prevents me from clicking them. |
| |
|
| Pages: 1 2 3 :: [one page] |