| Pages: 1 2 :: [one page] |
| Author |
Thread Statistics | Show CCP posts - 3 post(s) |

Seripis Chiktor
Amarr Cypher Industries.
|
Posted - 2011.03.25 18:54:00 -
[1]
Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned 2: You will loose players if we have to purchase a item to play the game. 3: the security of this type of device is antiquated. 4: How will you handle people who pay for multiple accounts. 5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check.
IP addresses. The ip address setup is worthless. Its easy to ghost an IP and fool this. These whole security measure setup is outdated. It seems more of scare tactic. I want measures in place that work. Not something that is going to catch the idiots.
Macros a macro setup is separate from eve-online install meaning you cannot disable it or punish some one for having it on their computer. Because technically you have no way of proving these macros are being used.
To be honest Im disappointed in todays security brief. you have said a lot of fluff about this. But nothing that is a true and functional security method.
The only true way to prevent this is a motivational approach. Humanity is based on one simple concept We will always take the easiest route with the most gain. So close the gap between traditional methods in game and the bots. Make the rewards in game for doing it the right way the same or better than doing it the wrong way.
Seripis.
Seripis Chiktor Cypher Industries |

Red DragonZA
|
Posted - 2011.03.25 19:04:00 -
[2]
Ditto!
A note on IPs. In countries like South Africa IPs are dynamic. So, you log on... and reset your router.. and presto.. you have a new IP address.
Therefore IP tracking will not really work.
|

Reiisha
EVE University
|
Posted - 2011.03.25 20:11:00 -
[3]
Originally by: Seripis Chiktor Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned 2: You will loose players if we have to purchase a item to play the game. 3: the security of this type of device is antiquated. 4: How will you handle people who pay for multiple accounts. 5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check.
IP addresses. The ip address setup is worthless. Its easy to ghost an IP and fool this. These whole security measure setup is outdated. It seems more of scare tactic. I want measures in place that work. Not something that is going to catch the idiots.
Macros a macro setup is separate from eve-online install meaning you cannot disable it or punish some one for having it on their computer. Because technically you have no way of proving these macros are being used.
To be honest Im disappointed in todays security brief. you have said a lot of fluff about this. But nothing that is a true and functional security method.
The only true way to prevent this is a motivational approach. Humanity is based on one simple concept We will always take the easiest route with the most gain. So close the gap between traditional methods in game and the bots. Make the rewards in game for doing it the right way the same or better than doing it the wrong way.
Seripis.
1: You need the id of the token aswell as the associated account, and find out the algorythm used - Either way it makes it a lot harder for anyone to hack into your account. Even Blizzard with it's 12m+ subscribers is still relatively safe, the only time it was hacked was with a man in the middle attack (which was hard to do in the first place).
2: They specifically said it won't be mandatory. It prolly won't be anyway unless CCP wants to charge people for the token, which i suspect they won't do (yet).
3: What's a better 2+factor method that's easy to implement and cheap?
4: Either link the token to multiple accounts or introduce a master account. Multiple tokens are possible but a little inconvenient.
5: You're already toting a laptop around, a token which is 200 times smaller might still fit in that briefcase/bag.
On IP's: Spoofing them requires knowing what IP is connected to what account in the first place. If you don't have that information you'll still generate at least one entry with the false IP. That, and iirc spoofing only works with udp, tcp packets don't work with it.
You mention that it should be just as easy to 'win' in the game as doing it by cheating. The problem is, bots are a method of playing the game without playing it. You're basically suggesting that people pay for a game they don't actually play, as they can generate infinite isk by doing absolutely nothing aside from logging in. You can't beat that, and most importantly, there will ALWAYS be people who LIKE cheating, regardless of it's reward, because they like griefing or whatever.
Of course i'll be branded a CCP fanboy for saying this, but the security people have put a lot more thought into this than you make it sound like. You're criticizing the methods without offering any (viable) alternatives - That, and Blizzard having set the precedent on how to implement this kind of account security somewhat successfully over 12 million customers, CCP doing the same (and more!) should be much better than them doing nothing at all.
"If you do things right, people won't be sure you've done anything at all"
|

Seripis Chiktor
Amarr Cypher Industries.
|
Posted - 2011.03.26 17:54:00 -
[4]
im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
and a laptop is a tool i utilize for work. This thing would be something extra to hang around and most likely get lost. Seripis Chiktor Cypher Industries |

SIR PRIME
Minmatar FireStar Inc Majesta Empire
|
Posted - 2011.03.29 20:43:00 -
[5]
Its one authenticator to cover all your accounts from the questions we asked after the brief.
Its far better than the current system.
About the only people that really should have a problem with this are account sharers ... and thats against the Eula anyway.
If you have a better idea/method then you can mail them as per the address they gave out in the briefing - if not stop emoing.
|

Ehrine Ashbark
Lyrus Associates The Star Fraction
|
Posted - 2011.03.29 21:03:00 -
[6]
One of the main points of this addition is to help defend against phishing and keylogger attacks, both of which rely on capturing your password which isn't enough when you're using 2-factor.
As someone else said (and CCP said in the brief if you were paying attention), you'll only need one token for all your accounts (as you just tie the accounts to the same token).
As for the IP thing, the main aim there is, again, to catch people logging in from elsewhere. If you log in from an IP in africa, then 5 minutes later from Canada, something fishy is going on. Sure, it won't stop someone really determined, but like most security methods it'll stop the majority of people from being able to break in (which deals with the bulk of the issue). If it's hard enough to do, people will target other things. Hell, lets be honest here, if they could break tokens easily they'd target WoW accounts rather than Eve accounts as there's far more money to be made by flogging stuff on eBay there ;)
|
|

CCP Adida
C C P C C P Alliance

|
Posted - 2011.03.30 20:10:00 -
[7]
Moved from Events and Gatherings.
Adida Community Rep CCP Hf, EVE Online
|
|

Voogru
Gallente Massive Damage We Are John Galt
|
Posted - 2011.03.30 20:16:00 -
[8]
Quote: On IP's: Spoofing them requires knowing what IP is connected to what account in the first place. If you don't have that information you'll still generate at least one entry with the false IP. That, and iirc spoofing only works with udp, tcp packets don't work with it.
It also requires a sending packets from a network that is not secured against UDP spoofing.
|

Kara Sharalien
Gallente Federal Navy Academy
|
Posted - 2011.03.30 20:53:00 -
[9]
Originally by: Seripis Chiktor This thing would be something extra to hang around and most likely get lost.
Then don't use it. I've been begging CCP to implement them for years instead of adding random restrictions to passwords, and would like to extend a huge e-grouphug to all at CCP involved in bringing them to us.
But not to you Seripis. You are not invited to the hug.
|

Aineko Macx
|
Posted - 2011.03.30 21:06:00 -
[10]
Originally by: Red DragonZA A note on IPs. In countries like South Africa IPs are dynamic. So, you log on... and reset your router.. and presto.. you have a new IP address.
Therefore IP tracking will not really work.
You are naive to think they'd do it on a single IP by IP basis. Instead, you do it by network (usually your ISP), which can be trivially obtained by doing a reverse DNS lookup. That would still allow an attacker to access it from an authorized network (given the size of ISPs these days not a far fetched scenarios), but would deter access from completely different network (say, a .cn domain when you are at .comcast.com). Sure, this can also be circumvented by additional means like using a hacked machine inside a trusted network as relay, but its an additional step. CCP is not after absolute security. At the current size of the customer base it is about reduction of incidents, and that can be obtained by such a method. And the keyfob btw. ________________________ CCP: Where fixing bugs is a luxury, not an obligation. |

Zircon Nalelmir
|
Posted - 2011.03.30 21:24:00 -
[11]
ITS OPTIONAL YOU ***GOTS.
|

Kara Sharalien
Gallente Federal Navy Academy
|
Posted - 2011.03.30 21:27:00 -
[12]
Originally by: Zircon Nalelmir ITS OPTIONAL YOU ***GOTS.
You are invited to the hug.
|

Zircon Nalelmir
|
Posted - 2011.03.30 21:31:00 -
[13]
Originally by: Kara Sharalien
Originally by: Zircon Nalelmir ITS OPTIONAL YOU ***GOTS.
You are invited to the hug.
Thanks man.
|

Sekket
Caldari White-Noise
|
Posted - 2011.03.30 23:04:00 -
[14]
Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
|

Vincent Athena
|
Posted - 2011.03.30 23:07:00 -
[15]
"So close the gap between traditional methods in game and the bots. Make the rewards in game for doing it the right way the same or better than doing it the wrong way. "
Can you give a detailed example?
|

Kara Sharalien
Gallente Federal Navy Academy
|
Posted - 2011.03.31 04:08:00 -
[16]
Originally by: Sekket Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
>>implying that security questions are more secure and/or less annoying then a dongle that generates psudo-random passwords
|

Jonathon Silence
Thorny Rose Enterprises
|
Posted - 2011.03.31 04:18:00 -
[17]
Originally by: Sekket Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
Not sure if an RSA cert is any different from any other SSL cert in any way, but it is trivial to script the export of a cert from a PC. If a key logger or other software has been installed it would not be much work to add teh functionality to copy the sert from the store on the pc and send that back to the Command and control server.
As most people still run as local admin with UAC turned off I am pretty certain that accessing the Secure Cert store would not be that difficult either. Not entirely sure on this as I do not work with the Secure Cert store that often.
Jonathon Silence
|

Miso Hawnee
|
Posted - 2011.03.31 05:14:00 -
[18]
Originally by: Seripis Chiktor
The only true way to prevent this is a motivational approach.
Seripis.
I live in a van, down by the river... 
|

Taedrin
Gallente The Green Cross Controlled Chaos
|
Posted - 2011.03.31 05:26:00 -
[19]
Originally by: Red DragonZA Ditto!
A note on IPs. In countries like South Africa IPs are dynamic. So, you log on... and reset your router.. and presto.. you have a new IP address.
Therefore IP tracking will not really work.
Dynamic IP addresses are not random. You are assigned an IP address from an allocated pool given to your ISP to hand out. IANA (The Internet Assigned Numbers Authority) assigns IP addresses to Regional Internet Registries, who in turn hand out IP addresses given to them by IANA to ISPs.
See here for the (almost completely filled up) IPv4 address space. As you can see, IP addresses have a very vague geographical location. assigned to them. You can increase the accuracy of the geographical location of an IP address by using geolocation techniques. These techniques look at your ISP, and how your ISP distributes IP addresses to their customers. They hand out certain ranges of IP addresses to customers served by certain routers. FURTHERMORE, you can do a traceroute of an IP address to give a reliable geographic location by parsing the names of the router's domain names.
Hackers can NOT "spoof" this in two way, secure communication. I have yet to hear a valid argument on how this can easily be countered by hackers. ----------
Originally by: Dr Fighter "how do you know when youve had a repro accident"
Theres modules missing and morphite in your mineral pile.
|
|

CCP Sreegs

|
Posted - 2011.03.31 09:41:00 -
[20]
Edited by: CCP Sreegs on 31/03/2011 09:47:25 Edited by: CCP Sreegs on 31/03/2011 09:41:35
Originally by: Voogru
Quote: On IP's: Spoofing them requires knowing what IP is connected to what account in the first place. If you don't have that information you'll still generate at least one entry with the false IP. That, and iirc spoofing only works with udp, tcp packets don't work with it.
It also requires a sending packets from a network that is not secured against UDP spoofing.
Spoofing IPs is almost a myth and can only be accomplished if you're pretty much on the same network as the guy you want to spoof.
:edit: The upstream path, but I'm trying to keep it simple
:edit2: the guy above me actually explained it better |
|
|

CCP Sreegs

|
Posted - 2011.03.31 09:54:00 -
[21]
Originally by: Seripis Chiktor Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned - What makes you think this? It's not trivial to do. 2: You will loose players if we have to purchase a item to play the game. - They don't have to 3: the security of this type of device is antiquated. - Provide more input please. What do you consider to be "cutting edge"? 4: How will you handle people who pay for multiple accounts. - As I said it will work across them 5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check. - Then don't get one
IP addresses. The ip address setup is worthless. Its easy to ghost an IP and fool this. - This is a terribly wrong statement regarding the ghosting. These whole security measure setup is outdated. It seems more of scare tactic. I want measures in place that work. Not something that is going to catch the idiots. - Please give me some examples of solutions that you think will work. What I see so far is you declaring that good solutions are bad without any feedback other than "I think it's bad" which could lead one to believe that you have no idea about what you're talking about.
Macros a macro setup is separate from eve-online install meaning you cannot disable it or punish some one for having it on their computer. Because technically you have no way of proving these macros are being used. - Not true.
To be honest Im disappointed in todays security brief. you have said a lot of fluff about this. But nothing that is a true and functional security method. - You just spent a post detailing a small portion of the true and functional security methods we said we're implementing then saying we didn't give any. Which is it?
The only true way to prevent this is a motivational approach. Humanity is based on one simple concept We will always take the easiest route with the most gain. So close the gap between traditional methods in game and the bots. Make the rewards in game for doing it the right way the same or better than doing it the wrong way.
Seripis.
I put my responses in line because I have no idea how better to do so |
|

Eyeama Spy
|
Posted - 2011.03.31 11:10:00 -
[22]
Just gotta love forum warriors, ccp goes to the trouble to hire a security team that knows their business and a load of tards on the interweb think they know the subject better then the experts. I hope that they all use bots and get banned.
|

Skippermonkey
Suddenly Ninjas Tear Extraction And Reclamation Service
|
Posted - 2011.03.31 11:24:00 -
[23]
if only stupidity on the forums gave out killrights in game...
(but then, i'd be podded repeatedly)
:p WHALE STEAK IS TASTY :) but i didnt get to eat the puffin :( |

yumike
|
Posted - 2011.03.31 11:37:00 -
[24]
Originally by: Seripis Chiktor 1: they can be cloned
Not really, Or at least - not feasibly. The only way they are typically "broken" are either via losing control of attached email and removing & re-attaching a new one) Or if the keylogger on your system is active, and sub ~2minutes or whatever the timeout is the hacker uses the login password and auth key.
Originally by: Seripis Chiktor 2: You will loose players if we have to purchase a item to play the game.
Why would you ever assume "extra security" would be *required*? Of course its optional, You shouldn't insinuate otherwise.
Originally by: Seripis Chiktor 3: the security of this type of device is antiquated.
I somewhat agree, And i'll personally never use any sort of authenticator for any game I play since its just more hassle and one more thing for me to lose.
Originally by: Seripis Chiktor 4: How will you handle people who pay for multiple accounts.
A fair question. Likely via a 'master' account sort of system.
Originally by: Seripis Chiktor 5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check.
Don't buy one.. then?
Originally by: Seripis Chiktor The ip address setup is worthless. Its easy to ghost an IP and fool this.
...No. Until you learn something about BGP and how networking is done, It's not possible to spoof a working ip address. I can send you snail mail with whatever address I want on it, Spoofing any real address.. But I can never get a response from you - the internet works the exact same.
Originally by: Seripis Chiktor These whole security measure setup is outdated. It seems more of scare tactic. I want measures in place that work.
You've already proven you know nothing, Which isn't a big deal (Not everyone knows much about network engineering.. its not a requirement in todays society.) But it all strips you of the ability to try and call them out for using "measures that dont work"
I'll stop.. for now.
|

Florestan Bronstein
Amarr Taishi Combine
|
Posted - 2011.03.31 11:38:00 -
[25]
Edited by: Florestan Bronstein on 31/03/2011 11:43:21
Originally by: CCP Sreegs a macro setup is separate from eve-online install meaning you cannot disable it or punish some one for having it on their computer. Because technically you have no way of proving these macros are being used. - Not true.
would like some more elaboration on the answer to this question, please.
Server-side detection can never provide "proof" (only indication - you can conclude that no single human player can mine 23/7 for several days without interruption but that's no positive proof that this account is indeed run by a bot, it just makes a bot the most likely explanation for the observed behavior) and I don't see any compelling reason why it shouldn't be possible to write a bot that won't raise any flags server-side.
Why not just record a couple dozen of real game sessions and make the bot interpolate between them? there is no law that says a bot has to run 23/7 and do just one task - I am sure bot writers will eventually become more creative (e.g. why not pull random text snippets from the web and have the bots chat with each other during their "mining op"?).
And I have no clue how one would build client-side detection that actually works - it will always come down to shoving EVE into some sort of VM and running the macro from outside the VM. You don't allow EVE to run under VMWare Workstation/VirtualPC/... - botters move to bare metal hypervisors; you try to prevent EVE from running on these, botters will start to investigate "Blue Pill"-like techniques.
If malware can have the capability to hijack a running system and install a hypervisor below it without anyone noticing - how are you going to prevent this from happening with the user's consent?
Do you want prevent people from running any form of remote access software on the PCs they run EVE on? If not, why not just run the bot on another machine than the EVE client?
Without use of Trusted Computing-like techniques how can you reliably detect/prevent bots client-side?
Maybe you feel confident that you can detect all bots currently out there - but I simply don't see how you can feel confident that you are in principle able to detect bots. (You could hire an awful lot of GMs and have them perform Turing tests but even that is imo only a temporary solution)
|

Mara Rinn
|
Posted - 2011.03.31 11:48:00 -
[26]
Originally by: Florestan Bronstein Server-side detection can never provide "proof" (only indication - you can conclude that no single human player can mine 23/7 for several days without interruption but that's no positive proof that this account is indeed run by a bot, it just makes a bot the most likely explanation for the observed behavior) and I don't see any compelling reason why it shouldn't be possible to write a bot that won't raise any flags server-side.
What advantage is there in running a bot which is indistinguishable from a human? Why would you pay for that bot rather than buy a plex?
-- [Aussie players: join ANZAC channel] |

RaTTuS
BIG Gentlemen's Agreement
|
Posted - 2011.03.31 11:50:00 -
[27]
if it looks like a badger, if it smells like a badger, if it plays like a badger, if it feels like a badger, is it in fact a dog
--
Join BIG
|

Florestan Bronstein
Amarr Taishi Combine
|
Posted - 2011.03.31 11:52:00 -
[28]
Edited by: Florestan Bronstein on 31/03/2011 11:56:20
Originally by: Mara Rinn
Originally by: Florestan Bronstein Server-side detection can never provide "proof" (only indication - you can conclude that no single human player can mine 23/7 for several days without interruption but that's no positive proof that this account is indeed run by a bot, it just makes a bot the most likely explanation for the observed behavior) and I don't see any compelling reason why it shouldn't be possible to write a bot that won't raise any flags server-side.
What advantage is there in running a bot which is indistinguishable from a human? Why would you pay for that bot rather than buy a plex?
because you can?
With use of different PCs, internet connections/VPNs, credit cards, ... you could of course run several of these bots in parallel.
(I have studied quite some time in an environment in which any computer-assisted proof was deemed to be highly unsatisfactory because you practically can't prove that the hardware used to derive it is in fact 100% bug-free - if you haven't done it, you should try some mathematics, it can really change your perception of ideas like "truth", "proof", "certainty")
|

Grimpak
Gallente The Whitehound Corporation Frontline Assembly Point
|
Posted - 2011.03.31 12:18:00 -
[29]
Originally by: RaTTuS if it looks like a badger, if it smells like a badger, if it plays like a badger, if it feels like a badger, is it in fact a dog
no, it's a cat. ---
Quote: The more I know about humans, the more I love animals.
ain't that right. |

Mara Rinn
|
Posted - 2011.03.31 12:26:00 -
[30]
Originally by: Florestan Bronstein because you can?
With use of different PCs, internet connections/VPNs, credit cards, ... you could of course run several of these bots in parallel.
Does that get you some sort of advantage over normal game play?
Quote: I have studied quite some time in an environment in which any computer-assisted proof was deemed to be highly unsatisfactory because you practically can't prove that the hardware used to derive it is in fact 100% bug-free
I, too, have done first year Software Engineering. I have mathematically proven the correctness of code, and undersrand how one would try to outsmart themselves. What I am asking is why, and what benefit would one hope for when there is no net gain.
I was hoping for something like "so I have a scout I trust" raher than "because." ;) -- [Aussie players: join ANZAC channel] |

dexington
Caldari Baconoration
|
Posted - 2011.03.31 12:28:00 -
[31]
Edited by: dexington on 31/03/2011 12:28:37
Originally by: Seripis Chiktor Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned 2: You will loose players if we have to purchase a item to play the game. 3: the security of this type of device is antiquated. 4: How will you handle people who pay for multiple accounts. 5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check.
IP addresses. The ip address setup is worthless. Its easy to ghost an IP and fool this. These whole security measure setup is outdated. It seems more of scare tactic. I want measures in place that work. Not something that is going to catch the idiots.
Macros a macro setup is separate from eve-online install meaning you cannot disable it or punish some one for having it on their computer. Because technically you have no way of proving these macros are being used.
To be honest Im disappointed in todays security brief. you have said a lot of fluff about this. But nothing that is a true and functional security method.
The only true way to prevent this is a motivational approach. Humanity is based on one simple concept We will always take the easiest route with the most gain. So close the gap between traditional methods in game and the bots. Make the rewards in game for doing it the right way the same or better than doing it the wrong way.
Seripis.
It's clear that you in no way what so ever have the technical knowledge needed to discuss or evaluate the results or effectiveness, of any digital security feature. More or less ever assumption you are making about the security features are wrong, next time you feel like raging on the forums ask questions before you state your false assumptions as fact, it would make you look like less of a fool.
|

Commander Azrael
Red Federation
|
Posted - 2011.03.31 13:23:00 -
[32]
Edited by: Commander Azrael on 31/03/2011 13:25:21
Originally by: Seripis Chiktor im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
What does RSA have to do with Blizzard? Or are you just complaining because blizzard use the actual tech to secure their accounts and you want something different?
Originally by: Seripis Chiktor Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned
Can you link me to a POC for this cloning? I genuinely am interested in knowing where you got this info from.
|

Awesome Possum
Original Sin. PURPLE HELMETED WARRIORS
|
Posted - 2011.03.31 13:30:00 -
[33]
Originally by: Commander Azrael Edited by: Commander Azrael on 31/03/2011 13:25:21
Originally by: Seripis Chiktor im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
What does RSA have to do with Blizzard? Or are you just complaining because blizzard use the actual tech to secure their accounts and you want something different?
how about leaving account security as the responsibility of the person creating and submitting the password? if you're silly enough to go watch some audrey bitoni **** then that's that. ♥
|

Ben Alman
Gallente
|
Posted - 2011.03.31 13:38:00 -
[34]
Edited by: Ben Alman on 31/03/2011 13:44:32
Originally by: Commander Azrael Edited by: Commander Azrael on 31/03/2011 13:25:21
Originally by: Seripis Chiktor im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
What does RSA have to do with Blizzard? Or are you just complaining because blizzard use the actual tech to secure their accounts and you want something different?
Originally by: Seripis Chiktor Im wondering how they will get past the practicality of utilizing a authenticator.
1: they can be cloned
Can you link me to a POC for this cloning? I genuinely am interested in knowing where you got this info from.
The algorithm (which takes time and a S/N as input) is known. (There are 3rd party authenticator apps for mobiles and PC out there) However in order to clone one you need to know it's serial number which you practically can't, except phishing(and there is nothing you can do about stupidity) or holding it in your hands which defeats the whole cloning point.
Theoretically it should be possible to reverse engineer the S/N from many many many codes. But this just leads us back to the stupidity part :)
|

De'Veldrin
Minmatar Self Preservation Society the 2nd Dead Terrorists
|
Posted - 2011.03.31 13:39:00 -
[35]
Originally by: Awesome Possum
Originally by: Commander Azrael Edited by: Commander Azrael on 31/03/2011 13:25:21
Originally by: Seripis Chiktor im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
What does RSA have to do with Blizzard? Or are you just complaining because blizzard use the actual tech to secure their accounts and you want something different?
how about leaving account security as the responsibility of the person creating and submitting the password? if you're silly enough to go watch some audrey bitoni **** then that's that.
And, as has been stated by CCP themselves, if you don't want it, don't get it. Even Blizzard's is optional last I knew, so no one is saying you aren't a big boy who can't dress himself in the morning. Quit raging about it.
I, for one, have been arguing for the use of tokens for a while. --Vel
Originally by: Blacksquirrel
This is EVE. PVE can happen anywhere at anytime. Be prepared.
|

ZombifiedRob
|
Posted - 2011.03.31 13:55:00 -
[36]
Back when I was into WoW I didn't mind having the authenticator. Threw it on my keychain and I was good to go. As long as they don't make it mandatory I don't have a problem with it. |

Commander Azrael
Red Federation
|
Posted - 2011.03.31 14:28:00 -
[37]
Originally by: Awesome Possum
Originally by: Commander Azrael Edited by: Commander Azrael on 31/03/2011 13:25:21
Originally by: Seripis Chiktor im disappointed because the people at CCP normally hold them self to higher standards than blizzard. Why do they not do this now?
What does RSA have to do with Blizzard? Or are you just complaining because blizzard use the actual tech to secure their accounts and you want something different?
how about leaving account security as the responsibility of the person creating and submitting the password? if you're silly enough to go watch some audrey bitoni **** then that's that.
They're optional. Don't like it, don't use it. More security options are never a bad thing. And considering the debacle that was the recent spotify auto installing malware to your machine, you don't have to always visit nefarious sites to get keyloggers and trojans.
Originally by: Ben Alman
The algorithm (which takes time and a S/N as input) is known. (There are 3rd party authenticator apps for mobiles and PC out there) However in order to clone one you need to know it's serial number which you practically can't, except phishing(and there is nothing you can do about stupidity) or holding it in your hands which defeats the whole cloning point.
Theoretically it should be possible to reverse engineer the S/N from many many many codes. But this just leads us back to the stupidity part :)
Yeah exactly, acquiring the serial number is almost impossible and the algorithm is well known but knowing that alone isn't much help.
the RSA algorithm has been around since the late 70's and is still widely used, that's pretty secure.
Still, all these people complaining about it. Why don't they just not use it? 
|

Ingvar Angst
Amarr Omni Industrial Coalition Talocan United
|
Posted - 2011.03.31 14:45:00 -
[38]
One problem people have in WoW is those without authenticators finding their accounts hacked and an authenticator put on the hacked account. CCP will need to make sure to have a system in place to remove authenticators obviously, but the only real way to prevent that is for CCP to basically send everyone a free authenticator and make them mandatory.
|

dexington
Caldari Baconoration
|
Posted - 2011.03.31 14:53:00 -
[39]
Originally by: Ingvar Angst One problem people have in WoW is those without authenticators finding their accounts hacked and an authenticator put on the hacked account. CCP will need to make sure to have a system in place to remove authenticators obviously, but the only real way to prevent that is for CCP to basically send everyone a free authenticator and make them mandatory.
I don't know if you mean the GM should be able to remove the token authorization, or the user. I'm sure the GM's are able to do it, but if the users are able to do it without the token it's a huge security risk, then you are basically back to one password based authorization.
|

Barakkus
|
Posted - 2011.03.31 16:47:00 -
[40]
Originally by: Seripis Chiktor
3: the security of this type of device is antiquated.
Please relay your information to ExxonMobil, AT&T, Harris Bank and a host of other multi billion dollar corporations that require RSA tokens for accessing various things.
It is not a requirement, you can use it if you want to. - - [SERVICE] Corp Standings For POS anchoring
|

Ben Alman
Gallente
|
Posted - 2011.03.31 17:00:00 -
[41]
FYI this is the one WoW uses (+mobile variants)
Digipass
|

Steve Thomas
Minmatar
|
Posted - 2011.03.31 17:05:00 -
[42]
Originally by: Seripis Chiktor Seripis.
ok in order, Im wondering how they will get past the practicality of utilizing a authenticator.WoW has roughly 30% of the accounts that are live linked to Authenticators, and they have actualy stated repetedly that they ARE considering just adding Authenticators to the boxed retail units. WoW has more accounts in France and Germany combined than EVE has subscriptions. or in other words.
Distribution is not a problem.
or did you mean that people who play mmos will not know how to push a button on the fob and then key in the 1 time security passcode?
1: they can be cloned How?
If your thinking cellphone cloneing from snooping in, well you dont hear about mass outbreaks of that happening, and you dont have an actual RF signal being generated. so they basicaly have to take YOUR token and clone it.(and if they can do that, why the hell would they bother when they can just steal your stuff and pawn it)
if someone manages to get the list of posible Token algorythms and codes. . . well Blizzard authenticators alone has 10^12 posible code keys. . . so you have to actualy hack into the Blizzard database to find whos key belongs to whos account. . . and thoes ARE NOT hooked to the internet directly, you have to go through the login or through dedicated terminals to access thoes, and if you have access to that. . .you STILL Need the password which is actualy handled by a seperate system and may I ask the hopefully obvious question, WHY THE HELL ARE YOU WASING TIME AND CREAKING MAKE WORK FOR YOUSELF TO STEAL A FEW HUNDRED USD WORTH OF GAME CURRENCY PER ACCOUNT WHEN YOU COULD HAVE STOLLEN ALL OF THE CC INFO FROM OVER 5 ****MILLION**** CURRENT SUBSCRIBER ACCOUNTS that pay Via credit card, (not counting the accounts payed via Debit cards and so on)
2: You will loose players if we have to purchase a item to play the gameUm dude, you lost that argument the second you made it. (1) they are not morons, there not going to try to make a profit on every one of thies they seel (2) most game companies going to this have said there not going to charge more than S&H for them, and some are actualy talking openly about putting them in the game box. (3) you do realise that the average mmo player pays more than 2 subs a month as it is.
4: How will you handle people who pay for multiple accounts.already discused elsewhere in painfull detail, but you were so buisy craming your fingers in your ears going NONONONONONONO to listen, but one last time. abd hopefully you will get it this time
you can use 1 Authenticator to activate one account. Once you activate that Authenticator its assigned to the billing info on that account, you can then put that authenticator on any account that is matches that information.
5: I often play from home work and while I'm traveling. I'm not toting some chip around with me just so i can do a skill check.then dont. or remove it from your account and risk getting hacked. up to you .end of line.
----
If you think your too paranoid to play EvE...
Then you clearly are not paranoid enough to play EvE
(Alt list) Rico Lobo |

Barakkus
|
Posted - 2011.03.31 17:11:00 -
[43]
Edited by: Barakkus on 31/03/2011 17:11:32
Originally by: Steve Thomas
1: they can be cloned How?
http://www.engadget.com/2011/03/18/rsa-hacked-data-exposed-that-could-reduce-the-effectiveness-o/
Just an example, but meh doesn't matter much really. - - [SERVICE] Corp Standings For POS anchoring
|

Iftama
|
Posted - 2011.03.31 17:18:00 -
[44]
Originally by: Sekket Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
Password + "security" questions are still only one factor. |

Kurfin
|
Posted - 2011.03.31 17:29:00 -
[45]
No security measure, or anti-bot measure, is going to be 100% effective. But if they can reduce account hacking and/or botting it's gotta be a good thing. Quit complaining.
|

Taedrin
Gallente The Green Cross Controlled Chaos
|
Posted - 2011.03.31 17:38:00 -
[46]
Originally by: Barakkus Edited by: Barakkus on 31/03/2011 17:11:32
Originally by: Steve Thomas
1: they can be cloned How?
http://www.engadget.com/2011/03/18/rsa-hacked-data-exposed-that-could-reduce-the-effectiveness-o/
Just an example, but meh doesn't matter much really.
But that brings us back to the question: if you can hack a heavily secured corporate server, why bother stealing MMO accounts, when you can steal credit card numbers.
Or better yet, why not hack into bank servers and steal billions of dollars by electronically wiring money? The reason? Because it is HARD, and you can pretty much assume that your average script kiddy isn't gonna have the brains to do this sort of thing.
Think about it this way: why hack into CCP's RSA server to steal RSA tokens so that they can more easily steal accounts when they could instead hack into CCP's database and give themselves as much ISK as they could ever possibly want? ----------
Originally by: Dr Fighter "how do you know when youve had a repro accident"
Theres modules missing and morphite in your mineral pile.
|

Steve Thomas
Minmatar
|
Posted - 2011.03.31 17:59:00 -
[47]
Originally by: Barakkus Edited by: Barakkus on 31/03/2011 17:11:32
Originally by: Steve Thomas
1: they can be cloned How?
http://www.engadget.com/2011/03/18/rsa-hacked-data-exposed-that-could-reduce-the-effectiveness-o/
Just an example, but meh doesn't matter much really.
Bascialy, the solution to the problem was to simply secure the sytem they used and re-issue new tokens thus rendering all existsing tokens (and the effort used to hack the system useless. they now segmented and disconected the archive, it now takes more effort to get the master key list, and even then all they realy got was a "list" of 10^16 out of 10^64 posible keys.
given how thoes keys work. . . it would be faster for them to just physicaly steal the disk drives dismantel them and build hardware to scan the data on the disks directly than to sit there and even spudo manualy go through literaly 1,000,000,000,000, keys. . .and hope that the batch of keys that you have is the correct ones out of 10,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 posible keys that existed at that time. the system they had at the time Did not store the actual keys used from each call for authentication. you would have to somehow capture that data wich is located on another server.
they now have avalible a theorectical 10^2048 key generator algorythms/seed combinations.
Frankly the same hack atack effort could also be used to get the accounts and passwords, and have frankly doing so is a lot easyer. .end of line.
----
If you think your too paranoid to play EvE...
Then you clearly are not paranoid enough to play EvE
(Alt list) Rico Lobo |

dexington
Caldari Baconoration
|
Posted - 2011.03.31 18:36:00 -
[48]
Originally by: Barakkus Edited by: Barakkus on 31/03/2011 17:11:32
Originally by: Steve Thomas
1: they can be cloned How?
http://www.engadget.com/2011/03/18/rsa-hacked-data-exposed-that-could-reduce-the-effectiveness-o/
Just an example, but meh doesn't matter much really.
The article seems to imply that it would be possible to reproduce the token in software, using the information stolen by the hackers. The article says the RSA advice they customers to enforce strong pin/password policies, probably to avoid brute force attacks. That is not the same as cloning the two-factor authentication token, for that you would need to extract the secret from the token.
Without physical access to the token and using something like optical micro probing to read the data directly from the hardware, you would need to steal the data from the CCP key servers. Anyone with the much access to the CCP infrastructure, could probably do a lot more interesting things then get access to the eve accounts. Personally i would use that kinda of unlimited network access to try and hack into StevieSG laptop, and see if there was any bikini pictures from her last vacation.
|

Steve Thomas
Minmatar
|
Posted - 2011.03.31 18:48:00 -
[49]
or to put it another way
the net result of that hack attack was to get a bunch of "key blanks" without knowing what the actual keys look like it was literaly a massice waste of time .end of line.
----
If you think your too paranoid to play EvE...
Then you clearly are not paranoid enough to play EvE
(Alt list) Rico Lobo |

Idami Raptor
Gallente Section Eight LLC Omega Vector
|
Posted - 2011.03.31 20:13:00 -
[50]
Have to agree with CCP, the author seems to just be ranting and raving about how aweful this is without providing any alternatives. It's like he's just 'heard about' these problems and has no idea what any of it means or how it works, and no idea of the alternatives.
I have a blizzard authenticator somewhere...I'm not sure where as I haven't used it for 2 years, but it's here somewhere. And it wouldn't be as easy to clone as you'd think, either. It's a rebranded Vasco Digipass Go-6, which uses either DES, 3DES, or AES as the hash function, and has at least two components in the input that are variable: a unique ID for the key, and an input taken from an internal clock.
In order to clone it, you would need to know the Key's unique ID AND the state of its internal clock, in order to duplicate both factors. I don't know for sure how they do it, but if I were setting it up, the Key's serial number would NOT be the input. Instead I'd have a lookup table where the key's unique ID was related to its serial number. I'd also have each key's clock set a different way.
It generates a 6 digit key(meaning 1 million possible keys) that changes about every minute and a half or so. Each key is only valid for use ONCE. If you need another one you have to wait until it's refreshed.
It isn't perfect, but it's not intended to be. You can NOT make any system completely secure, it's completely impossible. There are ALWAYS holes. The key is making it hard enough to get in through them that people don't bother. This is why it works for Blizzard. Earlier in the thread, someone said Blizzard had about 30% adoption of the authenticators. That means that 70% of the time, the folks stealing accounts don't NEED to try to get around one, so they likely won't bother trying. If the adoption rate got higher, you'd start to see more attacks on them and then it might get interesting.
The primary vulnerability of these sorts of tokens is a man in the middle attack: the attacker intercepts all communications in both directions and can use that to his own advantage. The problem here though, is that since each key is only valid once, for a relatively short window, they have to take advantage of it right that moment in order to get any use out of it. Meaning you got a confused end user sitting there wondering why he can't get on the server. Early on, Blizzard facilitated this sort of attack by making it possible to remove the authenticator from the account via two clicks on the account management page, which only required one authenticator key to get to. I warned 'em about that, loudly when they didn't listen initially, and they eventually changed it so that authenticator removal required two consecutive keys from the token AFTER using one to log in. Not perfect, but stronger, as the chances of intercepting three keys, especially with two of them being REQUIRED to be consecutive, is much lower than intercepting one.
It is of course vulnerable to social engineering attacks, but what isn't?
The only other flaw is that I always figured it had to consider the keys valid for a wider window than they were generated in, to account for possible variances in the clocks over time, so there may actually be multiple keys that are considered valid at any given time. Due to the frequency of them changing and the sheer number of possible keys, brute forcing it would be VERY difficult even so. Not impossible, but down to a matter of luck rather than just how much time you spend on it.
|

Barakkus
|
Posted - 2011.03.31 20:26:00 -
[51]
Originally by: dexington Personally i would use that kinda of unlimited network access to try and hack into StevieSG laptop, and see if there was any bikini pictures from her last vacation.
This tbqfh. - - [SERVICE] Corp Standings For POS anchoring
|

dexington
Caldari Baconoration
|
Posted - 2011.03.31 20:29:00 -
[52]
Originally by: Idami Raptor The primary vulnerability of these sorts of tokens is a man in the middle attack
Seems unlikely someone would decide to use two-factor authentication, and not use ssl for the connection during authentication.
|

Idami Raptor
Gallente Section Eight LLC Omega Vector
|
Posted - 2011.03.31 21:04:00 -
[53]
Originally by: dexington
Originally by: Idami Raptor The primary vulnerability of these sorts of tokens is a man in the middle attack
Seems unlikely someone would decide to use two-factor authentication, and not use ssl for the connection during authentication.
Well that's the key point of a MitM: They're basically acting as a proxy between the endpoints, intercepting everything, and spoofing both sides claiming to be the opposite endpoint. In such a case, the MitM can also ALTER anything that passes through however they choose.
What would happen, then, is that the MitM would connect to the server via that very SSL connection, as it intercepted and altered the handshake to have CCP open the secure connection with it instead of the user. After that, it gets tricky for him.
If the user(or their client) is expecting the SSL connection, he can't simply leave the end unsecured or the user will notice and figure out something's up. In that case he has to set up an SSL connection to the user, and depending on the setup may have to try to spoof the certificate too. He'll have a copy of the certificate CCP wanted to use from the SSL connection he's got to CCP, which might help some with that...
Harder? Yes. Impossible? Not hardly.
Worth the effort? That's the important question.
|

Furb Killer
Gallente
|
Posted - 2011.03.31 21:14:00 -
[54]
Originally by: Sekket Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
Doesnt having both authentication requirements on the same client (the certificate and the password) kinda defeat the entire idea behind two-factor authentication?
|

Idami Raptor
Gallente Section Eight LLC Omega Vector
|
Posted - 2011.03.31 21:25:00 -
[55]
Originally by: Furb Killer
Originally by: Sekket Edited by: Sekket on 30/03/2011 23:07:12
Originally by: Reiisha
3: What's a better 2+factor method that's easy to implement and cheap?
Generate and store an RSA cert on the client in the secure certificate store. If it's not present, require the user to provide the answers to his security questions.
/former2factorauthenticationprogrammer
Doesnt having both authentication requirements on the same client (the certificate and the password) kinda defeat the entire idea behind two-factor authentication?
And couldn't you still man in the middle that by just passing on the certificate from the real client? Especially if it's stored, and doesn't change?
|

dexington
Caldari Baconoration
|
Posted - 2011.03.31 21:35:00 -
[56]
Originally by: Idami Raptor
If the user(or their client) is expecting the SSL connection, he can't simply leave the end unsecured or the user will notice and figure out something's up. In that case he has to set up an SSL connection to the user, and depending on the setup may have to try to spoof the certificate too. He'll have a copy of the certificate CCP wanted to use from the SSL connection he's got to CCP, which might help some with that...
Harder? Yes. Impossible? Not hardly.
Worth the effort? That's the important question.
Unless you have a copy of the cert used by the server there is no way you can do mitm, without the client knowing something is wrong. Most app's that use ssl deploy with the cert fingerprint, and drop all connections that can't be established using the matching cert. Web browsers store the fingerprint first time you connect to the server, and gives the user a big "red" warning if the fingerprint no longer match the server cert.
You can't just "spoof" the credentials needed for at trusted ssl connection, and just making a copy would be the equivalent of making a PGP private key using only the public key, which with known mathematics is considered impossible.
So to be able to do a silent ssl mitm, you would basically need to hack the server running the ssl connection, making the mitm interception of data some what pointless.
|

Aineko Macx
|
Posted - 2011.03.31 21:38:00 -
[57]
@Sreegs: You said at the presentation that players will require either the TAN or knowledge of one charname on that account during every single login attempt. You could however make a small convenience exception to that: If the current login attempt comes from the same IP as the last login and is within a certain timespan (say, a few hours), you could dispense of the second factor authentication (the charname isn't a second factor, but you get the idea). This would greatly reduce the hassle for re-logons when switching chars or after disconnects and would thus help the token adoption rate, with negligible impact on the security. ________________________ CCP: Where fixing bugs is a luxury, not an obligation. |

Idami Raptor
Gallente Section Eight LLC Omega Vector
|
Posted - 2011.03.31 22:15:00 -
[58]
Originally by: dexington
Originally by: Idami Raptor
If the user(or their client) is expecting the SSL connection, he can't simply leave the end unsecured or the user will notice and figure out something's up. In that case he has to set up an SSL connection to the user, and depending on the setup may have to try to spoof the certificate too. He'll have a copy of the certificate CCP wanted to use from the SSL connection he's got to CCP, which might help some with that...
Harder? Yes. Impossible? Not hardly.
Worth the effort? That's the important question.
Unless you have a copy of the cert used by the server there is no way you can do mitm, without the client knowing something is wrong. Most app's that use ssl deploy with the cert fingerprint, and drop all connections that can't be established using the matching cert. Web browsers store the fingerprint first time you connect to the server, and gives the user a big "red" warning if the fingerprint no longer match the server cert.
You can't just "spoof" the credentials needed for at trusted ssl connection, and just making a copy would be the equivalent of making a PGP private key using only the public key, which with known mathematics is considered impossible.
So to be able to do a silent ssl mitm, you would basically need to hack the server running the ssl connection, making the mitm interception of data some what pointless.
Unless the client doesn't verify that the SSL connection actually comes from the expected source. If it doesn't check that, then rather than having to spoof the cert you just give them YOURS, the same as replacing a public key sent in a message with your public key, and then doing a de-crypt/re-encrypt.
In this particular case though, it's not quite your normal man in the middle attack you'd want to do. Instead of proxying it, you'd really just need to pull the authentication credentials, block the user's connection attempts, and during that change the user's password and remove the authenticator. Which is why blizzard's early implementation was particularly prone to it: one key from the authenticator was enough to do that, making it easier to automate without requiring social engineering.
Done properly, you're flat on right, it's very very hard to break without some serious social engineering, which is probably more effort than most are ever going to go to.
In the end, it's all about making it harder for the attacker to make a profit. The more it costs to get in, the less the attacker comes away with in the end. Make it hard enough, and they just don't bother. The work isn't worth the return.
In some ways making it mandatory would actually hurt that goal. The accounts without it act as low hanging fruit, and as long as there's enough of them to keep the account thieves happy, they won't be willing to expend much effort on breaking it. If everyone had it on the other hand, they might.
|

dexington
Caldari Baconoration
|
Posted - 2011.03.31 23:40:00 -
[59]
Originally by: Idami Raptor Unless the client doesn't verify that the SSL connection actually comes from the expected source. If it doesn't check that, then rather than having to spoof the cert you just give them YOURS, the same as replacing a public key sent in a message with your public key, and then doing a de-crypt/re-encrypt.
Not the most likely scenario, that would pretty much be the biggest mistake possible to do in the implementation of secure sockets.
|
| |
|
| Pages: 1 2 :: [one page] |