
Blue Dragon
|
Posted - 2003.10.28 09:04:00 -
[1]
Please understand that this is not an attack against you. It's just that the idea itself stinks...
I like the idea, but the problem is that I can see it being WELL and TOO EASILY exploited.
It would not be hard for someone to send a false message to the CCP servers, for one. Imagine the pain of seeing your wallet icon flash for no reason, and on clicking on it there is no money left because you supposedly did an online transfer.
Network engineer and web programmer both IRL, so unfortunately, I already can see how this could be a severe problem. Your account effectively gets hacked, you lose all your ISK's. You appeal to the CCP and chances are, your not the only one to have lost your shorts, so they'll be busy as it is. In the mean whiles your sitting with no cash. Heavens forbid if your the financial officer for your corp and they implement fund transfers in between corps.
The /only/ way I can see this working is if the following conditions are met (with 'you' = the person initiating the transfer): = You have to be logged in at the time. = You will get prompted to confirm. = It will have to be one of CCP's servers. = You will have to set it as trusted. = The information you provide in your http request, and the information that comes from the your current login MUST MATCH, or it should be considered an attempt to hack and therefore ignored.
If it is an attempt to hack, then information may be noted but no action should be taken (yet). It would be too easy to pretend to be someone else to have the flak fall on him if the hacker to be fails in the attempt. But if it's done constantly through the same source IP, over and over and over... and that person happens to be logged in at the time, then retaliation may happen.
Seriously, I like the idea, but it's opening a huge can of worms, and without planning it out /throughly/, promises to blow up real fast, real nastily.
All ugliness aside... I would love to see an idea like this work. I could code in a page to support my corp, with clients able to put in requests for what ores/minerals for my corp to dig up, and to put in a down payment while they're at it.
I just don't see it happening any time soon.
|