| Pages: 1 [2] 3 :: one page |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |
|

Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2008.06.04 08:21:00 -
[31]
So how long/supported stuff does threads need? And maybe there is a time-limit on how long it can run before a decision has to be taken? *bump*
Secure 3rd party service ■ Do you Veldspar? |
|

Chainsaw Plankton
IDLE GUNS IDLE EMPIRE
|
Posted - 2008.06.04 08:26:00 -
[32]
Originally by: Chribba So how long/supported stuff does threads need? And maybe there is a time-limit on how long it can run before a decision has to be taken? *bump*
always 1 more vote!
*doh it needs 1 more vote now*
|

Delezar
Hellfire-Empire
|
Posted - 2008.06.04 08:40:00 -
[33]
A very good idea, which I fully support.
|

Poreuomai
Mirkur Draug'Tyr
|
Posted - 2008.06.04 12:50:00 -
[34]
Edited by: Poreuomai on 04/06/2008 12:50:50
I completely support this, especially:
Quote:
When locked, a user can reset the lock by for example having a verification mail sent to his/her email with a reset link (just like any password reset feature)

|

Allaria Kriss
Elipse Inc.
|
Posted - 2008.06.04 13:08:00 -
[35]
Posting in support of improved account security.
|

Jacque Custeau
Knights of the Minmatar Republic
|
Posted - 2008.06.04 13:52:00 -
[36]
That strength-o-meter is very annoying and never works correctly.
Chribba's ideas on this issue are good. -------------------
|

easei
AnTi. Atrocitas
|
Posted - 2008.06.04 14:10:00 -
[37]
I'd support account security like this, but really the problem stems from windows as an operating system and people's general lack of understanding of internet security. All it takes is a visit to one website that drops a key-logger through any number of Explorer's security holes (even if you use firefox) and your machine gets owned.
The statistics are pretty sick, something on the order of 90% of windows PC's are "owned."
|

Rouque Vanderbuilt
Nuts and Bolts
|
Posted - 2008.06.04 21:08:00 -
[38]
/signed
|

Czanthria
Ad Astra Vexillum
|
Posted - 2008.06.04 23:05:00 -
[39]
-- Knowledge is Power! |

Lord Fitz
Deep Core Mining Inc.
|
Posted - 2008.06.04 23:10:00 -
[40]
I've fortunately never had my account hacked, but heard of plenty of people that have, something that would make most people more comfortable anyway.
|

MrZYD
|
Posted - 2008.06.05 23:35:00 -
[41]
I endorse this product and/or service to be implemented.
|

Elmicker
Wreckless Abandon
|
Posted - 2008.06.05 23:53:00 -
[42]
Originally by: Vaal Erit Chribbas first idea is terrible.
No it isn't. I've been in (and know many others who have been) in a position where an account is shared. This is against the EULA but commonplace. An IP log already exists for your API info, so why not for login attempts? If nothing else you could spot people attempting to "brute force" your password.
Quote: Oh and Chribbas second idea would be rarely used by players if at all
Eve has a very high proportion of very tech-savvy users. Alot of people would use this feature. I'd certainly use it, for example, as i know of several people who know my password, or who could easily obtain it, however, i trust them enough not to bother changing it, because that would just annoy me.
|

Ranamar
|
Posted - 2008.06.06 01:18:00 -
[43]
Originally by: Vaal Erit BINGO. Chribbas first idea is terrible. As someone who has cr@cked passwords I can tell you that your idea will do nothing Chribba. I am just as likely to cr@ck your pw if you change it every month or not. Most of the cr@cking is done via brute force+wordlist because the user picked a weak password.
Perhaps I misunderstood his idea, but I thought it involved logging who was trying to access your *account*. So, if you're *****ing it by brute force, you'll see a whole pile of failed attempts, and it will be (hopefully) self-evident that someone has been trying to do something you don't want them to do with your account.
Anyway, I'll support discussion of security options because I know enough to know I am insufficiently paranoid, but there are people who are properly paranoid, and I'm sure that group is even greater among those who frequent the forums than EVE in general. (... and the nature of the game means that we likely self-select with more tech-savvy people than in general.)
|

Savesti Kyrsst
White-Noise
|
Posted - 2008.06.06 19:13:00 -
[44]
_
|

Letouk Mernel
|
Posted - 2008.06.06 20:01:00 -
[45]
I believe that a list of the last few login attempts is somewhat of a standard practice now, and support that.
Other standard practices are, of course, the secret question / secret answer stuff, preventing changes unless confirmed by email, and password complexity rules.
I am not sure that locking the account to an IP address/range will be considered justified by CCP; they can already see and log the computer name and address from which you're logging in, and a simple look at the backlog will reveal a hacked account or not.
So it's a matter of coding this extra IP address locking stuff in order to prevent a call to Tech Support to have your stuff restored, except that they'll have to provide Tech Support for people who lock the wrong IP address or have exotic setups at home / elsewhere. Roaming laptops from hotels, for example.
I will, however, support CCP having a look and brainstorm about account security. One BIG vulnerability is the fact that character sales force us to reveal account names, which is half the information needed for brute force hacks. Maybe they can fix that somehow.
|
|

Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2008.06.12 08:34:00 -
[46]
moar support!!  |
|

Xplained
Welsh Wizards
|
Posted - 2008.06.12 09:05:00 -
[47]
I'll give a thumbs up for this idea, i like both points, but point 2 wouldnt work for me, at home i have a dynamic IP and work is static and i play from both locations 
Nice idea 
Byddin Rhyddid Cymru |

Halca
Mutually Assured Distraction
|
Posted - 2008.06.12 10:52:00 -
[48]
I'd be very interested in seeing some metrics on hacked accounts before I could subscribe to a particular strengthening of account security especially if it makes it more difficult for me to play the game, from multiple machines without static IP addresses, which I often do.
I am assuming that a very large majority of "hacked" accounts are simply people sharing their login information with other people and no amount of security measures will reign in stupid people. Even malicious software that reads your login information is easy to prevent if you are careful. |

Araviel
Epic.
|
Posted - 2008.06.12 11:02:00 -
[49]
supported, but i favor Serenity's idea, that toghter whit IP logs that you could access thru your account page.
----------------
|

Judas Jones
Black Company
|
Posted - 2008.06.12 23:25:00 -
[50]
Never can have enough security |

Jade Constantine
|
Posted - 2008.06.13 03:19:00 -
[51]
I'm going to support this and bring it up on the agenda this Sunday. Its a good idea and is worth putting in front of CCP. I'm going to include Serenity's option of the password strength bar in the proposal as well though as an alternative.
|

Kitoba
Legion of Dynamic Discord
|
Posted - 2008.06.13 03:29:00 -
[52]
/signed, all three proposals. I just hope the call center staff of my ISP knows what range my IPs are in.
Also, consider things like passook and generating passwords for users. Level 3 should be sufficient to stop dictionary attacks.
"Your password is easily guessable. Please use a different, like, for example, "theMsLy9". Click <here> to generate another one."
|

Siona Windweaver
|
Posted - 2008.06.14 13:31:00 -
[53]
No need to say anything.
|

Kalinda Veldrin
|
Posted - 2008.06.15 00:52:00 -
[54]
I fully support this issue.
I suggest that you add both the password security bar and the failed logins message by default. The audit log is also a great idea. I also agree with having any sort of IP lockout as an advanced and "agree to" service.
|

Maelia Gurast
|
Posted - 2008.06.15 01:28:00 -
[55]
I like this idea. Thumbs up from me.
|

saxsus
Opinicus Operations
|
Posted - 2008.06.15 12:22:00 -
[56]
very good idea
|

Jade Constantine
|
Posted - 2008.06.16 00:50:00 -
[57]
Success, got it voted through the CSM and for the agenda in Iceland.
CSM Manifesto 2008 | Destroy Outposts! |

Siebenthal
|
Posted - 2008.07.15 13:50:00 -
[58]
|

Apple Boy
Wyverns of Dionysus Interstellar Alcohol Conglomerate
|
Posted - 2008.07.27 18:21:00 -
[59]
I would love to be able to see a log of timestamps, IPs, etc.
|

Jeirth
Republic Military School
|
Posted - 2008.07.27 18:35:00 -
[60]
|
| |
|
| Pages: 1 [2] 3 :: one page |
| First page | Previous page | Next page | Last page |