Administrivia: Some new account security options

Announcements about major changes in Haven & Hearth.

Re: Administrivia: Some new account security options

Postby maze » Fri Mar 26, 2021 4:00 am

One of the reasons people account share is to have access to a universal town alt.

It would be nice if we could share an alt from the account page with other people - that would get rid of the problem entirely.

a few options would be nice
give someone permissions by adding their account name to the alt.
give a group of players access to your alt (set a color or many- anything other then white)
give a town access to your alt (set a color or many- anything other then white)
WARNING! MY ENGISH SUCKS.
game ideas
User avatar
maze
 
Posts: 2519
Joined: Sat Mar 27, 2010 3:15 am
Location: Canada

Re: Administrivia: Some new account security options

Postby MagicManICT » Fri Mar 26, 2021 7:09 am

@loftar: that is exactly what I was looking for. Sorry for the way the question was worded. It read differently in my mind when I posted it.
Opinions expressed in this statement are the authors alone and in no way reflect on the game development values of the actual developers.
User avatar
MagicManICT
 
Posts: 18437
Joined: Tue Aug 17, 2010 1:47 am

Re: Administrivia: Some new account security options

Postby APXEOLOG » Fri Mar 26, 2021 10:03 am

@loftar nice feature, but can we maybe do a step forward and introduce 2 changes:
1. Add a button to generate a new token directly from the web page (without downloading autohaven)
2. Add a button to show the token itself so that it can be copied

With this approach, we will be able to change the custom client's login saving to rely on tokens instead of logins and passwords.
The use-case scenario will be:
1. User A wants to share access with user B
2. User A goes to his security settings and generates a new token by pressing "Create new security token" (imagine that he also adds a comment for it: "for my best friend B")
3. User A hits the "Show token" button, copies it, and send it to his friend B
4. User B stores this token in his custom client and uses it to access the game
5. When user A wants to stop sharing he goes to his security settings and revokes specific token (this is where the comment can be helpful)
W10 Meme Plot | W9 Mantis Garden | W8 Core | W7 Ofir | W6 the City of Dis | W5 Vitterstad | W4 A.D. | W3 Mirniy
jorb wrote:All your characters will be deleted, and I will level every village any one of them were ever members of.
User avatar
APXEOLOG
 
Posts: 1267
Joined: Fri Apr 23, 2010 7:58 am
Location: Somewhere on Earth

Re: Administrivia: Some new account security options

Postby KwonChiMin » Fri Mar 26, 2021 12:00 pm

maze wrote:One of the reasons people account share is to have access to a universal town alt.

If i understand new system correctly - u now can just share tokened jar file of said alt for everyone in your village. And if someone should be excluded - just reissue new token.
User avatar
KwonChiMin
 
Posts: 369
Joined: Fri Mar 05, 2010 7:11 pm

Re: Administrivia: Some new account security options

Postby VDZ » Fri Mar 26, 2021 4:34 pm

APXEOLOG wrote:@loftar nice feature, but can we maybe do a step forward and introduce 2 changes:
1. Add a button to generate a new token directly from the web page (without downloading autohaven)
2. Add a button to show the token itself so that it can be copied

With this approach, we will be able to change the custom client's login saving to rely on tokens instead of logins and passwords.
The use-case scenario will be:
1. User A wants to share access with user B
2. User A goes to his security settings and generates a new token by pressing "Create new security token" (imagine that he also adds a comment for it: "for my best friend B")
3. User A hits the "Show token" button, copies it, and send it to his friend B
4. User B stores this token in his custom client and uses it to access the game
5. When user A wants to stop sharing he goes to his security settings and revokes specific token (this is where the comment can be helpful)

loftar wrote:On a separate note, account sharing is never supported, and is by far the number one reason for security breaches**
User avatar
VDZ
 
Posts: 2660
Joined: Sun Jul 17, 2011 2:27 am

Re: Administrivia: Some new account security options

Postby shubla » Fri Mar 26, 2021 4:39 pm

VDZ wrote:
loftar wrote:On a separate note, account sharing is never supported, and is by far the number one reason for security breaches**

But people are still going to share accounts.
In Finland, syringes are given to IV drug users, even though possessing and using IV drugs is illegal. It is done to decrease the potential harm from usage, because some people are still going to do it.
So why not do the similar in HnH?
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Administrivia: Some new account security options

Postby Ysh » Fri Mar 26, 2021 6:37 pm

shubla wrote:
VDZ wrote:
loftar wrote:On a separate note, account sharing is never supported, and is by far the number one reason for security breaches**

But people are still going to share accounts.
In Finland, syringes are given to IV drug users, even though possessing and using IV drugs is illegal. It is done to decrease the potential harm from usage, because some people are still going to do it.
So why not do the similar in HnH?

Some men will look at both cases and consider it to be enabling bad behavior.
Kaios wrote:Spice Girls are integral to understanding Ysh's thought process when communicating, duly noted.

I have become victory of very nice Jordan Coles Contest! Enjoy my winning submit here if it pleasures you.
User avatar
Ysh
 
Posts: 5953
Joined: Sun Jan 31, 2010 4:43 am
Location: Chatting some friends on forum

Re: Administrivia: Some new account security options

Postby loftar » Fri Mar 26, 2021 7:06 pm

To be clear, I don't think all cases of character-sharing are bad. Just which ones are and aren't can certainly be debated, but I don't think it's an intrinsic evil. By far the main problem is sharing of accounts, moreso than characters per se. That's not to say that sharing of characters is entirely unproblematic, both in terms of game mechanics and in terms of security, but we have in fact lightly considered implementing some form of more formal sharing of characters between accounts at times. It's more complex than it might seem at first glance, though, the aesthetics of it are less than obvious, and we do have higher-priority items to work on, but it's not entirely off the table.

I'm not sure I want to be seen as encouraging account-sharing by implementing the suggested changes, but it could at least be a step forward, and I could consider implementing it if only to better support custom clients. I'll have to think about it, and also have no lack of things to work on for the reset, but I'll keep it in mind.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 8926
Joined: Fri Apr 03, 2009 7:05 am

Re: Administrivia: Some new account security options

Postby Sevenless » Fri Mar 26, 2021 10:30 pm

I agree that account sharing is intrisically risky, but at the same time the nature of haven makes character sharing incredibly useful. Supported or not, encouraged or not, it's always going to be happening.

I wouldn't worry about it too much. The idea of character sharing as an ingame supported mechanic tickled my fancy though.
Lucky: haven is so quirky
Lucky: can be so ugly, can be so heartwarming
Sevenless: it is life

The Art of Herding
W15 Casting Rod Cheatsheet
Explanation of the logic behind the cooking system
User avatar
Sevenless
 
Posts: 7292
Joined: Fri Mar 04, 2011 3:55 am
Location: Canada

Re: Administrivia: Some new account security options

Postby iamahh » Sat Mar 27, 2021 12:11 am

wait nvm
iamahh
 
Posts: 1810
Joined: Sat Dec 12, 2015 8:23 pm

PreviousNext

Return to Announcements

Who is online

Users browsing this forum: Python-Requests [Bot], Yandex [Bot] and 25 guests