Robbed Account

General discussion and socializing.

Re: Robbed Account

Postby borka » Sat Feb 28, 2015 1:52 am

loftar wrote:I'm not sure if it's wise to divulge the details of how it works, though.


Not wise - that's not the kind of "transparency" i ask for
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 2:02 am

What kind are you asking for, then? :)
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby borka » Sat Feb 28, 2015 2:29 am

Number of attempts that have been logged, tracking of Brute Forcers ... everything that lowers paranoia and rumours :)
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 2:58 am

Well, I dunno, it's not like I keep book of brute-forcing statistics. :)

I mostly just notice them passing by in the logs every now and then, perhaps once or twice per month. Most of them seem to go by the forum's Hearthlings-list in order of number of posts. Many of them continue their attempts for days with no clue that it's completely in vain. :)

Unfortunately, all those I've looked into have been wise enough to use a proxy or some otherwise unconnected IP address, however, so I still haven't been able to connect it to anyone. I'll be very happy to bring the nukehammer to them as soon as they mess up.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby TeckXKnight » Sat Feb 28, 2015 3:35 am

Would it be possible to set something up to warn us if someone is attempting to brute force us so we can act accordingly? Just a small automatic alert to an e-mail or maybe even just a warning the next time we log into the forums.
User avatar
TeckXKnight
 
Posts: 8274
Joined: Tue Jul 13, 2010 2:31 am
Location: How Do I?

Re: Robbed Account

Postby Arcanist » Sat Feb 28, 2015 3:43 am

loftar wrote:
Xcom wrote:Make it so you have to wait 7 days before you can change email without having direct email verification.

What does "direct email verification" mean? A verification e-mail is sent to the new e-mail address, and a "receipt" e-mail is sent to the old.


An email is sent to the old address saying that someone is trying to change the e-mail. There is one link to say 'Wait! that's not me, i'm being hacked!!!' and another to give the all clear.

If neither is pressed within 7 days, or the all clear is given, the email is changed, and a recipt is sent to the new email.
User avatar
Arcanist
 
Posts: 2664
Joined: Mon Mar 19, 2012 2:01 pm

Re: Robbed Account

Postby Kitamie » Sat Feb 28, 2015 4:00 am

Arcanist wrote:
loftar wrote:
Xcom wrote:Make it so you have to wait 7 days before you can change email without having direct email verification.

What does "direct email verification" mean? A verification e-mail is sent to the new e-mail address, and a "receipt" e-mail is sent to the old.


An email is sent to the old address saying that someone is trying to change the e-mail. There is one link to say 'Wait! that's not me, i'm being hacked!!!' and another to give the all clear.

If neither is pressed within 7 days, or the all clear is given, the email is changed, and a recipt is sent to the new email.


One of our work sources uses this method as a precaution. It seems to work quiet well imo.
Kitamie
 
Posts: 524
Joined: Sat Jul 02, 2011 3:06 am

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 4:52 am

Arcanist wrote:An email is sent to the old address saying that someone is trying to change the e-mail. There is one link to say 'Wait! that's not me, i'm being hacked!!!' and another to give the all clear.

If neither is pressed within 7 days, or the all clear is given, the email is changed, and a recipt is sent to the new email.

Hmm, this might not be a completely terribad thing to do. I'll consider it.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby Mernil » Sat Feb 28, 2015 7:46 am

I didn't give my account information to anyone, nor did I share my account to anyone.
The client I'm using is H&H_Union.
I'm fairly confident my password wouldn't be that easy to bruteforce.

Loftar, do you log connections to game accounts?
User avatar
Mernil
 
Posts: 133
Joined: Tue Jul 29, 2014 9:54 pm

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 7:50 am

Mernil wrote:Loftar, do you log connections to game accounts?

Could you describe the timeline more precisely, please? Like, when did you stop playing, when did you come back, &c&c?
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Amazon [Bot], Claude [Bot] and 1 guest