Robbed Account

General discussion and socializing.

Re: Robbed Account

Postby Rodimus » Sat Feb 28, 2015 8:33 am

Always change password after leaving the game. No one knows when you return back.
W7 - Crestfall
W8 - Silvermoon
W10 - Pueblo Comedia
W11 - Misplaced Caves
W12 - Insulated Gulch
W14 - Vallblómbyrđa
W14 - Local Area Network
W15 - ???
User avatar
Rodimus
 
Posts: 321
Joined: Sun Nov 16, 2014 5:01 am
Location: Japan

Re: Robbed Account

Postby Mernil » Sat Feb 28, 2015 9:07 am

loftar wrote:
Mernil wrote:Loftar, do you log connections to game accounts?

Could you describe the timeline more precisely, please? Like, when did you stop playing, when did you come back, &c&c?


I've stopped playing 3 months ago I'd say. And got back into the game yesterday.

Then I've logged in the forums a few times during this period, 88.171.xxx.xxx is my IP.
User avatar
Mernil
 
Posts: 133
Joined: Tue Jul 29, 2014 9:54 pm

Re: Robbed Account

Postby Granger » Sat Feb 28, 2015 11:27 am

@Loftar: a more detailed list of logins (say: last 10 or 20, together with ip) in the account page could help the user to spot foreign logins.

Because in case you login and find something strange happened ingame you can't go back in time to see when the last login was (to remember stuff like: 'oh yes, i came back from the bar that night and i...') since you'll currently only see the last (current) one.

About changing mail: the 'mail the old account with yes/no links and if no answer within 7 days assume yes as default' looks like a good solution unless one knows that someone is on holiday. So it should only work while being logged into the account and impossible to trigger for a lost password case.

It also could be a good meachanic to separate the 'master' (=forum) account from the game login:
  • have a single account which is used to access the forum and character management
  • create new characters (in terms of 'alt') and a login token (pure random and long enough not to be hackable by brute force) for them on the website, with the option to create a new token (invalidates the current one) for a character
  • in the client the login token gives access to just the one ingame character, for your webstart client you could have a 'play' link on the characters page on the website (which hands the token to the java client, for custom clients the authors will certainly figure out something creative - or maybe you supply an option to set a path to a .jar on-disk which will get it as a parameter)
  • no per account limit on characters online

Upsides:
  • keylogging in custom clients couldn't compromise master account
  • ingame character creation room would have no runestone clutter (or unreachable ones because they extend into the void) since a maximum of one (for direct ancestor, if any) could be there
  • character sharing (which will happen anyway, even should village management be upgraded massively) is more secure (since it's on character, not account, basis)
  • multi-alting (which will most likely happen anyway and is impossible to police) would no longer eat forum nicks, so easier for new players to find one
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9254
Joined: Mon Mar 22, 2010 2:00 pm

Re: Robbed Account

Postby shubla » Sat Feb 28, 2015 5:31 pm

Add system, when logging on new IP you gotta do some crazy stuff such as verifying it via email.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Robbed Account

Postby Mernil » Sat Feb 28, 2015 5:39 pm

shubla wrote:Add system, when logging on new IP you gotta do some crazy stuff such as verifying it via email.


This idea is pretty simple to realize and would be very efficient, I like it.
User avatar
Mernil
 
Posts: 133
Joined: Tue Jul 29, 2014 9:54 pm

Re: Robbed Account

Postby RustyBuckitt » Sat Feb 28, 2015 5:54 pm

Just Figured I'd add some stuff.

For secure Passwords, check this video out:
https://www.youtube.com/watch?v=hYyWgPXfx9U

And as for security, why not have a security question?

Example:

Q: Favorite Book Author's First name.

A: Christopher


It has to be something that you'd be able to keep from being easy to breech, or something that you'd easily be able to realize. Like your friend asking you a ton of stupid questions out of "Curiosity," and you'd easily be able to catch on.

A list of some:
Q: Favorite Book Author's First name.
Q: Favorite Movie Director's Last name.
Q: Favorite Game Dev's Name (Don't pick Jorbtar).
Q: Favorite Cartoon Animator's First Name.
"Me and Stone gonna break your bones." In loving memorry of Stick

Image
User avatar
RustyBuckitt
 
Posts: 463
Joined: Wed Feb 19, 2014 4:09 am
Location: The "Bud" with "a friend"

Re: Robbed Account

Postby adyroty » Sat Feb 28, 2015 6:55 pm

not 100% sure if this is the one, but a friend told me that someone gave the account to care for him, and now accused of stealing account.He disconnected quickly and we have not discussed much, but I think that is the case below
loftar wrote:Literally all account issues I deal with end up in one of these cases:
[list][*]Shared accounts (this is 90%+ of issues).
User avatar
adyroty
 
Posts: 85
Joined: Fri May 07, 2010 6:39 pm

Re: Robbed Account

Postby borka » Sat Feb 28, 2015 7:33 pm

shubla wrote:Add system, when logging on new IP you gotta do some crazy stuff such as verifying it via email.


Ever heard of IP might change when Providers give you a new after 24hours forced net separation or when your DSL or broadband fails and 3G failover gets used by router or people rely on proxies ?!? So IP check wouldn't work ...
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Robbed Account

Postby shubla » Sat Feb 28, 2015 7:57 pm

borka wrote:
shubla wrote:Add system, when logging on new IP you gotta do some crazy stuff such as verifying it via email.


Ever heard of IP might change when Providers give you a new after 24hours forced net separation or when your DSL or broadband fails and 3G failover gets used by router or people rely on proxies ?!? So IP check wouldn't work ...

Well. Who cares? Then you can verify it everytime.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Robbed Account

Postby borka » Sat Feb 28, 2015 8:31 pm

yeah i guessed that you don't care about others - it's prolly well known by forumers ...
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Barkrowler [Bot], Claude [Bot], Yandex [Bot] and 1 guest