Robbed Account

General discussion and socializing.

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 11:01 pm

shubla wrote:Add system, when logging on new IP you gotta do some crazy stuff such as verifying it via email.

No, this is completely onerous. Just think about accesses from school/work, or having a dynamic IP at home or whatnot. A procedure like this just assumes account-theft by default, and honestly it's not so common that I want to compromise the default experience just because of it.

Granger wrote:About changing mail: the 'mail the old account with yes/no links and if no answer within 7 days assume yes as default' looks like a good solution unless one knows that someone is on holiday. So it should only work while being logged into the account and impossible to trigger for a lost password case.

Naturally, it is already only possible to change e-mail addresses when logged-in, so I don't see that being an issue. :)

Granger wrote:It also could be a good meachanic to separate the 'master' (=forum) account from the game login

That seems much too formalized for the standard use-case to me. That's not to say that I haven't considered formal mechanics for sharing characters between accounts, but it hasn't been a huge priority. I'll see if I get around to it.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby loftar » Sat Feb 28, 2015 11:04 pm

Mernil wrote:I've stopped playing 3 months ago I'd say. And got back into the game yesterday.

Then I've logged in the forums a few times during this period, 88.171.xxx.xxx is my IP.

It seems to me that you stopped playing on Oct 15. Then, on Oct 29, a Slovenian IP logged into your account. He logged pretty much right into it with only one failed password attempt, so it is clear that he knew the password rather than guessed it. If you're really sure that you never shared your password with anyone (color me doubtful), I can only assume a keylogging client.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby ewlol » Sun Mar 01, 2015 2:21 am

What about requiring a PIN to change core account details, like password and email? Or a security question?
User avatar
ewlol
 
Posts: 775
Joined: Mon Mar 29, 2010 2:40 pm

Re: Robbed Account

Postby loftar » Sun Mar 01, 2015 3:19 am

ewlol wrote:What about requiring a PIN to change core account details,

That's kinda the purpose the password is supposed to serve. ^^
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9045
Joined: Fri Apr 03, 2009 7:05 am

Re: Robbed Account

Postby ewlol » Sun Mar 01, 2015 7:45 am

loftar wrote:
ewlol wrote:What about requiring a PIN to change core account details,

That's kinda the purpose the password is supposed to serve. ^^


If your password is compromised, then what? It's just a secondary line of defense, I guess.

If a PIN check is added (solely) to changing core account information, then people with keylogged clients or those who share their accounts and regret it later will have an extra layer of security, yes?
User avatar
ewlol
 
Posts: 775
Joined: Mon Mar 29, 2010 2:40 pm

Re: Robbed Account

Postby Mernil » Sun Mar 01, 2015 9:36 am

So I had a little chat with the account borrower.
For the story, I've given the man an other account, on may 2014 (with login / password), he asked me for it and I wasn't playing, so I gave him.
Then, later, I've made myself a new one to play again, but used the same password I always use on H&H :oops: .
Later, the guy apparently looked for other accounts of mine on the forum found this one, and tried the password I gave to him earlier, and he was in...

So I've made a mistake and now, obviously, I've changed my password.
Though, taking advantage of something I gave willingly to sneakily access my other accounts is not nice.
But then my main didn't die in the process, and have been well kept. So all in all it's not that wicked neither.

Now this is still my account, and I'm having it back.
And that's still my characters so I'll also keep what's on them (as he kept what was on them when he "took" them for himself).

So yes, case closed I guess.
User avatar
Mernil
 
Posts: 133
Joined: Tue Jul 29, 2014 9:54 pm

Re: Robbed Account

Postby mvgulik » Sun Mar 01, 2015 10:21 am

Mernil wrote:For the story, I've given the man an other account, on may 2014 (with login / password), he asked me for it and I wasn't playing, so I gave him.
I was wondering when that might pup up. (As I had seen you say you gave a account away in a other post)

Which made me also wonder if you might have used the same password for both account. ...
Mernil wrote:Then, later, I've made myself a new one to play again, but used the same password I always use on H&H :oops: .

And so its a other case directly related to unsecured user behavior. :|

People!
Use some password tool to store and generate your passwords!!! ... Good passwords, no mixups/hickups/etc, and still no need to remember more than one password. (And a good secure USB stick if you like to carry your passwords around with you.)
mvgulik
 
Posts: 3770
Joined: Fri May 21, 2010 2:29 am

Re: Robbed Account

Postby borka » Sun Mar 01, 2015 12:46 pm

Mernil wrote:So yes, case closed I guess.


That simple Mernil ?!? Guess you forgot about something:

Mernil wrote:Sorry, I killed the animals it helped me think about what was going on.


Hope you solve that too please ...
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Robbed Account

Postby Mernil » Sun Mar 01, 2015 3:26 pm

borka wrote:Hope you solve that too please ...


Yes I'll give these guys a hug next time I see them.

Image
User avatar
Mernil
 
Posts: 133
Joined: Tue Jul 29, 2014 9:54 pm

Re: Robbed Account

Postby Senviro » Wed Mar 04, 2015 5:42 am

Woe is me. I'm late, as usual.

Send me a PM, Mr. Mernil.
User avatar
Senviro
 
Posts: 53
Joined: Sat Nov 30, 2013 2:25 am

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Claude [Bot] and 3 guests