[Announcement About Account Security] Haven/Salem

General discussion and socializing.

Re: [Announcement About Account Security] Haven/Salem

Postby btaylor » Sat Jul 27, 2013 8:49 pm

Had emails from H&H a few times in the past about my account password asking to be reset. Then a couple of days ago I can't access my email account because of strange activity. I got everything under control, but look at this:

Image

Do you even lift, Latvia?
The unfed mind devours itself. - Gore Vidal
User avatar
btaylor
 
Posts: 1691
Joined: Thu Oct 22, 2009 1:37 am

Re: [Announcement About Account Security] Haven/Salem

Postby Sevenless » Fri Aug 02, 2013 4:43 am

Windforce wrote:Wonder how long they would take to bruteforce a password called "Password"


bruteforces usually have a set of passwords that are common set at the start of the bruteforce attempt. In other words, it would be taken down almost immediately.
Lucky: haven is so quirky
Lucky: can be so ugly, can be so heartwarming
Sevenless: it is life

The Art of Herding
W15 Casting Rod Cheatsheet
Explanation of the logic behind the cooking system
User avatar
Sevenless
 
Posts: 7292
Joined: Fri Mar 04, 2011 3:55 am
Location: Canada

Re: [Announcement About Account Security] Haven/Salem

Postby TeckXKnight » Fri Aug 02, 2013 9:43 am

Brute forcing passwords is all about probability. To save time you hit the targets with the highest chance of being correct -- and so we have extensive lists of the most commonly used passwords.
User avatar
TeckXKnight
 
Posts: 8274
Joined: Tue Jul 13, 2010 2:31 am
Location: How Do I?

Re: [Announcement About Account Security] Haven/Salem

Postby dackT-E » Fri Aug 30, 2013 5:40 pm

Tonkyhonk wrote:Here is some news you all may be interested in. let me copy-paste the chat i had with loftar earlier instead of me trying to summarize it.

viewtopic.php?f=7&t=31016&start=30#p431095


could someone get links to these names? i know its alot to ask for but still itd make my day easier.
Last edited by borka on Fri Aug 30, 2013 5:58 pm, edited 3 times in total.
Reason: edited the biggest part of quote out
A day without sunshine is like, you know, night.
-Steve Martin
User avatar
dackT-E
 
Posts: 224
Joined: Wed Sep 21, 2011 7:39 pm

Re: [Announcement About Account Security] Haven/Salem

Postby borka » Fri Aug 30, 2013 5:49 pm

what for do you want them?
Avatar by SacreDoom
Java 8 - manually downloads - good to check for actual versions url here:
viewtopic.php?f=42&t=40331
Remember what the dormouse said: Feed your head Feed your head
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: [Announcement About Account Security] Haven/Salem

Postby Dzedajus » Fri Aug 30, 2013 10:40 pm

If you want to try and see why exactly those names were more actively attacked then I think we all already figured it out, at that time they all posted on ICA threads more or less actively, unless you noticed something else.
User avatar
Dzedajus
 
Posts: 1099
Joined: Sat Feb 05, 2011 9:08 pm

Re: [Announcement About Account Security] Haven/Salem

Postby Mopstar » Fri Nov 29, 2013 11:57 am

Feels good mang,although I would wonder why my account was tried.Hardly worth the effort :lol:

Last time I used the irc was when delamore still played activly I think
Wolfang wrote:
+1 I don't know how he did it, but Mopstar did steal his own stuff. You have to be a pretty hardcore thief to be able to steal your own things!
User avatar
Mopstar
 
Posts: 441
Joined: Wed Dec 02, 2009 6:03 pm

Re: [Announcement About Account Security] Haven/Salem

Postby Chemox » Mon Dec 23, 2013 2:28 am

Security questions/ sms confirmation/ ... All those things are possibilities that help against hackers.
Against bruteforce attacks the easiest way is to lock an account after 5-6 attempts and send an reactivation mail to the owner. Telling them somebody is trying to acces their account and that they may have to make their password better.
In order to counter botnets I suggest using IP checking (enable disable by account owners if they have troubles) => Lock an account whenever somebody tries to acces it from outside of the country where the original user logged in.

These are just some ideas
See what you can do with it
Chemox
 
Posts: 17
Joined: Fri Dec 30, 2011 2:27 am

Re: [Announcement About Account Security] Haven/Salem

Postby TeckXKnight » Tue Dec 24, 2013 12:55 am

A form of security that I've absolutely fallen in love with is phone verification. If a system/device attempts to login to your account that hasn't before then your phone gets a text asking if that's really you or not. Short of stealing someone's computer or phone there's not much you can do to break past this.
User avatar
TeckXKnight
 
Posts: 8274
Joined: Tue Jul 13, 2010 2:31 am
Location: How Do I?

Re: [Announcement About Account Security] Haven/Salem

Postby borka » Tue Dec 24, 2013 6:47 pm

The only flaw is the connection between a forum and a Telephone number (which in most cases is connected to Real Name + adressdata) then... :?

Teck also my Phone would be textspamming me (changing / dynamic IP) - look at qmark... :lol: another problem would be those that need to post/ play by proxy ...
Avatar by SacreDoom
Java 8 - manually downloads - good to check for actual versions url here:
viewtopic.php?f=42&t=40331
Remember what the dormouse said: Feed your head Feed your head
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: No registered users and 2 guests