My account has been hacked from this client

General discussion and socializing.

Re: My account has been hacked from this client

Postby jordancoles » Sun Jan 30, 2022 7:53 am

Sounds like you got raided and they bashed your HFs or took over your personal claim so you got wilderness spawned

I doubt you were hacked in this case
Duhhrail wrote:No matter how fast you think you can beat your meat, Jordancoles lies in the shadows and waits to attack his defenseless prey. (tl;dr) Don't afk and jack off. :lol:

Check out my pro-tips thread
Image Image Image
User avatar
jordancoles
 
Posts: 14078
Joined: Sun May 29, 2011 6:50 pm
Location: British Columbia, Canada

Re: My account has been hacked from this client

Postby Fostik » Sun Jan 30, 2022 10:01 pm

CLAVICEMBALO3 wrote:It's really really bad experience, it's really a shit. Why you dont put a check system from other devices?
for example when you enter in Amazon account, they always want a check if you enter from other device

Have you checked logins here?
https://www.havenandhearth.com/portal/profile-sec
Known as zunzon. Contact discord: zunzon.
User avatar
Fostik
 
Posts: 2251
Joined: Tue Jul 05, 2011 4:08 pm
Location: EU

Re: My account has been hacked from this client

Postby loftar » Mon Jan 31, 2022 12:30 am

I'm not sure about the implied timeframe or if you're referring to some other account than the one you're posting from, but over the past couple of days, you have only been logging in from one pool of dynamic IP addresses, which is also the same as that which you're posting from, so it doesn't look like you've been hacked.

Fostik wrote:Have you checked logins here?
https://www.havenandhearth.com/portal/profile-sec

That doesn't actually list logins, only active tokens. Though I have considered adding a log of last logins (and other security-related events) to it, since these questions pop up every now and then. I'm just not sure how wise I think it is to list potentially sensitive information in a way that could potentially be used by someone who actually did hack your account. Thoughts? Opinions?
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9056
Joined: Fri Apr 03, 2009 7:05 am

Re: My account has been hacked from this client

Postby shubla » Mon Jan 31, 2022 12:52 am

loftar wrote:Thoughts? Opinions?

2FA via email or via time based token/code whatever those are called. At least as an opt in thing.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13041
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: My account has been hacked from this client

Postby loftar » Mon Jan 31, 2022 3:51 am

shubla wrote:2FA via email or via time based token/code whatever those are called. At least as an opt in thing.

I have considered that too, but that seems like a completely separate question from the one I posed, no?
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9056
Joined: Fri Apr 03, 2009 7:05 am

Re: My account has been hacked from this client

Postby SnuggleSnail » Mon Jan 31, 2022 4:20 am

Not sure exactly what you want to show, but keep in mind there's a crapload of account sharing, often even with people you're not really close friends with. I would be kinda annoyed if people got anything relevant whenever I logged into their account.
"We specialize in permadeath and forum drama." -man who removed death and deletes every drama thread
http://www.seatribe.se/
User avatar
SnuggleSnail
 
Posts: 3028
Joined: Sat Oct 12, 2013 4:04 pm

Re: My account has been hacked from this client

Postby MagicManICT » Mon Jan 31, 2022 5:07 am

loftar wrote:I have considered adding a log of last logins (and other security-related events) to it, since these questions pop up every now and then. I'm just not sure how wise I think it is to list potentially sensitive information in a way that could potentially be used by someone who actually did hack your account. Thoughts? Opinions?


SnuggleSnail wrote:Not sure exactly what you want to show, but keep in mind there's a crapload of account sharing, often even with people you're not really close friends with. I would be kinda annoyed if people got anything relevant whenever I logged into their account.


I'm of the opinion the more security information available to a user concerning their account, the better. To address Snail's concern, it could be an opt in/opt out thing where using some form of 2FA could be used to toggle it on and off so someone that is hosting/using a shared account doesn't get such information out there, and someone on the account (without access to the linked email) can't just turn it on to skim everyone's connection information. Optionally, a very basic "Logged in from <your city, state, province, country) on <date/time>" might be generic enough without giving away too much.

Part of me wants to say "well, that's the issue with sharing accounts." Some games explicitly disallow it going so far as to ban all accounts as it becomes more than a bit difficult when someone eventually complains about it getting shared with the wrong individuals or the account is actually hacked. Other games provide means of sharing accounts through the login process so that the account owner remains separate from the authorized users on the account.
Opinions expressed in this statement are the authors alone and in no way reflect on the game development values of the actual developers.
User avatar
MagicManICT
 
Posts: 18435
Joined: Tue Aug 17, 2010 1:47 am

Re: My account has been hacked from this client

Postby axus » Mon Jan 31, 2022 6:21 am

SnuggleSnail wrote:Not sure exactly what you want to show, but keep in mind there's a crapload of account sharing, often even with people you're not really close friends with. I would be kinda annoyed if people got anything relevant whenever I logged into their account.

SO you're saying this is a good solution to the account sharing "problem"
axus
 
Posts: 118
Joined: Thu Nov 18, 2021 4:22 pm

Re: My account has been hacked from this client

Postby Fostik » Mon Jan 31, 2022 9:03 am

loftar wrote:That doesn't actually list logins, only active tokens. Though I have considered adding a log of last logins (and other security-related events) to it, since these questions pop up every now and then. I'm just not sure how wise I think it is to list potentially sensitive information in a way that could potentially be used by someone who actually did hack your account. Thoughts? Opinions?


Yeah, as been said above, big villages meta is account sharing for special characters who is minmaxing certain stats for development in particular directions, e.g. max surv or max masonry characters shared between others. People may not want to have this information open by default.
Probably only displaying device name and location would be not that private?

Otherwise you can consider to communicate new unique login information (change of country or device) over account email, probably this is what Shubla meant about 2FA - to use any second factor that will not be available by just stealing an account.
Known as zunzon. Contact discord: zunzon.
User avatar
Fostik
 
Posts: 2251
Joined: Tue Jul 05, 2011 4:08 pm
Location: EU

Re: My account has been hacked from this client

Postby DreadKatak » Mon Jan 31, 2022 8:28 pm

Looking forward to 2FA, for sure. I would definitely opt-in. This is probably the only account-required game that I play that doesn't have those security features yet.
User avatar
DreadKatak
 
Posts: 76
Joined: Mon Nov 26, 2018 3:10 am

PreviousNext

Return to The Inn of Brodgar

Who is online

Users browsing this forum: Claude [Bot] and 15 guests