Pages: [1] 2 3 4 :: one page |
|
Author |
Thread Statistics | Show CCP posts - 2 post(s) |
Aera Aiana
|
Posted - 2010.03.18 14:09:00 -
[1]
What exactly prevents a phishing site from asking for a character name in addition to just my accountname and password?
This does not seem like a big improvement to my account security... |
Something Random
Gallente The Barrow Boys
|
Posted - 2010.03.18 14:19:00 -
[2]
If your going to type in all your details on a phishing site, theres nothing CCP can take the blame for.
Get yourself some responsibility. |
Amerilia
|
Posted - 2010.03.18 14:20:00 -
[3]
Originally by: Something Random If your going to type in all your details on a phishing site, theres nothing CCP can take the blame for.
Get yourself some responsibility.
I do, and now, how to remove this auto-login disabling annoyance? |
|
Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2010.03.18 14:27:00 -
[4]
So... sometimes you get another page that asks you for a character that's on the account? Or how does this show itself (since I haven't seen it yet)? |
|
Shikome Alluin
Genco Curatores Veritatis Alliance
|
Posted - 2010.03.18 14:35:00 -
[5]
Edited by: Shikome Alluin on 18/03/2010 14:35:44
Originally by: Chribba So... sometimes you get another page that asks you for a character that's on the account? Or how does this show itself (since I haven't seen it yet)?
Yepp, that's it. (asks for character) It says it does not recognize my "location" and thus asks for my character, so Im guessing it randomly blocks your IP to confirm?
I am also not remembered at all, so now I need to log in manually every time (5 seconds, the horror hehe)
Or is this on my end?
|
|
Chribba
Otherworld Enterprises Otherworld Empire
|
Posted - 2010.03.18 14:42:00 -
[6]
Edited by: Chribba on 18/03/2010 14:43:00 Ok that might explain why EVE-Search isn't logging in properly atm.
edit/also the character thing, does it show after the first login or at the same time as the login? |
|
Sandeep
|
Posted - 2010.03.18 14:44:00 -
[7]
Originally by: Chribba So... sometimes you get another page that asks you for a character that's on the account? Or how does this show itself (since I haven't seen it yet)?
Kind of defeats the purpose? What's to stop phishing sites from doing man-in-the-middle attack by fetching any additional security questions from the real EVE website, presenting them to you, and intercepting your answers?
Adding the same identifying feature ("something you know") won't help.
I doubt they are going to mail us RSA keyfobs or smartcards, but couldn't they just ask us to register our browsers/clients like banks in the USA do?
And/or display "last logged in from [IP ADDRESS] [Geo-located city/country name]" every time you log in.
|
Shikome Alluin
Genco Curatores Veritatis Alliance
|
Posted - 2010.03.18 14:51:00 -
[8]
Edited by: Shikome Alluin on 18/03/2010 14:53:22
Originally by: Chribba Edited by: Chribba on 18/03/2010 14:43:00 edit/also the character thing, does it show after the first login or at the same time as the login?
Goes to new page after login.
|
Phantom Slave
Universal Pest Exterminators
|
Posted - 2010.03.18 14:58:00 -
[9]
It's increased account security if your username/password is stolen from another website/game. Lets say you play some random Farmville type game, and somebody hacks your account there. You didn't follow the guidelines and used the same username/password as you use here, which just compromised 2 accounts.
CCP now requiring another question for security gives a 3rd element that the phisher/trojan/attacker in the scenerio above does *not* know about. |
Sandeep
|
Posted - 2010.03.18 15:06:00 -
[10]
Originally by: Phantom Slave CCP now requiring another question for security gives a 3rd element that the phisher/trojan/attacker in the scenerio above does *not* yet know about.
Fixed. Just log in to game or account management to get those missing info. Sure this measure can deter bots, but not for long.
|
|
Tippia
Reikoku IT Alliance
|
Posted - 2010.03.18 15:12:00 -
[11]
Edited by: Tippia on 18/03/2010 15:12:35
Originally by: Sandeep Fixed. Just log in to game or account management to get those missing info. Sure this measure can deter bots, but not for long.
…or the API – that makes entirely bottable, unless they require the same things there. |
Akita T
Caldari Caldari Navy Volunteer Task Force
|
Posted - 2010.03.18 15:28:00 -
[12]
So basically, every time my IP changes because I reset the internet connection, I have to retype my character name just to post on the forums ? Bloody brilliant ! NOT. Where's the opt-out for that ?
|
Sandeep
|
Posted - 2010.03.18 15:37:00 -
[13]
Originally by: Akita T So basically, every time my IP changes because I reset the internet connection, I have to retype my character name just to post on the forums ? Bloody brilliant ! NOT. Where's the opt-out for that ?
I'll take this option over the completely random and unasked for auto-log-out and character switch, assuming they fix the latter two. It's probably the 3rd time I have to re-log, reset my forum settings and default character today.
At least our names are easy to spell.
|
Amerilia
|
Posted - 2010.03.18 15:37:00 -
[14]
Edited by: Amerilia on 18/03/2010 15:38:02 Oh damn it, I live in germany and get a new IP DAILY! ****you ccp...
edit: guess Ill make an alt and try to name it as short as possible.. |
Omg Corn
Gallente Zorp Corp
|
Posted - 2010.03.18 15:48:00 -
[15]
Originally by: Akita T
Where's the opt-out for that ?
Right here :D |
De'Veldrin
Minmatar Special Projects Executive The Obsidian Legion
|
Posted - 2010.03.18 15:57:00 -
[16]
Edited by: De''Veldrin on 18/03/2010 15:57:33 Actually I like it.
Assuming it remembers all of the IP addresses I use regularly, and not just the last one, I'm content.
Originally by: Something Random If your going to type in all your details on a phishing site, theres nothing CCP can take the blame for.
Get yourself some responsibility.
Also, this.
|
Aera Aiana
|
Posted - 2010.03.18 16:13:00 -
[17]
Edited by: Aera Aiana on 18/03/2010 16:15:36
Originally by: Something Random If your going to type in all your details on a phishing site, theres nothing CCP can take the blame for.
Get yourself some responsibility.
This is not about me. I'm pointing out that someone "stupid" enough to enter his/her account information on a third party site will also be stupid enough to do the same with a character name.
Originally by: Sandeep Fixed. Just log in to game or account management to get those missing info. Sure this measure can deter bots, but not for long.
Mh, I was about to think that Phantom Slave had a point. But you mention the game and that might actually be a problem. Unless they do that check during game login too (maybe this'll be in an upcoming patch?). The account management page uses the same login system though, so that is "safe". |
Kuar Z'thain
Fraser's Finest
|
Posted - 2010.03.18 16:15:00 -
[18]
As a person who accesses the Internet, and therefore EVE from multiple ISPs in a single day, I'm really getting a kick out of....
...no this is ******ed. |
Serpents smile
|
Posted - 2010.03.18 16:27:00 -
[19]
Edited by: Serpents smile on 18/03/2010 16:31:16 Dear CCP.
Though I admire and worship your concerns about my account security, your current "fix" to the apparently ongoing account compromises is a horrendous solution to it.
Having to fill the required details in over and over and over again, is a pain in the rear.
Please give me an option to disable this terrible oddball "feature" to your boards.
Sincerely,
3 accounts.
PS: sitting behind one single computer why the heck, does your script tell me I'm logging in from an unknown (or whatever) location? It's the same computer in the same room in the same house where I started my eve online 'adventure. As if the 5 min timer isn't enough, you now made it worse to participate in your forums. |
Wet Ferret
|
Posted - 2010.03.18 16:34:00 -
[20]
This is awesome. Now the 300 logins that I'm forced to do daily, because this forum just refuses to work properly ever, are even more exciting! |
|
Kitimortoa
|
Posted - 2010.03.18 16:35:00 -
[21]
The interwebs...where you can always find someone whining about something insignificant... |
Chainsaw Plankton
IDLE GUNS IDLE EMPIRE
|
Posted - 2010.03.18 16:36:00 -
[22]
oh, it made me log in today, figured my account expired, as that is what happened last time, but it let me in fine, didn't have to do anything extra.
and holy comma splice batman.
or is this (in game)
(or was this to deter us avoiding the 5 min thing ) |
lethaldeathspell
|
Posted - 2010.03.18 16:38:00 -
[23]
Why not have something like WoW for increased security, like the Battle.Net Authenticator.
http://us.blizzard.com/store/details.xml?id=1100000822 |
Chainsaw Plankton
IDLE GUNS IDLE EMPIRE
|
Posted - 2010.03.18 16:57:00 -
[24]
Originally by: Sandeep
I doubt they are going to mail us RSA keyfobs or smartcards, but couldn't they just ask us to register our browsers/clients like banks in the USA do?
they make them optional and sell them would probably make a nice bit of cash that way too. |
Dianna Soreil
Monolithic.
|
Posted - 2010.03.18 16:59:00 -
[25]
Quote: Assuming it remembers all of the IP addresses I use regularly, and not just the last one, I'm content.
yeah, because IP addresses are definitely not dynamic for all consumer-level internet connections
it doesn't bother me from work since we use a static IP, but it's a pain in the ass from home. also wtf can't I use auto-login anymore?? |
Teibor
|
Posted - 2010.03.18 17:09:00 -
[26]
Agreed, biggest problem atm imo is that there is no auto-login feature anymore. I have no complaints with regards increasing security but to remove the auto-log just means I'll tend to use the forum less. |
Admiral Pelleon
White Shadow Imperium Z.E.R.G
|
Posted - 2010.03.18 17:18:00 -
[27]
This is really annoying. Before I could at least accept the stupid forums logging me out every 10 minutes (as ******ed as this is), but now it's a hassle to log back in as well. |
Akita T
Caldari Caldari Navy Volunteer Task Force
|
Posted - 2010.03.18 17:28:00 -
[28]
Edited by: Akita T on 18/03/2010 17:29:07
Originally by: Akita T So basically, every time my IP changes because I reset the internet connection, I have to retype my character name just to post on the forums ?
Scratch that, it's not even just that, the character name thing... that would be just mildly annoying... but no, it's much, MUCH worse... before, the "cookie" or whatnot would re-login me by just clicking "log in", but now thanks to this change I also have to type in my username and password each time (and guess what, I *DO*NOT* have an easy to type password).
LAZY NERD RAGE !!!
I mean, seriously, you don't need this kind of "security" for the FORUMS, you need it for the GAME, and you haven't implemented it into the game !
I really, really want an opt out of this "security feature" back into the old "less secure" way. P.S. I would however welcome increased game login security, but typing in the character name would not nearly be enough for that.
|
Lance Fighter
Amarr
|
Posted - 2010.03.18 17:28:00 -
[29]
wtb:Greasemonkey scripts? >.> |
Akita T
Caldari Caldari Navy Volunteer Task Force
|
Posted - 2010.03.18 17:35:00 -
[30]
Edited by: Akita T on 18/03/2010 17:35:47 AND DID I ALSO MENTION HOW ANNOYING IT IS THAT THE FORUM LOGS YOU OUT AT RANDOM TOO ? YEAH, I DON'T THINK I HAVE. IT'S ABOUT AS ANNOYING AS READING THIS !
|
|
|
|
|
Pages: [1] 2 3 4 :: one page |
First page | Previous page | Next page | Last page |