The 0.10.1d account changes

"
Udja wrote:
I haven't seen it yet, but I'm wondering if you're going to do what Rift does - coin lock. If you don't sign into your account for an extended amount of time, or from another location I'm guessing, the account is "locked" when you log in and can only be "unlocked" after supplying a code sent to your email. This is a good solution. But you should all know that NOTHING is 100% secure but a lot of proactive care needs to be done on the client's end (players) as well; don't share passwords, use strong passwords and nothing that can be broken with dictionary attacks. I can even give you all an algorithm that I use that makes it extrememely hard for crackers to break. GGG can only do so much from their end to keep your accounts secure but the players must also take responsibility as well :)


I made a guide in my work about strong password, Im using transposition, replacement, signs, Caps and 9+ lenght.

Just an example:

Password: pathofexile

Password with replacement: p4th0f3x1l3

Password with Replacement and Transposition: 3x1l3f0p4th

Password with Replacement, Transposition and Signs: 3x1l3*f0!p4th

Password with Replacement, Transposition, Signs and Caps: 3X1l3*F0!p4Th

(this was just an example I'm not using this passwords in any of my accounts)

And you just need to remember the first word and what methods you use, and everytime use words out of everything known about the game or yourself.

Regards!
Indestructible, determination that is incorruptible
From the other side, a terror to behold
Annihilation will be unavoidable, every broken enemy will know
That their opponent had to be invincible, take a last look around while you're alive
I'm an indestructible master of war
"
Some games have a policy of restoring the items on an account if the user lost their password and someone else took the items. We can't do this because either of the two policies would be devastating to Path of Exile:
a) If we restore the items in a way that duplicates them then users are able to arbitrarily copy their items by presenting a plausible looking case to our support department. This is actively abused in other games and their playerbases know that they can duplicate items at will through customer support.
b) If we restore the items, removing them from the people who got them, then users are able to tradehack each other by performing trades and then requesting that support restore their items. This would undermine the entire trust in the trade community because items could vanish at any time after you receive them in trade.


a little confused by this so this only applies to persons whom aren't high ranking ladder players or streamers?
"
Udja wrote:
"
gerdalti:

Are there any plans for an Authenticator? 2 stage authentication removes the threat of hacked passwords (for users smart enough to use it). Quite a few MMO's have taken to using them, and they seem to work very well. Almost everyone these days has an Android or iOS phone, seems like that would be an easy way to go about it.


Correction :) 2 stage authentication GREATLY REDUCES the threat of hacked passwords but doesn't remove it.


True, I guess greatly reduces is a much more true statement. They don't do much else right these days, but Blizzard has their 2 stage authentication done properly.
New Location? Requires a code
Every week or so? Requires a code
Day to day? If you've already put your code in, you're cool.
"We're a small company and only have 8 customer support staff at the moment."

Keep it small! We'll give you a full support! -- Even though I still can't support you guys with microtransaction items at this moment! @_@

But just keep it small and active! Big doesn't mean good, like Blizzard! All of us will support you, don't worry! Keep up the great spirit!

P/S: Some people aren't really want the conveniences of saving password from different location. They may disguise themselves as a normal user asking for such conveniences but actually hope for the conveniences to hack! Retyping the password from different location is not a big deal to us who love this game and want to play it safe!
Shadow Character Build:
Essence Drain + Contagion + Curse Vulnerable on Damage Taken + Decoy Totem
Armor + Energy Shield
Wand + Spirit Shield
What about MAC address registration instead? That's unique to the computer.

Are there any/many people who play on more than one computer system?
Kilts for Templars <tm> - Our mission is to replace the ancient Greek toga worn by the Templar with a kilt. It fits the theme of Wraeclast better, and it fits the voice of the Templar.
I really would like to see a game where I can login using the OpenID standard (using Google, Facebook, Twitter ...). Using that you have the two-step authentication for free, if the users enable it on the OpenID provider.

Using that you don't have to store the password or the password hash (I really hope you only store the hash ;-) ), so the server becomes 100% secure against password theft.
"
WippitGuud wrote:
What about MAC address registration instead? That's unique to the computer.

Are there any/many people who play on more than one computer system?


I do play on more than one machine, and cloning a MAC address is as easy as editing a config file. But It is indeed another layer of protection.

The way the Steam handles this issue
is something interesting to see.
Last edited by DarkMantle on Feb 22, 2013, 12:07:45 PM
"
exploder:

I made a guide in my work about strong password, Im using transposition, replacement, signs, Caps and 9+ lenght.

Just an example:

Password: pathofexile

Password with replacement: p4th0f3x1l3

Password with Replacement and Transposition: 3x1l3f0p4th

Password with Replacement, Transposition and Signs: 3x1l3*f0!p4th

Password with Replacement, Transposition, Signs and Caps: 3X1l3*F0!p4Th

(this was just an example I'm not using this passwords in any of my accounts)

And you just need to remember the first word and what methods you use, and everytime use words out of everything known about the game or yourself.

Regards!


LOL! It's good to see someone from the "fold." :) Personally, I've always been interested in cryptographic techniques, have a background in Quantum Cryptography and my mentor (from the NSA [National Security Administration - aka, No Such Agency ;)]) is considered an international security guru - he thinks that's hilarious and of course I tease him about it lol!

Your replacement/transposition is quite effective, personally I prefer the transposition and 3 position slide (oh that does sound dirty doesn't it lmao!) but I get the sneaky feeling most lay-men would have a major coronary if they had to figure out how you arrived at 3X1l3*F0!p4Th from pathofexile. Personally, for the everyday person, I give them the easy way to do it:

1) Pick a song, poem or something catchy that you'll remember - Ring around the rosey, pocket full of posey...

2) Grab the first letter - Ratrpfop

3) Make some numbers - Ra7rpf0p

4) Add some special characters - R@7rp*0p

5) Give it a cap or 2 - R@7Rp*0p

and there you go - easy for the everyday guy to remember and meets the minimum of security requirements; min 8 char; uppercase, lowercase, special characters and numbers.

Cheers




The Pope quit, a meteor fell on Russia, an
asteroid came close to the earth, there's snow
in Arizona, star wars and star trek have the
same director! Who the hell is playing jumanji?
Thank goodness that you have the balls to lay out the truth of the matter, especially in CS manpower restrictions, rather than having stupid policies that you cannot enforce. Two thumbs up to this post.

Oh, and very quick response to the issue. I'd give you more thumbs up if I had more thumbs.
Last edited by kosryvrdrgn on Feb 22, 2013, 10:23:51 AM
So just logged in and it told me that someone from my "Neighbour" City logged into already into my Account, i didn't thought any bad about it and let the System sent me a new Password. After i typed it in and entered the Char Selection i saw already the bad outcome of this.. my HC Char died it seems and was set back into the Default League and also some Items are missing.. so how am i suppose to fix that Problem now ? I mean the Char is just lvl 49 but it would be the 3rd Time already that i have to level a new Char then in HC just because someone was able to get into my Account..

And on the side, my Password isn't easy and is also kinda a longer one, so i assume because GGG just got a Service Team of 8 Employeès means that i won't have any chance to get my Char back atleast to the Hardcore League am i right ?

Regards , dcHu.

Report Forum Post

Report Account:

Report Type

Additional Info