EntropiaForum.com
Go Back   EntropiaForum.com > Information > About Entropia Universe
Notice
About Entropia Universe Entropia Universe information.

Reply
 
LinkBack Thread Tools
Old 05-12-2006, 06:25   #1
Safety not guaranteed!
e-lite's Avatar
This member has helped support EntropiaForum in the past via donations.
Become a premium member today and enjoy enhanced EntropiaForum features!
e-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Mastere-lite Ultimate Master  
  Activity Longevity
4/2020/20
Posts: 4,094
Gender: Male Ingame: Male
Avatar Name:
Xaero e-lite Cynque
Soc: Magnum Opus
Location: Sweden
EFD: 3,386.31
Reputation: Ultimate Master
Fame: 2389 Achievements: 84
Style: TI Second Entity
How to make login more secure

Good morning everyone.

Well we all know about the recent and increasing amount of "hacked accounts". The problem here isn't that the account where "hacked". It happens simply because the victims PC is infected with a trojan keylogger that sends the users login name and password to the "hacker". I think this is the most common scenario. Then there can be other reasons, the list is endless.

One of the best solutions is to get yourself a gold card. But there's still things that MindArk can do to both implement additional security to the login procedure, and increase security for them who do not have a gold card. The feature I have come up with will work as follows:

MindArk announces the new feature, and everyone have to login to client loader and activate the settings under user preferences.

Under user preferences the user must now choose a "keyword" from a static list over perhaps 50-100 words. The user must also choose a "color" from a static list over 20-30 colors.

The "keyword" and "color" that the user selected will now be associated with his/hers username and password, and will be relative to it. (This will require for MA to add two more columns to the user database)

From now on the user have to pick the keyword and the color from the pop-up menus in the client loader everytime he/she wants to login. The pop-up menus will show the same static list, but in a random sequence every time.(Se screenshot) If the user have choosen "yellow" and "Fungoid" his/hers username and password will only work when "Fungoid" and "Yellow" is selected.

This feature implements additional security even if the users PC is infected with a keylogger or trojan, simply because selecting the keyword and color is almost impossible to "keylogg". So the hacker might be able to get the username and password, but he still has no clue what the keyword and the color is.


Click to enlarge

Last edited by e-lite; 05-12-2006 at 09:14. Reason: added "static content, random sequnce", thanks to Mr. Wot
__________________
e-lite is online now Reply With Quote
Old 05-12-2006, 07:06   #2
Oye
Dominant
Oye's Avatar
This member has helped support EntropiaForum in the past via donations.
Oye CapableOye CapableOye CapableOye CapableOye CapableOye CapableOye CapableOye CapableOye CapableOye CapableOye Capable  
  Activity Longevity
1/2015/20
Posts: 385
Gender: Male Ingame: Male
Avatar Name:
Arne Oye Ness
Soc: Angry Vikings
Location: Norway
EFD: 1,536.00
Reputation: Capable
Fame: 391 Achievements: 15

That sound like a very good idea.

Sould not be to much work for MA either. Only question is if MA will do anything like this, since it might lead to less sale of the Gold-card.

I really think MA should have done something like this, to prove that they have focus on security.
__________________
Proud member of

www.angryvikings.com

Oye is offline Reply With Quote
Old 05-12-2006, 07:17   #3
Old Alpha
KapokWu's Avatar
KapokWu InitiatedKapokWu InitiatedKapokWu InitiatedKapokWu InitiatedKapokWu InitiatedKapokWu Initiated  
  Activity Longevity
1/2018/20
Posts: 741
Gender: Male Ingame: Male
Avatar Name:
Kapok "Kapok" Wu
Soc: Phoenix Omega
Location: Finland
EFD: 19,556.34
Reputation: Initiated
Fame: 69 Achievements: 5

I hope that list of 50-100 alternative keywords is generated
anew each time. Also, each avatar should be sent a message
about the new MA generated email address, which is for their
account management only
__________________
Fool me once, shame on you, fool me twice, shame on Wu!
KapokWu is offline Reply With Quote
Old 05-12-2006, 07:26   #4
Old
q Slane q's Avatar
q Slane q Unskilled  
  Activity Longevity
0/2015/20
Posts: 102
Gender: Male Ingame: Male
Avatar Name:
qqq Slane qqqq
Soc: Magnum Opus
EFD: 5,375.81
Reputation: Unskilled
Fame: 43 Achievements: 1

Yeah, and implement GC for logging in to "My Section" on the website. Dont want any looney depositing my salary for me ;-p
__________________
q Slane q is offline Reply With Quote
Old 05-12-2006, 07:35   #5
Alpha
Rapido's Avatar
Rapido NoviceRapido NoviceRapido NoviceRapido Novice  
  Activity Longevity
3/2017/20
Posts: 617
Gender: Male Ingame: Male
Avatar Name:
Rob Rapido Green
Soc: Rangers
Location: Strängnäs, Sweden
EFD: 10,465.20
Reputation: Novice
Fame: 1269 Achievements: 96
Style: Segna Chomper

Nice suggestion there E-lite, I like it very much. Wonder what MA say about it?

Yes I should buy a goldcard and probebly will soon, the reason (for me anyway) is, if you dont have a lots of peds, you easely use them for other things instead...

Rapido
Rapido is offline Reply With Quote
Old 05-12-2006, 07:41   #6
Stalker
Nakia's Avatar
This member has helped support EntropiaForum in the past via donations.
Nakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia IncredibleNakia Incredible  
  Activity Longevity
0/2018/20
Posts: 2,600
Gender: Female Ingame: Female
Avatar Name:
June Nakia Smith
Soc: Novus Ordo Seclorum
Location: In MrSmith's heart
EFD: 3,666.61
Reputation: Incredible
Fame: 660 Achievements: 9
Style: Zychion Battle
Flower Beauty Sense Firestorm

very good idea, would be nice if something like this was made

+rep for a nice idea and good explanation

edit I must spread some before giving it again
__________________
Click HERE to add your wish for PE/EU's future
~ Playing Since 30th Dec 2004 and Queen of Calypso since Dec 2004 ~
Nakia is offline Reply With Quote
Old 05-12-2006, 07:47   #7
Prowler
This member has helped support EntropiaForum in the past via donations.
Noggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin Elite  
  Activity Longevity
3/2018/20
Posts: 1,371
Gender: Male Ingame: Male
Avatar Name:
Balthazar Noggin Fishburn
Soc: nothing AND nowhere (nAn)
Location: UK
EFD: 1,640.40
Reputation: Elite
Fame: 0 Achievements: 0

Great idea... Alternatively a method online banks use is quite a good method too;

When you create your account, type in a word or phrase between 10 and 15 characters long. When you log in each time, the login process asks you for 3 random characters from this phrase which you select from listboxes.

So for example, if your memorable word was "Cornundacuda", it might ask you for letters 3, 9 and 11 of this phrase (r, c and d). This is a very simple way to reduce the effectiveness of keyloggers... this could also be applied to the login for the website too (an area which isn't protected even if you have a gold card!).

Anyways, +reps for the idea!
__________________
Quote:
Originally Posted by Etopia
..but if you think MA will use a player compliant solution , you put your fingeur in your eye so deep you can touch your pantie that sure ...
Noggin is offline Reply With Quote
Old 05-12-2006, 07:51   #8
Old Alpha
This member has helped support EntropiaForum in the past via donations.
Moser QualifiedMoser QualifiedMoser QualifiedMoser QualifiedMoser QualifiedMoser QualifiedMoser Qualified  
  Activity Longevity
0/2020/20
Posts: 752
Gender: Male Ingame: Male
Avatar Name:
Mark Moser Jorgensen
Soc: Dawn Daemons
Location: Norway
EFD: 14,334.73
Reputation: Qualified
Fame: 122 Achievements: 3

Good idea. Another option would be a picture with numbers and letters popping up, and you needing to write then in to login.
Moser is offline Reply With Quote
Old 05-12-2006, 07:57   #9
Jac
Banned
multiple accounts
Jac's Avatar
Jac ApprenticeJac ApprenticeJac ApprenticeJac ApprenticeJac Apprentice  
  Activity Longevity
0/2016/20
Posts: 345
Gender: Male Ingame: Male
Avatar Name:
Jacob Jac McGregor
Soc: Northern Household
Location: Germany
EFD: 6,261.30
Reputation: Apprentice
Fame: 188 Achievements: 3

Good idea. Even simplier online-banking is done. You have to "human-read" some graphical manipulated digits and "click" them in via a pop-up-keypad (not typing it, keyloggers!).


Click to enlarge


Advantage for MA: No change of the database needed, just some more code for the authentification-process...

Explanation: The digits are generated randomly and dont need any relationship to the account. Its a picture to prevent them being read from screen via Windows-API... even OCR-Software cant read this properly.


Jac


EDIT: damned, Moser was quicker... lol
Jac is banned from EntropiaForum (either temporarily or permanently). Reply With Quote
Old 05-12-2006, 08:15   #10
Prowler
This member has helped support EntropiaForum in the past via donations.
Noggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin EliteNoggin Elite  
  Activity Longevity
3/2018/20
Posts: 1,371
Gender: Male Ingame: Male
Avatar Name:
Balthazar Noggin Fishburn
Soc: nothing AND nowhere (nAn)
Location: UK
EFD: 1,640.40
Reputation: Elite
Fame: 0 Achievements: 0

Quote:
Originally Posted by Jac
Explanation: The digits are generated randomly and dont need any relationship to the account. Its a picture to prevent them being read from screen via Windows-API... even OCR-Software cant read this properly.
Excuse me if I'm being dense, but I don't think I get how this will protect accounts from hackers -- isn't this simply a bot-prevention? If the numbers are not related to the account, then can't the hacker simply type them in when challenged?

This is my understanding of what you just said:

Player logs in as normal with usual account name and password. Player is then prompted to input a number sequence generated within a bitmap.

Surely anybody who logs in will get a randomly generated number? I don't see how this is related to the user to increase security, simply to stop some sort of login automation!

Again, it's early and my brain hasn't started working properly yet
Noggin is offline Reply With Quote
Reply

Bookmarks

Thread Tools
 
EntropiaTracker.com Loot Trends
Hunting Loot: + 31.81 % Mining Loot: + 35.13 % Crafting Loot: + 11.05 %
EntropiaTracker.com Latest Uber Loots
 Barry Tayonas Marshall OreAmp OA-101 Light (L) - 2106 PED: 10/12/2008 19:23 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1155 PED: 10/12/2008 19:20 | Stoikow Stoikow Mudorow Atrox Young - 1639 PED: 10/12/2008 19:09 | Cloud Cloudy Skywalker Atrox Mature - 21879 PED: 10/12/2008 19:05 | Macco Macco Macco Shriek Basic - 1303 PED: 10/12/2008 19:00 | Barry Tayonas Marshall OreAmp OA-101 Light (L) - 1611 PED: 10/12/2008 18:42 | Bobby Skankinbob Deluxe Work Pattern Shirt (F,C) - 1904 PED: 10/12/2008 18:28 | Levinstein Lev II Ganganite stone - 1252 PED: 10/12/2008 18:18 | Cali Destiny Sijngaard Atrox Young - 1481 PED: 10/12/2008 18:15 | Adriana ADI Zulawinska EnMatAmp MA-105 (L) - 1298 PED: 10/12/2008 18:13 | Ahbin LaG Pludidee Simple II Conductors - 1255 PED: 10/12/2008 17:43 | Violet Vi Neomir OreAmp OA-101 (L) - 4009 PED: 10/12/2008 17:28 | Lord Keldon Keldon Zinc stone - 1445 PED: 10/12/2008 17:12 | Fahd Scarface Kahn Lysterium stone - 3045 PED: 10/12/2008 17:11 | MH Grave Digger Daspletor Mature - 1081 PED: 10/12/2008 16:58 | Warvar Mortal Wild Blausariam stone - 1149 PED: 10/12/2008 16:49 | Mantus Crosskeeper Wolfenmond OreAmp OA-101 (L) - 10204 PED: 10/12/2008 14:48 | Parker Parker Van Helsing Maffoid Clan Warlord - 1616 PED: 10/12/2008 14:40 | Trox´s must die 2day with Atrox Mature - 17665 PED: 10/12/2008 14:32 | Axel Foley Head Gazzurdite stone - 1405 PED: 10/12/2008 14:19 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3094 PED: 10/12/2008 14:07 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3887 PED: 10/12/2008 14:05 | Max Marmac Power Aurli Weak - 23214 PED: 10/12/2008 13:39 | Toast Toast CHG OreAmp OA-101 (L) - 2449 PED: 10/12/2008 13:36 | nirvana pretty the best Lysterium stone - 1540 PED: 10/12/2008 13:23 | Jade Kaliah Elite OreAmp OA-101 (L) - 1716 PED: 10/12/2008 12:33 | Narcissus nar cissus Cumbriz stone - 1626 PED: 10/12/2008 12:07 | Alex Neophyte Zane OreAmp OA-105 (L) - 5450 PED: 10/12/2008 11:48 | Alex Neophyte Zane OreAmp OA-105 (L) - 1862 PED: 10/12/2008 11:42 | Toast Toast CHG OreAmp OA-101 (L) - 1658 PED: 10/12/2008 10:57 | Jar Jasis Sismondi Atrox Young - 8703 PED: 10/12/2008 10:49 | never say never Lysterium stone - 1925 PED: 10/12/2008 10:42 | Bart Muskito Joosten Typonolic Steam - 2277 PED: 10/12/2008 10:23 | Pieter Belov Belovski EnMatAmp MA-107 (L) - 1594 PED: 10/12/2008 10:10 | lee mundo chis Dino Shoes (F,C) - 2073 PED: 10/12/2008 09:35 | CHUNBIAO WIFELOVER WEI EnMatAmp MA-102 (L) - 1350 PED: 10/12/2008 09:31 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 3344 PED: 10/12/2008 09:11 | Maronelle Analytic Thunder Analina Ignisium stone - 1172 PED: 10/12/2008 09:10 | Pieter Belov Belovski EnMatAmp MA-102 (L) - 1689 PED: 10/12/2008 08:07 | Veronica Accesible Bosch Armax Bull Old - 1199 PED: 10/12/2008 07:38 | liliang baoshen liliang Blausariam stone - 1285 PED: 10/12/2008 07:14 | liliang baoshen liliang Blausariam stone - 1373 PED: 10/12/2008 07:07 | Rose Marie Descartes Lysterium stone - 1147 PED: 10/12/2008 06:45 | Divine Vixen Incarnate OreAmp OA-101 Light (L) - 1442 PED: 10/12/2008 05:12 | Ambu Swunt Ambulimax Young - 2495 PED: 10/12/2008 05:11 | HE Runt loves Paul Daikiba Old Alpha - 17122 PED: 10/12/2008 04:21 | Aurora Linzey Zamperath OreAmp OA-101 (L) - 1195 PED: 10/12/2008 01:30 | dire Godspeed straights OreAmp OA-101 (L) - 1487 PED: 10/12/2008 01:13 | Leonarda Leona DaVinci Cersumon Mature - 1654 PED: 10/12/2008 00:59 | Hola Ketty HolaKetty Force Nexus - 6063 PED: 10/12/2008 00:54 | Venera Venera Marss EnMatAmp MA-103 (L) - 1472 PED: 10/11/2008 23:28 | idvali idvali mosu OreAmp OA-101 (L) - 2513 PED: 10/11/2008 22:05 | Cloud Cloudy Skywalker Feffoid Raider - 1960 PED: 10/11/2008 21:18 | Hedores Hedaya Cassapaya OreAmp OA-101 (L) - 1232 PED: 10/11/2008 21:13 | Fred Ice Issue Morpheus Stone - 1410 PED: 10/11/2008 20:26 | Tom Archy Bald Erdorium stone - 1027 PED: 10/11/2008 20:25 | Susan Porcupine Butcherlyfly Svempa X1 (L) - 1290 PED: 10/11/2008 20:23 | Annabell Annabella Jones Berycled Old - 2403 PED: 10/11/2008 20:10 | Divine Vixen Incarnate OreAmp OA-107 (L) - 1133 PED: 10/11/2008 19:42 |

~