EntropiaForum.com
Go Back   EntropiaForum.com > Information > About Entropia Universe > Security
Notice
Security Discussion relation to Entropia Universe account security.

Reply
 
LinkBack Thread Tools
Old 11-30-2007, 16:53   #1
Guardian
ufcfl's Avatar
ufcfl Beginnerufcfl Beginner  
  Activity Longevity
3/2019/20
Posts: 288
Gender: Male Ingame: Female
Avatar Name:
Kylie Kylie White
Soc: Federation of Free Wanderers
Location: Nangis, France
EFD: 902.94
Reputation: Beginner
Fame: 4 Achievements: 1
Style: Old EF Skin
More secure goldcard

We've seen some cases of people having a goldcard who were hacked because of the EU website that only asks for the password. Then the thief can fill a support case asking do disable the GC.
I see a simple thing that would fix this. When someone asks in a support case for a GC disable, MA should first ask the player to enter one (or more) GC code(s). The code would have to be a not used one yet, so the player wouldn't login until support answers. That way, MA could verify if the person is really the owner of the GC.

What do you think?

PS : Sorry for the bad english
__________________
Known ingame as Kylie White
ufcfl is offline Reply With Quote
Old 11-30-2007, 16:59   #2
Prowler
Rednexi's Avatar
Rednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi VeteranRednexi Veteran  
  Activity Longevity
6/2014/20
Posts: 1,362
Gender: Male Ingame: Male
Avatar Name:
Redneksi Rednexi Babek
Soc: The NBK
Location: Humppa-akatemia
EFD: 95.55
Reputation: Veteran
Fame: 872 Achievements: 27
Style: Original EF Skin
Opalo Toxic Shot

just had to gratz...why on earth there is a gratz button on security forum ?
__________________
You have come here because society has no further use for you. This place will now become your holding pen until our death.
Rednexi is offline Reply With Quote
Old 11-30-2007, 17:12   #3
Prowler
jdegre's Avatar
EntropiaForum Senior Member, click here for more information.
jdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteranjdegre Veteran  
  Activity Longevity
7/2015/20
Posts: 1,534
Gender: Male Ingame: Male
Soc: Survival Program
Location: Madrid, Spain
EFD: 562.65
Reputation: Veteran
Fame: 335 Achievements: 11
Style: TI Second Entity
Champagne

Quote:
Originally Posted by ufcfl View Post
We've seen some cases of people having a goldcard who were hacked because of the EU website that only asks for the password. Then the thief can fill a support case asking do disable the GC.
i hope it is not that simple!. i was under the impression that, if you order to disable the GC form the web site, you must fax/mail MA some kind of identity proof.... are you sure MA will disable your GC just by filing a support case?
__________________
The Chipping Optimizer Tool

Skill Scanner
Automatically extract your skills from in-game screenshots
Now updated for VU9.3!!
jdegre is offline Reply With Quote
Old 11-30-2007, 17:16   #4
Elite
onyx oZ Zombie's Avatar
EntropiaForum Senior Member, click here for more information.
onyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteranonyx oZ Zombie Veteran  
  Activity Longevity
7/2014/20
Posts: 3,921
Gender: Male Ingame: Male
Location: St. Louis, US
EFD: 83.92
Reputation: Veteran
Fame: 466 Achievements: 10
Style: TI Second Entity
Serendipity Ranged Damage Assessment Marksmanship

Quote:
Originally Posted by jdegre View Post
i hope it is not that simple!. i was under the impression that, if you order to disable the GC form the web site, you must fax/mail MA some kind of identity proof.... are you sure MA will disable your GC just by filing a support case?
im pretty sure that is the case, jdegre, but have no verification
__________________

oZ, fighting spelling abuse of the word "LOSE" since August '05
onyx oZ Zombie is offline Reply With Quote
Old 11-30-2007, 17:18   #5
Prowler
Vap0r's Avatar
Vap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r SkilledVap0r Skilled  
  Activity Longevity
2/2018/20
Posts: 1,427
Gender: Male Ingame: Male
Avatar Name:
Vap0r Vaps
Soc: cK
Location: Cambodia, 3rd hut on the left
EFD: 1,049.75
Reputation: Skilled
Fame: 145 Achievements: 2
Style: Segna Chomper
Commando Serendipity Champagne Toxic Shot
Wrench

I guess the grats is for not understanding how it works ?
Nobody with a gold card can have someone log into the EU website and request the card be disabled without providing the same documentation needed for limit increases. IE Color Goverment Issued ID, Utility bill in your name, birth certificate etc. These measures are in place to prevent such incidents from happening and yes they are a pain in the arse but they are for your protection.
I'd really like to see an example of someone with a GC being hacked, that 1) Didnt give someone the next number in the sequence or 2) didnt give someone the GC itself.
I do internet banking security in the states and the GC system is surprisingly better then most US banks.
GREAT JOB MINDARK!
__________________
-------------------------------------------
Is that an olive branch or a finely tuned M7a2?
-------------------------------------------

Vap0r is offline Reply With Quote
Old 11-30-2007, 17:19   #6
Old Alpha
Alien's Avatar
Alien TrainedAlien TrainedAlien TrainedAlien TrainedAlien TrainedAlien TrainedAlien Trained  
  Activity Longevity
5/2011/20
Posts: 726
Gender: Male Ingame: Female
Soc: The Calypso Rescue Team
Location: Cardiff > Wales > UK
EFD: 43.60
Reputation: Trained
Fame: 292 Achievements: 4

MA will've definately protected against this.. I remember reading somewhere if you want the GC disabled you have to fax them a goverment issued ID signed by someone or other (Can;t remember who)

Oh and Grats ;P
__________________
Alien is offline Reply With Quote
Old 11-30-2007, 17:21   #7
Guardian
Art Ludgren's Avatar
Art Ludgren NoviceArt Ludgren NoviceArt Ludgren Novice  
  Activity Longevity
0/209/20
Posts: 316
Gender: Male Ingame: Male
Avatar Name:
Art Ludgren
Soc: TKoC
EFD: 612.29
Reputation: Novice
Fame: 0 Achievements: 0
GC security on website....

Quote:
Originally Posted by ufcfl View Post
We've seen some cases of people having a goldcard who were hacked because of the EU website that only asks for the password. Then the thief can fill a support case asking do disable the GC.
I see a simple thing that would fix this. When someone asks in a support case for a GC disable, MA should first ask the player to enter one (or more) GC code(s). The code would have to be a not used one yet, so the player wouldn't login until support answers. That way, MA could verify if the person is really the owner of the GC.

What do you think?

PS : Sorry for the bad english
A couple thoughts, I paid $20 for a gold card, what do you mean they will disable it from a support case, without proper identification!!!
YOU GOTTA BE KIDDING

If an account gets hacked and the gold card gets subverted because MA does not follow it's own procedures MA should FULLY reimburse player for all lost items.

On the idea of using the gold card on the website; what if my GC is broken

I think that when the goldcard is registered as being received, one of the codes should be entered into the website WITH the serial number of the gold card. With this combination you should be able ( and only able to) cause a broken gold card to be replaced, sent to the current address on record.

In the case that the above mentioned code and serial number are unavailable, the only solution I would find acceptable is the photocopy of passport being sent to MA and then a new GC being sent out to the address of record.

There should be the only 3 ways to get a broken card replaced, passport, personal visit to MA with passport or with the above mentioned registered gold card code and gold card serial number.

Obviously the GC should be used for address changes. And no address changes without a proper GC code.

Of course in the US the postal authorities ( almost a separate police department in themselves ) take a VERY DIM view of people using the mail to further any type of crime.

Yes I know a lot of people will say "I FORGOT", well put the info on a scrap of paper and put it in your ( or your parents) safe deposit box, or hide it under a floorboard in your house.


Art.
Art Ludgren is offline Reply With Quote
Old 12-01-2007, 14:05   #8
Guardian
ufcfl's Avatar
ufcfl Beginnerufcfl Beginner  
  Activity Longevity
3/2019/20
Posts: 288
Gender: Male Ingame: Female
Avatar Name:
Kylie Kylie White
Soc: Federation of Free Wanderers
Location: Nangis, France
EFD: 902.94
Reputation: Beginner
Fame: 4 Achievements: 1
Style: Old EF Skin

Hmm, it seems i forgot the first reason why someone would want his GC disabled : a not working goldcard. So how could MA ask the person a valid GC code to verify his identity?
Sorry for the useless thread
ufcfl is offline Reply With Quote
Old 12-01-2007, 14:13   #9
Master of the Universe
andyzammy's Avatar
andyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkableandyzammy Remarkable  
  Activity Longevity
2/2014/20
Posts: 5,051
Gender: Male Ingame: Male
Avatar Name:
Adapted Zammy(L) Mutated
Soc: Divide & Conquer
Location: Bradford
EFD: 102.04
Reputation: Remarkable
Fame: 1601 Achievements: 40

Quote:
Originally Posted by ufcfl View Post
We've seen some cases of people having a goldcard who were hacked because of the EU website that only asks for the password. Then the thief can fill a support case asking do disable the GC.
please do tell us about these cases! new to me

they ask for RL id. which is why nobody will ever be able to hack u.
__________________
....don't worry, it's all part of the Master Plan....
andyzammy is offline Reply With Quote
Old 12-01-2007, 15:23   #10
Guardian
Art Ludgren's Avatar
Art Ludgren NoviceArt Ludgren NoviceArt Ludgren Novice  
  Activity Longevity
0/209/20
Posts: 316
Gender: Male Ingame: Male
Avatar Name:
Art Ludgren
Soc: TKoC
EFD: 612.29
Reputation: Novice
Fame: 0 Achievements: 0
nice try at sarcasm

Quote:
Originally Posted by ufcfl View Post
Hmm, it seems i forgot the first reason why someone would want his GC disabled : a not working goldcard. So how could MA ask the person a valid GC code to verify his identity?
Sorry for the useless thread
If you noted I suggested that you REGISTER a valid GC code + GC serial number for future use in an emergency. I also mentioned that SOME people would forget/lose it and therefore:

MA already has policy that requires passport or other reasonable id copy required for turning off gold card.

Nice try at sarcasm but it just shows you did not read the post


Quote:
Originally Posted by Art Ludgren View Post
<Stuff deleted>

On the idea of using the gold card on the website; what if my GC is broken

I think that when the goldcard is registered as being received, one of the codes should be entered into the website WITH the serial number of the gold card. With this combination you should be able ( and only able to) cause a broken gold card to be replaced, sent to the current address on record.
As a general statement "Anyone with a Gold Card would NOT want it disabled". Yes there may be exceptions, but MA seems to have it covered by policy. If MA breaks their own policy that is a different matter although EULA seems to cover that by our agreeing that even if we suffer losses by MA negligence we hold them harmless.

As far as useless thread, it is useful in showing MA how much of their documentation/EULA/FAQ people actually read.



Art

BTW: fDid not mention, pushed publish instead of preview

You actually mentioned that people use a not yet used GoldCard code yourself in first post?????
Art Ludgren is offline Reply With Quote
Reply

Bookmarks

Thread Tools
 
EntropiaTracker.com Loot Trends
Hunting Loot: + 78.82 % Mining Loot: + 16.15 % Crafting Loot: + 16.51 %

~ Entropia Universe | Entropia Radio | Entropia Wiki | Entropia Tracker | Entropians IM ~

All times are GMT. The time now is 03:32. | Calypso Time: 3:32

Copyright ©2005 - 2008, EntropiaForum.com.
Entropia Universe is a registered trademark of Mindark PE AB.
All other copyrights and trademarks are property of their respective owners.
Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.