Author Topic: How did they get your password?  (Read 11660 times)

Offline Ryan.

  • Honorable
  • *****
  • Posts: 104
  • Skillers™
  • Registered: 28/06/2012
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
Re: How did they get your password?
« Reply #30 on: 22 03, 2014, 02:38:59 pm »
Well, that is one of the huge problems a server could face. Those steps given above are awesome to prevent it but I also came up with a new idea.

What I was thinking lately is that why not having PIN codes for accounts? You will be asked to give a PIN code while registering an Ingame account and there, you will be warned strictly that you cant change the PIN code once you have it.

For this, people will have one and only one PIN code added either in your account data by setAccountData or into a new database. So when you lost your password, you gotta click "Forgot password" in login window and it will ask for your current e-mail and as well as your account PIN code. If both things are correct and matching the database/account data, you will be asked for new password.

In my opinion, this PIN code system is better and the serial protection is also great. Here, few questions arise:

What if I forgot my PIN code?
- Thats your fault but if you prove it that you are NOT a hacker, you can inform Lx+ staff to change your code by /changepin account newPin command.

If we can only set it on the time of registering, what about existing accounts?
- On player login, if database/account data returns false value, player will be asked for PIN code, window will appear saying "Your account doesnt have any PIN code yet, to proceed playing, enter any PIN code two times." And here players will be strictly warned aswell that you cannot change your PIN code.

What if a hacker contacts a staff to change my PIN?
- For this purpose, if someone asks to change his PIN, staffs will inform them that I will change PIN after 7 days. So if real owner logs in in these days, he will see that his account hacked and he will easily recover it by PIN code.

If the PIN system is not going to work, then the serial system is great option, I just gave my input.
I am not "Ex." anything, I have proudly served this community as: SK Founder,
 Developer, L3 staff, L2 staff, Supporter, Minister of Fairness, PAM, CB, PC, SO, Senior Community Member and of course, a rule abiding player. Peace.

jackrockman

  • Guest
Re: How did they get your password?
« Reply #31 on: 22 03, 2014, 04:13:10 pm »
Well, that is one of the huge problems a server could face. Those steps given above are awesome to prevent it but I also came up with a new idea.

What I was thinking lately is that why not having PIN codes for accounts? You will be asked to give a PIN code while registering an Ingame account and there, you will be warned strictly that you cant change the PIN code once you have it.

For this, people will have one and only one PIN code added either in your account data by setAccountData or into a new database. So when you lost your password, you gotta click "Forgot password" in login window and it will ask for your current e-mail and as well as your account PIN code. If both things are correct and matching the database/account data, you will be asked for new password.

In my opinion, this PIN code system is better and the serial protection is also great. Here, few questions arise:

What if I forgot my PIN code?
- Thats your fault but if you prove it that you are NOT a hacker, you can inform Lx+ staff to change your code by /changepin account newPin command.

If we can only set it on the time of registering, what about existing accounts?
- On player login, if database/account data returns false value, player will be asked for PIN code, window will appear saying "Your account doesnt have any PIN code yet, to proceed playing, enter any PIN code two times." And here players will be strictly warned aswell that you cannot change your PIN code.

What if a hacker contacts a staff to change my PIN?
- For this purpose, if someone asks to change his PIN, staffs will inform them that I will change PIN after 7 days. So if real owner logs in in these days, he will see that his account hacked and he will easily recover it by PIN code.

If the PIN system is not going to work, then the serial system is great option, I just gave my input.

Well, That what I just think about it and write My suggestion about that subject .. but, I think no one noticed it .. 

Well, For every account must have got "Security account log-in" .. I think It is the best way to save our accounts .. Because when the hacker log-in the account .. There are window will appear saying "Security account log-in" .. So he won't log-in in the account.. Because he stole Account and Password .. Not Account's security code .. So I suggest to do this .. and No one give to anybody his "Security code" ..

Somethings about that suggestion :-

No one give his " Security code " to anyone
If someone forget his " Security code " .. There will be a window in log-in window .. Like " Forgot Password "
Email-adress of " Security code " will be the same for The account.
If this script added .. to make your " Security code " will be a command it is " /securitycode <yoursecuritycode> " and The message will be sent to your account's email-adress.. To confirm it

Just that.

Offline Arran

  • Administrator
  • ******
  • Posts: 5642
  • Registered: 20/11/2010
    YearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYearsYears
  • Ingame: [CIT]Arran
Re: How did they get your password?
« Reply #32 on: 22 03, 2014, 04:34:51 pm »
I've decided what I'm going to do.
Proof You Are so Much More Than What You Realise
Authority is not truth. Truth is authority.