![]() |
alternative to ip validation on RC
Many people who use RC to connect are on dial up, and numerous ip additions are needed. This is sometimes a real inconvenience, and I have been on both the end of the one to update the ip list for someone, and have beem the on e to be not able to log in to rc, and needed to wait for hours for another admin to log in and update my ip list.
Not only is this a problem with dial up, but I have a comcast high speed cable modem, and it seems that they too have recently gone to DHCP, and in the past three days I have had at least five differences in my ip in the second set of numbers. for example, 64.181.*.* where the 181 is, that number almost always changes at least once, if not two or three times a day, and my cable modem is always on! How about using the MAC address of the network card to identify a specific computer to log in? That hardware integrated number does not change unless you get a different comptuer. Or some kind of consistent number, without needing to shell out big bucks to comcast for a business account, which is the only way to get a static ip from them now. |
Stefan said something about being able to ban by "computer ID".
There should also be a way to limit the RC access to Computer ID as well. |
Quote:
Quote:
Just log the set of IP adresses you receive and make out a pattern. "All the numbers change" is not a pattern. If there is none that Graal would be content with, settle for the most common one, and if that fails you, gain new IP adresses until you get one that matches. And what the hell is a computer ID and why would you ban people's computers? |
Quote:
The new Graal banning system uses some computer ID to ban the player therefore no account can log in. =O |
Quote:
|
Quote:
|
Quote:
|
Perhaps a password system would achieve this, set up in this mannor.
A 56k user, or any user, logs onto RC as normal using their account name and password. When they connect to the server via RC, no functions, nor RC chat will be available to them, and they will not appear on the playerlist. The NPC server will then PM them asking for their RC password. This password will be able to be set and saved by a manager or admin. The player then PMs the server the password to authenticate, and if correct, RC works as normal. While not as secure as an IP, it is for sure an extra level of protection. |
Quote:
|
About the MAC Addresses:
It may be ease to spoof the MAC Address, but it would be hard to know what to spoof it to. If the person managed to get their password and username, it doesn't matter whether the person is a hacker or not; They just need to ask to add their IP, and they pass in flawlessly; The staff get too used to adding IPs for that person, and the security measure is wrecked by doing so. |
Quote:
Quote:
|
Quote:
If you ask me, using MAC addresses is more secure than IP. A combination of the two might be better. |
Quote:
Quote:
|
Graalians just need to stop being *****s as far as security goes. Most of the problems with account theft is the owners themselves giving out the passwords or allowing players to send them viruses - in which case if a hacker gains access to someones passwords outside of an email account, they don't need a IP to log on. They just need to log on using the staff member's computer.
Graal's security system is far from flawless, but if a security breach occurs it's usually the fault of an ingorant staff member - not the system itself. |
Quote:
|
All times are GMT +2. The time now is 01:25 PM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.