Graal Forums  

Go Back   Graal Forums > Development Forums > NPC Scripting > Code Gallery
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #31  
Old 02-22-2007, 09:51 PM
Kristi Kristi is offline
Bowie's Deciple
Kristi's Avatar
Join Date: Dec 2003
Location: Boston, MA
Posts: 748
Kristi has a spectacular aura aboutKristi has a spectacular aura about
Send a message via AIM to Kristi Send a message via MSN to Kristi
Quote:
Originally Posted by Gambet View Post
I'd understand you arguing if there were currently a way to secure the passwords, but since there isn't, I don't really see why we need to continue going back and forth.

I understand the risks, thus you're talking to the wrong person. If I could secure the password system, I would.
Because you are calling the players idiots instead of doing anything. Revise the script to say *Staff can see your password, so do not choose anything that resembles passwords on other things you own* or something along those lines. Make it loud and clear.

There are things you can do to at least better it, like md5 ;/
__________________
Reply With Quote
  #32  
Old 02-22-2007, 09:57 PM
Gambet Gambet is offline
Registered User
Join Date: Oct 2003
Posts: 2,712
Gambet is on a distinguished road
Quote:
Originally Posted by Kristi View Post
Because you are calling the players idiots instead of doing anything. Revise the script to say *Staff can see your password, so do not choose anything that resembles passwords on other things you own* or something along those lines. Make it loud and clear.

There are things you can do to at least better it, like md5 ;/

You're calling the players idiots as much as I am, only in my case it's explicit and in yours it's implicit.

If someone wanted to go as far as trying to crack a persons password based on something as stupid as a Graal bank password, then what makes you think they wouldn't go to an md5 decryption site that does the work for them?

Sure, it would require an extra step, but if they're willing to do it in the first place, it won't stop them.
Reply With Quote
  #33  
Old 02-22-2007, 10:02 PM
Kristi Kristi is offline
Bowie's Deciple
Kristi's Avatar
Join Date: Dec 2003
Location: Boston, MA
Posts: 748
Kristi has a spectacular aura aboutKristi has a spectacular aura about
Send a message via AIM to Kristi Send a message via MSN to Kristi
Quote:
Originally Posted by Gambet View Post
You're calling the players idiots as much as I am, only in my case it's explicit and in yours it's implicit.

If someone wanted to go as far as trying to crack a persons password based on something as stupid as a Graal bank password, then what makes you think they wouldn't go to an md5 decryption site that does the work for them?

Sure, it would require an extra step, but if they're willing to do it in the first place, it won't stop them.
There is nothing wrong with being more secure. Of course its still flawed, but it can still be a deterrent. Also, my request for stating that staff can see your password right in the npc, as my last post requested, still stands, not to mention the other safety edit (using player.account serverside instead of letting the client pass what their account name is, since they can change it)
__________________
Reply With Quote
  #34  
Old 02-22-2007, 10:03 PM
Gambet Gambet is offline
Registered User
Join Date: Oct 2003
Posts: 2,712
Gambet is on a distinguished road
Quote:
Originally Posted by Kristi View Post
There is nothing wrong with being more secure. Of course its still flawed, but it can still be a deterrent. Also, my request for stating that staff can see your password right in the npc, as my last post requested, still stands.

If I ever get back to touching up this system, then sure, but for now, I'll leave it up to whoever decides to use it on their server.
Reply With Quote
  #35  
Old 02-23-2007, 07:05 AM
Twinny Twinny is offline
My empire of dirt
Twinny's Avatar
Join Date: Mar 2006
Location: Australia
Posts: 2,422
Twinny is just really niceTwinny is just really nice
Send a message via AIM to Twinny
How about instead of a password, the script generates a 5 number long code which is used as a pin? Saves letting the user possibly give out an important password.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 05:32 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.