Graal Forums  

Go Back   Graal Forums > General Forums > Graal Main Forum (English)
FAQ Members List Calendar Today's Posts

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #16  
Old 10-03-2006, 09:40 PM
konidias konidias is offline
Old Bee
konidias's Avatar
Join Date: Jul 2001
Location: Orlando, FL
Posts: 7,222
konidias will become famous soon enough
Send a message via AIM to konidias
I'm not liking this for the security issue it poses.

I always liked that the forum pass and account pass could be different. Because there seem to be many more ways to get your account pass stolen. For example, if someone obtained your graal account pass and e-mail, you could have the forum account linked to a different pass and e-mail, and then private message an admin to try and help you get your account back.

Also if someone get's your graal account pass, now they could come on the forum and post a bunch of spam or porn or whatever and get your forum account banned really fast. =/
  #17  
Old 10-03-2006, 09:44 PM
Skyld Skyld is offline
Script-fu
Skyld's Avatar
Join Date: Jan 2002
Location: United Kingdom
Posts: 3,914
Skyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud ofSkyld has much to be proud of
Send a message via AIM to Skyld
They are meant to be linked anyway, just like Graal.net is, and the Wiki is.
  #18  
Old 10-03-2006, 09:45 PM
WanDaMan WanDaMan is offline
Master Tux
WanDaMan's Avatar
Join Date: Aug 2002
Location: England, United Kingdom
Posts: 5,571
WanDaMan is a jewel in the roughWanDaMan is a jewel in the rough
Send a message via MSN to WanDaMan
Woah, that's a huge flaw. Listen to Konidias!
__________________
V$:CONFL16T
  #19  
Old 10-03-2006, 09:50 PM
Damix2 Damix2 is offline
RED SQUARE CLUB
Join Date: Nov 2003
Location: NY-what's better?
Posts: 3,577
Damix2 will become famous soon enough
Excellent, we can start a loriel-esque way to not only get forum passwords but now graal passwords aswell!
__________________
  #20  
Old 10-03-2006, 10:38 PM
unixmad unixmad is offline
Administrator
unixmad's Avatar
Join Date: Mar 2001
Location: Paris
Posts: 695
unixmad is a name known to allunixmad is a name known to allunixmad is a name known to all
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...

Quote:
Originally Posted by konidias View Post
I'm not liking this for the security issue it poses.

I always liked that the forum pass and account pass could be different. Because there seem to be many more ways to get your account pass stolen. For example, if someone obtained your graal account pass and e-mail, you could have the forum account linked to a different pass and e-mail, and then private message an admin to try and help you get your account back.

Also if someone get's your graal account pass, now they could come on the forum and post a bunch of spam or porn or whatever and get your forum account banned really fast. =/
  #21  
Old 10-03-2006, 10:48 PM
Googi Googi is offline
A Serious Epidemic
Googi's Avatar
Join Date: Oct 2001
Location: Canada
Posts: 18,866
Googi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud of
Send a message via AIM to Googi
Quote:
Originally Posted by unixmad View Post
and they are really secure
Which is why we just had to change them.
__________________
  #22  
Old 10-03-2006, 10:57 PM
Darlene159 Darlene159 is offline
Administrator
Darlene159's Avatar
Join Date: Aug 2001
Location: Florida
Posts: 12,470
Darlene159 has much to be proud ofDarlene159 has much to be proud ofDarlene159 has much to be proud ofDarlene159 has much to be proud ofDarlene159 has much to be proud ofDarlene159 has much to be proud of
Random, auto-generated passwords is a good idea anyway because too many people pick way too easy passwords, and tend to use the same password for everything, or at least several things.
__________________
FORUM RULES
GRAAL BIBLE (Lots of useful info)
INFO ABOUT REPUTATIONS.
INFO ABOUT INFRACTIONS.
HOW TO APPLY FOR THE NON-GRAAL RELATED FORUM (<<READ THOROUGHLY!)

SUPPORT: http://support.toonslab.com

NOTE: YOU ARE RESPONSIBLE FOR YOUR OWN POSTS.
READ>THINK>POST
  #23  
Old 10-03-2006, 11:59 PM
Demisis_P2P Demisis_P2P is offline
Kanto League Champion
Demisis_P2P's Avatar
Join Date: Jan 2005
Posts: 2,357
Demisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud of
Quote:
Originally Posted by unixmad View Post
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...
If somebody steals my Graal account by getting into my email address then they have 2 days to do whatever they want. Since password changes can only be sent every 2 days (not to mention that any smart person with access to your email account would change your email password).

I could make a support ticket, if I remember my username and password for that, but by the time it's responded to and acted on it'll probably already be too late. (And when I say 'acted on' I mean having the account temp-globalled.)

Since all my paypal info would also be in my email account, or they would have direct access to it as a consequence of having my email address, then the chances of me ever being able to fully regain control of my account are slim to none.
  #24  
Old 10-04-2006, 12:03 AM
KuJi KuJi is offline
Banned
Join Date: Apr 2004
Location: Staten Island, New York
Posts: 2,202
KuJi will become famous soon enough
Send a message via ICQ to KuJi Send a message via AIM to KuJi Send a message via MSN to KuJi Send a message via Yahoo to KuJi
Hahaha @ Demisis.

I had all my accounts switched to one email and thats like 5-10 accounts (ask ibonic on this =P).

And recently my IP's been changing a lot aswell (ask Ibonic on that aswell =P)

Anyway.. I don't think anyones accounts even been leaked out (actual password).. it was more for security of something that MAY happen then DID happen @ Googi =o
  #25  
Old 10-04-2006, 12:03 AM
Minoc Minoc is offline
Registered User
Minoc's Avatar
Join Date: Sep 2001
Posts: 4,385
Minoc has much to be proud ofMinoc has much to be proud ofMinoc has much to be proud ofMinoc has much to be proud ofMinoc has much to be proud ofMinoc has much to be proud of
Quote:
Originally Posted by Demisis_P2P View Post
If somebody steals my Graal account by getting into my email address then they have 2 days to do whatever they want. Since password changes can only be sent every 2 days (not to mention that any smart person with access to your email account would change your email password).
How would that somebody get into your e-mail account?
__________________
-
  #26  
Old 10-04-2006, 12:03 AM
Lord Sephiroth Lord Sephiroth is offline
Babylon OG
Lord Sephiroth's Avatar
Join Date: Jan 2005
Location: Winnipeg, Manitoba, Canada
Posts: 798
Lord Sephiroth will become famous soon enough
Send a message via AIM to Lord Sephiroth
Quote:
Originally Posted by unixmad View Post
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...
There have been a lot of closed/deleted threads regarding the efficiency of the support center though. A lot of people are unhappy with the time it takes to get responses, and sometimes their tickets are just closed by a certain someone with no response what-so-ever.
__________________
Babylonian; wherever I or it may lay.
  #27  
Old 10-04-2006, 12:04 AM
MysticX2X MysticX2X is offline
Prince
MysticX2X's Avatar
Join Date: Sep 2005
Posts: 2,529
MysticX2X will become famous soon enough
Yeah i learned to remember my graal password along time ago. its real easier logging into graal
__________________
-Mystic

former acc: mystic2k


RIP Matt (NBK)
  #28  
Old 10-04-2006, 12:05 AM
Googi Googi is offline
A Serious Epidemic
Googi's Avatar
Join Date: Oct 2001
Location: Canada
Posts: 18,866
Googi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud ofGoogi has much to be proud of
Send a message via AIM to Googi
Quote:
Originally Posted by Demisis_P2P View Post
I could make a support ticket, if I remember my username and password for that, but by the time it's responded to and acted on it'll probably already be too late. (And when I say 'acted on' I mean having the account temp-globalled.)

Since all my paypal info would also be in my email account, or they would have direct access to it as a consequence of having my email address, then the chances of me ever being able to fully regain control of my account are slim to none.
The truly secure use different E-Mail addresses for everything important.
__________________
  #29  
Old 10-04-2006, 12:07 AM
Mykel Mykel is offline
:o
Mykel's Avatar
Join Date: May 2002
Location: Canton, Ohio.
Posts: 5,526
Mykel has a spectacular aura about
Send a message via AIM to Mykel Send a message via MSN to Mykel
Quote:
Originally Posted by Darlene159 View Post
Random, auto-generated passwords is a good idea anyway because too many people pick way too easy passwords, and tend to use the same password for everything, or at least several things.
There is little to no harm in someone discovering what someone's forum password is. There is a great deal of harm in finding out someone's graal password. Having the forum password be the same as the graal password only allows one additional way to hack someone's password.

And as you already said, having the same password for multiple things is a security risk.

Quote:
Originally Posted by Googi View Post
Which is why we just had to change them.
Haha, good point.

Quote:
Originally Posted by unixmad View Post
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...
If our Graal password is stolen, chances are we wouldn't find out until after something happens. As I replied to moony, having a password be the same for multiple things only increases risk. Plus, it can be a hassle too.

Once, just once, do a poll or something and actually give the players what they want.
__________________
(Married to Skyld)
  #30  
Old 10-04-2006, 12:16 AM
Demisis_P2P Demisis_P2P is offline
Kanto League Champion
Demisis_P2P's Avatar
Join Date: Jan 2005
Posts: 2,357
Demisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud of
Quote:
Originally Posted by Minoc View Post
How would that somebody get into your e-mail account?
Email addresses have lots of 'failsafes' like secret questions that can be guessed. Or they're linked to a secondary email address.
If either your primary or your secondary email address expire then they can also simply be re-registered by another person, and they would still be in the database for whatever things you signed up for with that email address.

Alternatively if you use an ISP email address and you change ISPs or move then the email address is lost, and could be re-registered by somebody else that uses that same ISP.

It's also possible for 'graal hackers' to put keyloggers or trojans into their programs and gain access to accounts that way. Of they could make a graal-related website that requires registration and do a Velox.

There are lots of possibilities.

Quote:
Originally Posted by Googi View Post
The truly secure use different E-Mail addresses for everything important.
Most people just use the one. It's more convenient (for any would-be hackers aswell, I guess). But most people just don't think about having a database leaked everytime they sign up to a website.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 11:50 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.