Graal Forums  

Go Back   Graal Forums > Development Forums > Future Improvements
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 11-09-2005, 10:44 PM
Gambet Gambet is offline
Registered User
Join Date: Oct 2003
Posts: 2,712
Gambet is on a distinguished road
Internet Protocol Security

I believe, to make it impossible for one to steal anothers account, that Graal should use an Internet Protocol (IP) security system in which when you log on the client with your account, your IP is saved and the game will ask you to give a security password for your account, and only that IP can access the account from then on, unless you input the security password. Basically, what will happen is that whenever you log into client, your IP is scanned, and if it matches the one that was registered into the client, then you will be able to use that account as you normally would. If the IP does NOT match, then a box should come out in which it will ask you to type in the security password that you inputed upon registering your computer IP (meaning the password that was asked of you to input when you first logged onto the account while the system is in affect). After putting in the security password, whatever IP the computer you are using currently has, will then override the previous IP saved by the account and you will have full access to the account as you normally would. Of course, if you have not yet registered your IP to your account, then upon logging into your account, you will be asked to write up a security password that you will be able to use to access your account if the IP that the client will save does not match the IP of which a computer that you use in the future may have. This would work for users both with static IP's and those without static IP's, or simply those that use different computers to play Graal. This will completely prevent users from ever getting into ones account, unless of course someone is foolish enough to reveal their security password.


If you want to get even more technical, then instead of registering your own security password, it would be even more protection if Graal gave you a password instead (like the passwords it gives you upon registration). With this security password that Graal gives you, each time you use it, whether the IP matches or not, you will be able to gain access to the account.

NOTE: The IP that the client recognizes as yours for a specific account will only change if you are trying to log in with a different IP and you have to use the security password to log in.


Also, to prevent users from forgetting their security password, it would be nice if the client displayed a users security password in the interface or so as a reminder. To prevent account stealers from stealing a users security password, I believe that their should not be an email function in which you can request your password by email, since account stealers will try to hack into your email account and take your password.


Questions? Comments? Please, don't be shy. Just remember that I can only post once every eight hours.


EDIT:
For the two posts below mines: I believe that their should be as much security as possible. If you find it annoying to have to type in a simple password, then you shouldn't complain if your account was ever accessed into. Those that complain about this based on laziness do not deserve any help when they are in a situation where someone has hacked into their account. Although people are secure or think they are secure, ANYTHING CAN HAPPEN. I mean, just take this whole Velox thing as an example. You never know what people are going to try to do to gain access into your account. It's always nice to have extra security preventing users from getting into your account. Also, just because one manages to steal your account password does NOT mean they will manage to take your security password. Stealing one thing is not the same as stealing two. By being secure and having this system in full function, you will NEVER have a problem with someone getting into your account for as long as you play Graal.

Last edited by Gambet; 11-09-2005 at 11:10 PM..
Reply With Quote
  #2  
Old 11-09-2005, 10:57 PM
petro1212 petro1212 is offline
Angelus
petro1212's Avatar
Join Date: Mar 2003
Location: The Moon
Posts: 445
petro1212 is on a distinguished road
Send a message via AIM to petro1212 Send a message via MSN to petro1212
No offense gambet but this just a whole bunch of extra work. I for one have an IP that changes on a regular basis and I would hate to remember extra passwords.

Ontop of that if you don't want your account to be "stolen" or something like that. Change your password on regular basis and use unique passwords such as x34PDEzE3 ect.

Above all people should keep their anti viral programs up to date and preform scans on a regular basis.



Your idea is good but not so practical. The value of an account isn't so great and if you would follow guide lines your account(s) will never get stolen.

Incase someone else manages to obtain your password simply make a helpdesk ticket. It ain't that hard :S

Your idea would be lovely for people who love to share their password with their friends but not for the people who are secure about their accounts.
__________________
Reply With Quote
  #3  
Old 11-09-2005, 10:58 PM
Fry Fry is offline
Registered User
Fry's Avatar
Join Date: Sep 2001
Location: Germany
Posts: 384
Fry has a spectacular aura about
Please explain to me in what way this has any use besides annoying users who have a dynamic IP? What will happen if one of these evil "hackers" acquires both your passwords? Usually, if people get access to one password, they can also easily access the other. Please, explain.
__________________
Graal Statistics

Top 3 servers at the moment (players):


Reply With Quote
  #4  
Old 11-09-2005, 11:44 PM
Zero Hour Zero Hour is offline
Stiff Upper Lip
Zero Hour's Avatar
Join Date: Oct 2006
Location: Nova Scotia, Canada
Posts: 0
Zero Hour is on a distinguished road
Send a message via AIM to Zero Hour
Quote:
Originally Posted by Fry
Usually, if people get access to one password, they can also easily access the other.
Indeed.
__________________
Reply With Quote
  #5  
Old 11-09-2005, 11:59 PM
Dach Dach is offline
call me Chad, it's cooler
Dach's Avatar
Join Date: Aug 2002
Posts: 1,899
Dach is on a distinguished road
So, what you're saying is, we should have a password?
__________________
Scripting Documents:Old Script Documentation-Movement Tutorial
Reply With Quote
  #6  
Old 11-10-2005, 12:02 AM
Mykel Mykel is offline
:o
Mykel's Avatar
Join Date: May 2002
Location: Canton, Ohio.
Posts: 5,526
Mykel has a spectacular aura about
Send a message via AIM to Mykel Send a message via MSN to Mykel
Quote:
Originally Posted by Dach
So, what you're saying is, we should have a password?
It's the way of the future.
__________________
(Married to Skyld)
Reply With Quote
  #7  
Old 11-10-2005, 12:19 AM
GrowlZ1010 GrowlZ1010 is offline
defunct
Join Date: May 2002
Posts: 187
GrowlZ1010 is on a distinguished road
Firstly, I assume you mean the IP address, since we wouldn't get much uniqueness if we assign every player the identifier "4" (or 6, but let's not go into that). Clarity is everything!

Secondly, IP addresses are not intended for authentication and certainly aren't tied to an individual computer, so let's not pretend that they are. Users with dial-up or even many kinds of residential DSL will be assigned addresses randomly from a pool of available ones; if they have to type in a password every time they reconnect, they'll not only be annoyed, but they'll also make the password as easy to remember as possible - maybe the same password, maybe the email address, maybe the username with some numbers appended, whatever - which kinda negates the security of such a scheme. (If you'd proposed some kind of psuedo-unique hardware-based hash featuring MAC addresses, or installed devices, or some other exotic combination, then maybe, but the IP just isn't good enough.)

Thirdly, there's not much GraalOnline can realistically do if you're prepared to type in all your passwords and details into third-party websites. If you're really determined to give your account away to someone, you will, no matter how many hurdles are thrown in your way, and disabling useful functionality because it might be misused is a bad idea.

The internet is a dangerous place full of electronical muggers and cyber banditos, but as long as you exercise some basic common sense - your car key isn't the same as your front door key, back door key, garage key, bank vault key, and Fred's Super Honest Happy Budget No-Fraud Credit Discount Emporium account key, is it? Do you make a habit of giving complete strangers your home address and duplicates of your keys? - and only hand out your details when you absolutely have to, you'll be fine.
Reply With Quote
  #8  
Old 11-10-2005, 12:28 AM
Shiftk03- Shiftk03- is offline
I am the trap
Shiftk03-'s Avatar
Join Date: Nov 2001
Location: Dirty South
Posts: 1,688
Shiftk03- will become famous soon enough
Yeah. I have residential DSL and my IP changes with each connection. That would just annoy the hell out of me, forcing me to quit Graal all together. Also: Hunky Doo Diddlysplat kazoo woohoo
__________________
Reply With Quote
  #9  
Old 11-10-2005, 01:55 AM
Mark Sir Link Mark Sir Link is offline
Kevin Azite
Mark Sir Link's Avatar
Join Date: Sep 2005
Posts: 1,489
Mark Sir Link is just really niceMark Sir Link is just really nice
Send a message via AIM to Mark Sir Link
Quote:
Originally Posted by Shiftk03-
Also: Hunky Doo Diddlysplat kazoo woohoo
amen.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 04:00 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.