Dev Blog: Security: Different times - Different ways

I was suggesting that a permanent removal of skill point transfer privileges, accompany a three day ban.

1 Like

The guy who made the password format publicly stated that he regrets making such recommendations, especially the “change you password every 30 days” part which contributed nothing towards the security of the accounts.

1 Like

That would certainly work better than just a 3 day suspension.

Still waiting on CCP to respond whether they confiscate assets gained via illegal activities.

Would help prevent account hijacking, in the long run.
I dont see how it would prevent botting.
Im unsure how effectively CCP can use 2FA to identify repeat offenders, regarding data confidentiality.

The 30 day wait, however, does nothing practical:

  • True new players have no SP to extract anyways.
  • Existing accounts will just have to wait 30 days, once, after enabling 2FA.

Incentivizing 2FA either by carrot or stick, is an option to consider to prevent account hijacking, if its really as wide spread as CCP seems to indicate.

Well, those boots that i meet last Time where very frendly. As long as they dont steal an accounts, meeting with them could be a quite unique feeling :stuck_out_tongue_winking_eye:

This would be important, yes, cos otherwise first offence botters will just strip-mine the account/character and start all over again.

Still waiting on confirmation that value won by botting will be investigated and confiscated.

If CCP is not confiscating ISK gained from botting (and the ISK value of minerals obtained by using mining bots), that would be a change in the procedures that were put in place in March 2012. Here’s the dev blog where it was announced.

1 Like

Yes it would.

But 2012 vs 2018…

Now they reduced suspension for botting to 3 days…

Despite my questions, there has been no confirmation CCP is still following this policy.

Damn, I got trolled. You got me!

I personally don´t understand social behavior or most of it due to being different as my wife likes to say or close to be an autistic person as my doc says so excuse my lack of understanding but you are aware of the fact that even CEOs and COFs are commonly undermining my security advises on a daily basis because of “too inconvenient”? The “security community” advertises stuff like passphrases not passwords and pgp mailing for decades now yet people say “it´s too inconvenient to use it” when it´s simply not. In EvE you lose you account (worst case) in the real world you lose your company or millions and yet people go full social pron on facebook, using passwords a 12years can crack in 5minutes and/or putting it on a post it under their keyboard.

There you are totally wrong.

First, I won´t call it “hacking into someones account” because you simply need to be a “script kiddy” to do so. Hijacking accounts where huge back in the World of Warcraft high times. Teenagers with barely any knowledge about hacking at all used simple tools to break into accounts and sell them after.
7/10 people - personal experience and actual studies - use passwords that won´t withstand a simple brutforce attack. Getting the email is easy, getting the tools is even easier so breaking into someones account is no magic at all. 2FA is a simple thing and while it won´t protect your account with that poor password it helps a lot to get rid of the most stupid script kiddies. But as long as people use 5+ accounts, safe the login data and don´t use 2FA, account hijacking will be as easy as stealing a lolly from a toddler. Now that EvE accounts are actually worth a lot thanks to skill extractors, skill injectors and the ever growing RMT market, I´d assume it became lucrative in some countries to hijack accounts and make some good income.
To this day Blizzard is the only company that has a somewhat forced security policy and I know a lot of people who are still pissed about that. And while I encourage more security, it´s always the user who is the weak link. Easy to guess passwords, no separated mail accounts for important things, using bookmarks for important sites like eve account management, online banking and whatnot makes it super easy for the “dark side” to steal your ■■■■.

Wrong where?
Wrong about what exactly?

Still trying to flame people I see?
How unexpected /s

Who are you talking to?

You got your answer (lol)

What is this supposed to mean?

Do you consider asking someone where/how one is “totally wrong” as they claim, to be flaming?
Do you consider me asking you whom you are referring to, to be flaming?

Wtf are you on about?

You know, when people answer your questions in the last post they made, it makes you look lIke an hypocrite who will only accept the answers he wants.

Same thing as in the Should I resub thread and many others before. Lmao

image

4 Likes

Is CCP already checking passwords against known passwords?

Does not work if your language is not English or you have problems translating your own language to English.
Other than that i agree.

I got an answer, but no to any of my questions.
An answer to a query, must follow the syntax of the query, to be valid.
His did not.