Ktalah
28th March 2005, 06:48 AM
With all the hackings that keep occuring I think that maybe it might be wisdom to make some improvements to the security of accounts.
The first thing I came up with was a selloff password. Basically you would have to input a password (different from your normal password) whenever you attempted to selloff weapons to a value higher than the one you picked. In example, you're a top player and you're really paranoid about being sold off. Hence you make your value for which a password is required 0. You're unlucky enough to be hacked, but they cannot sell off your armory without the password. This could be applied to vacation mode to.
You should have to input your password to change email or password, this would make javascript 'hacks' less effective. On the topic of javascript, the 'change commander' script could be countered quite efficiently by giving players a couple of hours in which they could revert to the previous commander (or lack of), and/or adding a password.
I dislike the insecurity of the password retrieval system, but I cannot immediately think of anything logical that could be done by the admins, users can simply not use free web based e-mails.
I think it's important that any enhancements are made on the basis that if anyone doesn't want to be more secure they don't have to be. Hence most of these modifications would only be prohibitive if you set them up that way.
The first thing I came up with was a selloff password. Basically you would have to input a password (different from your normal password) whenever you attempted to selloff weapons to a value higher than the one you picked. In example, you're a top player and you're really paranoid about being sold off. Hence you make your value for which a password is required 0. You're unlucky enough to be hacked, but they cannot sell off your armory without the password. This could be applied to vacation mode to.
You should have to input your password to change email or password, this would make javascript 'hacks' less effective. On the topic of javascript, the 'change commander' script could be countered quite efficiently by giving players a couple of hours in which they could revert to the previous commander (or lack of), and/or adding a password.
I dislike the insecurity of the password retrieval system, but I cannot immediately think of anything logical that could be done by the admins, users can simply not use free web based e-mails.
I think it's important that any enhancements are made on the basis that if anyone doesn't want to be more secure they don't have to be. Hence most of these modifications would only be prohibitive if you set them up that way.