Fed up with account "security"

3 pages Page 1
shinta_himura
shinta_himura
Lion's Arch Merchant
#1
Ok, you know what, I've had it!

If Arena Net cared about account security don't you think we'd have something a bit better than "8-13 Alpha Numeric Only" passwords? I mean what is the issue with these people?

I would love to have a secure password but your primitive password system DOESN'T ALLOW IT.

Plenty of other places allow MUCH MORE than 13 freaking characters, AND they allow symbols. WHAT is your problem?? All of that money you're raking in from your cash shop and you still can't afford to host passwords longer than 13 characters?

I'm tired of seeing these weekly security warnings, logging in to see if they've done anything legitimate to help the problem, and seeing NOTHING.

13 Characters, alpha-numeric only, give me a damn break.
F
Fay Vert
Desert Nomad
#2
13 character alpha numeric is not a problem compared to the real weaknesses in the system. Unfortunatley, the biggest weakness doesn't lie with ANet. What use is stonger passwords when many people choose 1234?

Having said that, ANet should do a lot more for account protection. Thye can start by allowing you to specify non-deletable (time locked) characters and items.
makosi
makosi
Grotto Attendant
#3
A method of 'locking' your GW account to your own particular computer would be great. Also, a temporary account lock for frequent wrong password attempts would prevent brute forcing.
Aycee
Aycee
Lion's Arch Merchant
#4
Oh gosh rager in the building. There is literally probably over a million different pass combinations you can make using 13 alpha numeric. Passwords aren't the problem.
subman247
subman247
Academy Page
#5
Really?! Your crying because of password length? Dont use the same password for multiple things and be smart with what you do online. If your not stupid or terribly unlucky you have a much better chance of not being a target. Iv played 6 years and never had a single scare. In this day and age of major hacking if the right person really wanted you acRED ENGINE GORED ENGINE GORED ENGINE GORED ENGINE GO they would get it. If the FBI, CIA and Sony can be hacked there is nothing A-net can do to provide 100% security. Cross your fingers and hope for the best

lol I have no idea why that was RED ENGINED.
Del
Del
Desert Nomad
#6
OP, you can make a strong password with alphanumeric and limited chars, the weekness generally comes from people using actual words in their passwords, which makes them easier for bruteforce programs. Randomizing lowercase and capital letters, aw well as mixing it all up with numbers alone is very strong. the problem is security breaches here and in ncsoft's sites. Many people use the same password for everything, so stealing info for this site generally helps hackers steal accounts more effectively than bruteforcing.

Quote:
Originally Posted by subman247 View Post
lol I have no idea why that was RED ENGINED.
You probably accidentally typed "acc unt"
LifeInfusion
LifeInfusion
Grotto Attendant
#7
biggest problem always has been NCSoft Master accounts, fake account emails claiming to be from NCsoft, and people using crappy passwords (or ones they use EVERYWHERE).

It's not a bank you know, you don't need more than 13 alphanumeric with capitals and lowercase.

Not like you need something more than
SvCN2iTYeIN5Y
shOSN8HO85mpV
T36d84Rso51N6
ddL5djPoS7aC1
To6bHdQdGQ9eK
pj7kG1PIY24p9

I'd like ! or $ to be usable too, but that's wishful thinking.

Ironically a strong password is supposed to be 15+ characters and has symbols, such as ` ! " ? $ ? % ^ & * ( ) _ - + = { [ } ] : ; @ ' ~ # | \ < , > . ? /
End
End
Forge Runner
#8
Quote:
Originally Posted by Aycee View Post
There is literally probably over a million different pass combinations you can make using 13 alpha numeric.
62^13 or 200,028,539,268,669,788,905,472


now take into account that after a few password attempts it starts taking longer and longer (assumed purposely) to check the password this last attempt took like 10 seconds...

Sooo because of this lets take 5 seconds and be nice... say that after the first few they can only make one attempt every 5 seconds that means it will take
277817415650930262368.7 hours or 11575725652122094265.4 days orrrr 31714316855129025.4 years

(just a thought I'd have better luck with a 4 number pin number that most debit/credit cards are bound to with only 10,000 possibilities)



feel free to correct me if my math was wrong I have a horribad headache atm.

Anet actually does a great job preventing this type of attack and I like the way the time keeps adding up each time you try to log in (btw this last fake attempt=30 seconds...all while my other account on the same pc is doing fine .


Sooo yes while their allowed passwords may be limited. They have implemented shit to keep it from getting hit with a brute force attack.
There is ofc course the possibility of using a botnet for it...but that still won't be very efficient i dont believe.


The main issue is the ncmaster accounts.
deluxe
deluxe
Desert Nomad
#9
I think all these account hacks have very little to do with brute force password cracking, but some kind of bug in the ncsoft website.
My account got hacked, my password got changed...
How in gods name is it possible to change a password without me getting a confirmation email about it?
Chrisworld
Chrisworld
Krytan Explorer
#10
I've rules out keyloggers too.
Lishy
Lishy
Forge Runner
#11
How can you even get hacked if you change your account to use a fresh email? Definitely a flaw with NCSoft, perhaps?

If not, then it must be keyloggers. But for those with protected systems, linux, and who don't use suspicious programs...????
Xenex Xclame
Xenex Xclame
Desert Nomad
#12
So what's with all this whining, did OP use a simple password like "password" and got hacked?

Account security on the login side is good enough.Not only do you need the 13 digit password, which like end has posted is going to take along time to guess.

You also need the login name, so as long as your not stupid enough to use the same email for msn/forums will add another amazingly long time to guess.

You also need the character name, which in reality isn't hard to find, but you still have to find a login and password to fit with the character name.

So let's say I wanted to ai and attack one person, I might be able to find out his email since he uses it for MSN too and his character name because I played with him, or seen screens of his character,I would still need to break his password.

Yes having symbols added to possible character allowed in password would increase password security, but its not like the way it is now is a simple 1-2-3 step thing.



And all this is forgetting that the way most people get "hacked" is by giving the "hacker" info unknowingly or knowingly, thinking that person is trustworthy.No amount of character and symbols will help against people just being dumb.
Porkchop Sandwhiches
Porkchop Sandwhiches
Lion's Arch Merchant
#13
I just want a different method than using my email address as my login, is that so hard to ask?
Xenex Xclame
Xenex Xclame
Desert Nomad
#14
Quote:
Originally Posted by Porkchop Sandwhiches View Post
I just want a different method than using my email address as my login, is that so hard to ask?

Ugh so do I.It seemed convenient when GW came out since I wouldn't have to remember another login, I dunno why, but even so I didn't use a email address that I used for something else.
Reverend Dr
Reverend Dr
Forge Runner
#15
Quote:
Originally Posted by shinta_himura View Post
"Alpha Numeric Only" passwords?
This is a terrible horrible thing. I laugh at every website that refuses to allow symbols in passwords.

Alpha Numeric for names is understandable but not allowing it for passwords only reduces security. There is a reason that strong password generators default to giving passwords with symbols included.

Now none of this is really seems like it is going to really affect the largest GW security issues (this is speculation), but there is still no reason for alpha numeric only passwords ever.
Reformed
Reformed
Jungle Guide
#16
Quote:
Originally Posted by Lishy View Post
How can you even get hacked if you change your account to use a fresh email? Definitely a flaw with NCSoft, perhaps?

If not, then it must be keyloggers. But for those with protected systems, linux, and who don't use suspicious programs...????
If I was selling gold through a website the very first thing I'd check to potentially compromise an account would be to throw in the same credentials they used during registration. In other words...a valid email address, a password (both of which may or may not have been reused) and a character name which they would need for delivery.

While I don't rule out NCSoft liability the simplest explanation is that the victim gave out the info to 'friends' and forgot or unwittingly revealed it to others by being careless.
Skyy High
Skyy High
Furnace Stoker
#17
Quote:
Originally Posted by shinta_himura View Post
Ok, you know what, I've had it!

If Arena Net cared about account security don't you think we'd have something a bit better than "8-13 Alpha Numeric Only" passwords? I mean what is the issue with these people?
lolwut?

My password isn't alpha numeric.

Quality thread.
C
Chthon
Grotto Attendant
#18
Quote:
Originally Posted by Skyy High View Post
lolwut?

My password isn't alpha numeric.

Quality thread.
Once bonded to a damned NCMA account, your GW password can only be changed through the NCMA account. While GW supports symbols in passwords, the NCMA feature to set the GW password only allows alpha-numeric. Just one more example of needlessly shitty "security" forced on GW by NCSoft.
X
Ximvotn
Banned
#19
I like a password I can actually remember, 1 numeral is fine, if you're that nervous about your account then use a virtual keyboard.
Verene
Verene
Furnace Stoker
#20
Quote:
Originally Posted by Chthon View Post
Once bonded to a damned NCMA account, your GW password can only be changed through the NCMA account. While GW supports symbols in passwords, the NCMA feature to set the GW password only allows alpha-numeric. Just one more example of needlessly shitty "security" forced on GW by NCSoft.
Really?

Cos my account is linked to a NCMA, and I've changed my password in the game itself before...

(and yes, it was after they were linked)