![]() |
Account changes
Maybe if people want to change their account from the usual Graal###### there should be a payment in the store which allows an account name change.
Also password should be changeable. Just my thoughts. |
Won't happen. Information about your account is tied to the account name. If you change it, you lose everything everywhere because ultimately the account no longer exists by name. This is one of the reasons why community names even exist: So you can change that identifier without losing any account information.
Also, http://graalonline.com/accounts/lostpass is how you change your password. |
I worded that wrong, I meant "custom passwords" instead of like ch67AG87 ones and no that isn't my password.
And why can't the information be linked to your account in some other way, having Graal###### account's suck. It takes out the creativity. |
Quote:
As for the password thing, I would only agree to custom passwords as long as the person customising their password was forced to use a strong password. Even stronger than the current one. EG: Must include at least 1 capital, at least 1 symbol and at least 1 number and ultimately be over 8 characters long. People come up with the stupidest and most obvious passwords sometimes that it doesn't even give hackers a challenge to decrypt, if they even have to decrypt anything at all. You could just know someone well enough to know they'd be stupid enough to make their password their cat's name. |
Well I agree, the passwords should be forced to be strong.
And It would be changed by all new accounts NOT having Graal###### where as instead you should be able to specify your own; as it used to be as I believe. |
Would really like to see passwords be changable by users, but it should not cost gelats—that's just ridiculous.
Also, password strength requirements are annoying. As long as it's eight characters or so, let a user be responsible for their own account. Worrying about hackers getting passwords from the hashes is not really an issue unless the passwords database is stolen, at which time Graal should force a password reset for all users anyway. |
Quote:
In line with your desires, it would be better for them to leave the current system in place where people have the option to pick and alter their community name, BUT the Graal number (and other people's Graal numbers) needs to be absolutely hidden from existence. The only exception being for administrative requirements, something players have no need to be involved in. It all comes back to that. Something developers have been trying to get recognised for far too long. |
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.
|
Quote:
|
Quote:
Another thing is that after you paste in your password you're going to want to clear it from your clipboard so it's not sitting there waiting to be picked off. |
Quote:
|
I also wish the Graal### portion wasn't visible to the public but what I find ironic is this. Graal## people complain because they don't have a named account. Graal named accounts people complain cause they can't change their community name. All claim its unfair. The moral of this story is "The grass is always greener on the other side of the fence"
|
Quote:
|
Graal could have just followed what many other game companies do, Nexon for example. You have a Nexon ID in which you use to login then you can create characters on the actual game. The players only see your character name and not your actual account name, a lot safer in my opinion.
|
Quote:
Quote:
|
Quote:
|
I read up to the "custom passwords". I have to shake my head quickly and shout "NO". As a majority of graalians don't use the most common sence and often, you guessed it, repeat passwords. Ever wonder why people are getting hacked left and right all the time? Leaked databases, I have seen and forwarded to Graal Staff. Where people hardcore own themselves by using the same password as there email. And some people have lost everything, facebook, myspace, aim, etc.. it's just not secure at all.. Let graal gen you a password, end of story.
As for account names, about Graal#### blah blah names.. Live with it, the problem is the lack of support (from developers) for proper usage. Basically, if you don't like it ignore it because of the following ;) All account's have an account name, but not all accounts have a community name. Accounts created before Graal###, have there community name set as there account name, ex: Classic Subscription Account Test Results: (bloodpet) player.account, returns "bloodpet" player.communityname, returns "bloodpet" As far as scripting goes, ALWAYS USE ACCOUNT NAME NOT COMMUNITY... or your script can/will break. (Those accounts that have Graal###, but never bought a community name)... I don't know why people insist the Graal### names are problems, because its not a compatibility error but a human error on the developers behalf.. GRR Best solution: making Graal### invisable, and giving us a feature that is retard proof for scripters. findplayer() and findplayerbycommunityname(). People don't understand when to use them because they try using communit name's instead of account and it can't find them. It IS messy. But its not rocket science. there should be 0 complaints from anyone about the current system. |
Quote:
Quote:
|
Quote:
Quote:
If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often :p |
Solution that won't require account resets or major script modifications:
player.account stays static. No longer visible on profile. It's an identifier only. For all Graal# accounts, allow them to make a decent username on next login to the list server. That's set to communityname. For all non-Graal# accounts, set communityname to their player.account value. Display communityname on the profile. player.communityname will remain static. Forever. Seriously, what kind of MMO let's you change your username spontaneously? That's what the nickname is for. Quote:
|
Quote:
Phishing and other social engineering methods are how most Graalians are being compromised these days. A majority of graal users probably have their password email still in their inbox. Manually entering your password and not saving it is as secure as you can be. A memorized password is more secure than a password stored in your email or in a text file, and if they have their graal email they'll also have no problem getting the right password. The PC ID system is not stable either and is only going to cause further annoyance, also considering that the system has flat out broke at times eliminates any kind of trust I would have in it. On topic: The big flaws with the account system need to be fixed and our tools updated to work with it. If it was implemented and finished properly we would of never had to make stupid threads about it. |
Quote:
|
Funny thing is I've already memorized my current Graal password.
I don't even use any form of key memorization like in Dusty's comic he posted. |
Quote:
|
Quote:
|
You just need to reset your password until you get one thats all letters, attempt to pronounce the word it makes and remember your hand motions.
After you got that down the only tricky part is remembering which letters are uppercase. |
Why not just let users set their own passwords and force passwords to have 1 upper case and at least one symbol.
|
Quote:
|
Quote:
Quote:
|
I still think we should be allowed custom passwords.
Graal is the only game that I have played that insists on random jiberish as a password. |
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.
|
Quote:
Dota 2, HoN, Starcraft 2, Minecraft, (WoW and LoL, two gigantic games that i don't play) let you choose your own password. |
Quote:
|
Quote:
Edit: I should've explained: * safe in terms of brute force; doesn't really take that long anymore to brute force an eight character password, as long as the service allows enough attempts per minute. |
Quote:
If you would like to explain how I come off like a kid to you, please feel free to PM me. |
Quote:
|
Bottom line that forcing generated passwords on users forces them to store the password somewhere(usually saving the email) meaning it's actually easier to obtain than letting them choose their own and keeping the password in their head.
|
Quote:
|
The moral of this thread is, "let us choose our own password".
|
Well the new standard seems to be to generate a password, but also allow setting your own password if it meets some security level. We will probably need to add that sometime, but make it inside the game, not on website.
|
| All times are GMT +2. The time now is 11:13 PM. |
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.