Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Future Improvements (https://forums.graalonline.com/forums/forumdisplay.php?f=10)
-   -   Account changes (https://forums.graalonline.com/forums/showthread.php?t=134265811)

Gunderak 02-22-2012 09:54 AM

Account changes
 
Maybe if people want to change their account from the usual Graal###### there should be a payment in the store which allows an account name change.
Also password should be changeable.
Just my thoughts.

TSAdmin 02-22-2012 10:47 AM

Won't happen. Information about your account is tied to the account name. If you change it, you lose everything everywhere because ultimately the account no longer exists by name. This is one of the reasons why community names even exist: So you can change that identifier without losing any account information.
Also, http://graalonline.com/accounts/lostpass is how you change your password.

Gunderak 02-22-2012 11:29 AM

I worded that wrong, I meant "custom passwords" instead of like ch67AG87 ones and no that isn't my password.
And why can't the information be linked to your account in some other way, having Graal###### account's suck.
It takes out the creativity.

TSAdmin 02-22-2012 11:58 AM

Quote:

Originally Posted by Gunderak (Post 1685476)
I worded that wrong, I meant "custom passwords" instead of like ch67AG87 ones and no that isn't my password.
And why can't the information be linked to your account in some other way, having Graal###### account's suck.
It takes out the creativity.

How exactly would you change it? There is always going to be some form of identifier for accounts that you cannot change. The fact that the "Graal" numbers are even still visible is really the only problem. If you had no idea it even existed and it was never referred to as your account name (lets call it an account ID), but you still had the ability to change your community name (although we could call that your account name in the event we dont know "GraalXXXX" exists), then nothing would be different and we would be content with exactly this setup. You could still change your community name and not be any wiser of your internal account id. Basically, people's biggest issue with the "GraalXXXX" numbers is the fact that they can see them, therefore know they exist as their "real" account when in fact it's really just an identifier that shouldn't even be known about.

As for the password thing, I would only agree to custom passwords as long as the person customising their password was forced to use a strong password. Even stronger than the current one. EG: Must include at least 1 capital, at least 1 symbol and at least 1 number and ultimately be over 8 characters long. People come up with the stupidest and most obvious passwords sometimes that it doesn't even give hackers a challenge to decrypt, if they even have to decrypt anything at all. You could just know someone well enough to know they'd be stupid enough to make their password their cat's name.

Gunderak 02-22-2012 01:10 PM

Well I agree, the passwords should be forced to be strong.
And It would be changed by all new accounts NOT having Graal###### where as instead you should be able to specify your own; as it used to be as I believe.

cbk1994 02-22-2012 02:29 PM

Would really like to see passwords be changable by users, but it should not cost gelats—that's just ridiculous.

Also, password strength requirements are annoying. As long as it's eight characters or so, let a user be responsible for their own account. Worrying about hackers getting passwords from the hashes is not really an issue unless the passwords database is stolen, at which time Graal should force a password reset for all users anyway.

TSAdmin 02-22-2012 02:34 PM

Quote:

Originally Posted by Gunderak (Post 1685485)
Well I agree, the passwords should be forced to be strong.
And It would be changed by all new accounts NOT having Graal###### where as instead you should be able to specify your own; as it used to be as I believe.

But that negates your efforts to allow people to change their public identifier. You want people to be able to pick and choose their account name, but the way you want it (back to the way it used to be) once you pick it, you're stuck with it. Enter community names. Changeable at reasonable request without the disappointment of starting over because your identifier has changed. The only thing wrong with the current system is the fact that people are being told to upgrade before they are allowed to choose a name which has lead to problems like their Graal#### identifier being public by default.

In line with your desires, it would be better for them to leave the current system in place where people have the option to pick and alter their community name, BUT the Graal number (and other people's Graal numbers) needs to be absolutely hidden from existence. The only exception being for administrative requirements, something players have no need to be involved in. It all comes back to that. Something developers have been trying to get recognised for far too long.

BlueMelon 02-22-2012 07:33 PM

Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.

Crow 02-22-2012 07:46 PM

Quote:

Originally Posted by BlueMelon (Post 1685522)
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.

I'm assuming that Graal also stores them when they couldn't be used successfully. Therefore, you can easily get the encrypted version for every password. One could probably write a script to brute force that. I suppose using a key logger would be a little easier though :p

fowlplay4 02-22-2012 07:57 PM

Quote:

Originally Posted by BlueMelon (Post 1685522)
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.

It could just wait for you to open Graal and steal the password from there. Your email and other accounts are likely to get hijacked before they take your Graal account via a key-logger, especially if you keep the password email there.

Another thing is that after you paste in your password you're going to want to clear it from your clipboard so it's not sitting there waiting to be picked off.

Demisis_P2P 02-22-2012 09:12 PM

Quote:

Originally Posted by TSAdmin (Post 1685478)
How exactly would you change it? There is always going to be some form of identifier for accounts that you cannot change. The fact that the "Graal" numbers are even still visible is really the only problem. If you had no idea it even existed and it was never referred to as your account name (lets call it an account ID), but you still had the ability to change your community name (although we could call that your account name in the event we dont know "GraalXXXX" exists), then nothing would be different and we would be content with exactly this setup. You could still change your community name and not be any wiser of your internal account id. Basically, people's biggest issue with the "GraalXXXX" numbers is the fact that they can see them, therefore know they exist as their "real" account when in fact it's really just an identifier that shouldn't even be known about.

Yeah, community names weren't a bad idea, but they really screwed up the implementation of it something shocking.

Bell 02-22-2012 09:52 PM

I also wish the Graal### portion wasn't visible to the public but what I find ironic is this. Graal## people complain because they don't have a named account. Graal named accounts people complain cause they can't change their community name. All claim its unfair. The moral of this story is "The grass is always greener on the other side of the fence"

Crono 02-22-2012 10:33 PM

Quote:

Originally Posted by Bell (Post 1685542)
I also wish the Graal### portion wasn't visible to the public but what I find ironic is this. Graal## people complain because they don't have a named account. Graal named accounts people complain cause they can't change their community name. All claim its unfair. The moral of this story is "The grass is always greener on the other side of the fence"

nop, just do rufus' idea and everything would be solved. never seen a game have so many problems with fundamental crap

Unkownsoldier 02-23-2012 12:02 AM

Graal could have just followed what many other game companies do, Nexon for example. You have a Nexon ID in which you use to login then you can create characters on the actual game. The players only see your character name and not your actual account name, a lot safer in my opinion.

cbk1994 02-23-2012 12:46 AM

Quote:

Originally Posted by Crono (Post 1685546)
nop, just do rufus' idea and everything would be solved. never seen a game have so many problems with fundamental crap

What is Rufus' idea? If you mean the one he had for giving all players a Graal### account, it's just not possible.

Quote:

Originally Posted by Demisis_P2P (Post 1685538)
Yeah, community names weren't a bad idea, but they really screwed up the implementation of it something shocking.

This really was (and still is) the largest problem. It took years to get support for them in RC, and the publicly released RC still doesn't support them. There's also no scripting functions for getting the cname of an account (and vica-versa).

Crono 02-23-2012 12:49 AM

Quote:

Originally Posted by cbk1994 (Post 1685562)
What is Rufus' idea? If you mean the one he had for giving all players a Graal### account, it's just not possible.

completely hide graal#### from users and have it only display their community names.

scriptless 02-23-2012 01:45 AM

I read up to the "custom passwords". I have to shake my head quickly and shout "NO". As a majority of graalians don't use the most common sence and often, you guessed it, repeat passwords. Ever wonder why people are getting hacked left and right all the time? Leaked databases, I have seen and forwarded to Graal Staff. Where people hardcore own themselves by using the same password as there email. And some people have lost everything, facebook, myspace, aim, etc.. it's just not secure at all.. Let graal gen you a password, end of story.

As for account names, about Graal#### blah blah names.. Live with it, the problem is the lack of support (from developers) for proper usage. Basically, if you don't like it ignore it because of the following ;)

All account's have an account name, but not all accounts have a community name. Accounts created before Graal###, have there community name set as there account name, ex:

Classic Subscription Account Test Results: (bloodpet)
player.account, returns "bloodpet"
player.communityname, returns "bloodpet"

As far as scripting goes, ALWAYS USE ACCOUNT NAME NOT COMMUNITY... or your script can/will break. (Those accounts that have Graal###, but never bought a community name)...

I don't know why people insist the Graal### names are problems, because its not a compatibility error but a human error on the developers behalf.. GRR


Best solution:
making Graal### invisable, and giving us a feature that is retard proof for scripters.

findplayer() and findplayerbycommunityname(). People don't understand when to use them because they try using communit name's instead of account and it can't find them. It IS messy. But its not rocket science. there should be 0 complaints from anyone about the current system.

cbk1994 02-23-2012 03:01 AM

Quote:

Originally Posted by scriptless (Post 1685570)
I read up to the "custom passwords". I have to shake my head quickly and shout "NO". As a majority of graalians don't use the most common sence and often, you guessed it, repeat passwords. Ever wonder why people are getting hacked left and right all the time? Leaked databases, I have seen and forwarded to Graal Staff. Where people hardcore own themselves by using the same password as there email. And some people have lost everything, facebook, myspace, aim, etc.. it's just not secure at all.. Let graal gen you a password, end of story.

This is nonsense. Let players be responsible for their own accounts. We don't need to be protecting people from their own stupidity, even those who lack common "sence". Very few other services insist on randomly generating passwords. Making it harder to login to your account is not a good way to retain players.

Quote:

findplayer() and findplayerbycommunityname(). People don't understand when to use them because they try using communit name's instead of account and it can't find them. It IS messy. But its not rocket science. there should be 0 complaints from anyone about the current system.
We are lacking functions to convert between account and commityname, there is still a bug with communityname (which is empty if one has not been chosen; it should instead be the account), and the released Windows RC (which most developers use) does not support community names in the playerlist.

BlueMelon 02-23-2012 03:02 AM

Quote:

Originally Posted by Crow (Post 1685523)
I'm assuming that Graal also stores them when they couldn't be used successfully. Therefore, you can easily get the encrypted version for every password. One could probably write a script to brute force that. I suppose using a key logger would be a little easier though :p

Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.

Quote:

Originally Posted by fowlplay4 (Post 1685526)
It could just wait for you to open Graal and steal the password from there. Your email and other accounts are likely to get hijacked before they take your Graal account via a key-logger, especially if you keep the password email there.

Another thing is that after you paste in your password you're going to want to clear it from your clipboard so it's not sitting there waiting to be picked off.

Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often :p

Hezzy002 02-23-2012 05:55 AM

Solution that won't require account resets or major script modifications:

player.account stays static. No longer visible on profile. It's an identifier only.

For all Graal# accounts, allow them to make a decent username on next login to the list server. That's set to communityname.

For all non-Graal# accounts, set communityname to their player.account value.

Display communityname on the profile.

player.communityname will remain static. Forever. Seriously, what kind of MMO let's you change your username spontaneously? That's what the nickname is for.

Quote:

Originally Posted by BlueMelon (Post 1685579)
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.



Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often :p

Myself being a real programmer, I'm going to call you out, just based on this post, your name, your signature, and avatar, that you're one of those annoying kids.

fowlplay4 02-23-2012 06:19 AM

Quote:

Originally Posted by BlueMelon (Post 1685579)
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.

Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often :p

When people talk about Keyloggers they aren't referring to the literal act of logging your keystrokes and sending them to you. They're referring to malicious RATs.

Phishing and other social engineering methods are how most Graalians are being compromised these days. A majority of graal users probably have their password email still in their inbox.

Manually entering your password and not saving it is as secure as you can be. A memorized password is more secure than a password stored in your email or in a text file, and if they have their graal email they'll also have no problem getting the right password.

The PC ID system is not stable either and is only going to cause further annoyance, also considering that the system has flat out broke at times eliminates any kind of trust I would have in it.

On topic:

The big flaws with the account system need to be fixed and our tools updated to work with it. If it was implemented and finished properly we would of never had to make stupid threads about it.

DustyPorViva 02-23-2012 06:22 AM

Quote:

Originally Posted by cbk1994 (Post 1685495)
Would really like to see passwords be changable by users, but it should not cost gelats—that's just ridiculous.

Also, password strength requirements are annoying. As long as it's eight characters or so, let a user be responsible for their own account. Worrying about hackers getting passwords from the hashes is not really an issue unless the passwords database is stolen, at which time Graal should force a password reset for all users anyway.

http://imgs.xkcd.com/comics/password_strength.png

Fulg0reSama 02-23-2012 06:25 AM

Funny thing is I've already memorized my current Graal password.

I don't even use any form of key memorization like in Dusty's comic he posted.

DustyPorViva 02-23-2012 06:29 AM

Quote:

Originally Posted by Fulg0reSama (Post 1685627)
Funny thing is I've already memorized my current Graal password.

I don't even use any form of key memorization like in Dusty's comic he posted.

I still remember my password for my Graal account that is 13 years-old because it's a custom-defined password. However I still don't know my password for my current account(that I've had for 9+ years) because it's a generated assortments of letters and numbers that is just beyond memorizing(for me, personally).

Fulg0reSama 02-23-2012 06:38 AM

Quote:

Originally Posted by DustyPorViva (Post 1685628)
I still remember my password for my Graal account that is 13 years-old because it's a custom-defined password. However I still don't know my password for my current account(that I've had for 9+ years) because it's a generated assortments of letters and numbers that is just beyond memorizing(for me, personally).

Yeah, mine isn't custom defined, I accidentally resetted mine sometime ago :C

fowlplay4 02-23-2012 06:51 AM

You just need to reset your password until you get one thats all letters, attempt to pronounce the word it makes and remember your hand motions.

After you got that down the only tricky part is remembering which letters are uppercase.

Gunderak 02-23-2012 07:07 AM

Why not just let users set their own passwords and force passwords to have 1 upper case and at least one symbol.

DustyPorViva 02-23-2012 07:17 AM

Quote:

Originally Posted by Gunderak (Post 1685634)
Why not just let users set their own passwords and force passwords to have 1 upper case and at least one symbol.

Forcing symbols and crap like that does nothing to improve the security of a password in most cases and only makes it harder to remember for some people to remember, especially since these requirements vary from one site to the next.

Crow 02-23-2012 09:10 AM

Quote:

Originally Posted by BlueMelon (Post 1685579)
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.

Most keyloggers don't only check typed keys anymore. Many also capture the current clipboard if there's text in it, and some go through obvious password fields in your web browser and copy the contents. Like it's been said, it could just read it from memory.


Quote:

Originally Posted by Gunderak (Post 1685634)
force passwords to have 1 upper case and at least one symbol.

Unnecessary. Additional possible characters does not make your password more secure.

Gunderak 02-23-2012 11:43 AM

I still think we should be allowed custom passwords.
Graal is the only game that I have played that insists on random jiberish as a password.

Emera 02-23-2012 06:25 PM

A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.

Crono 02-23-2012 06:53 PM

Quote:

Originally Posted by Emera (Post 1685696)
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.

I play popular games and all of them let you choose your own password.

Dota 2, HoN, Starcraft 2, Minecraft, (WoW and LoL, two gigantic games that i don't play) let you choose your own password.

xXziroXx 02-23-2012 07:04 PM

Quote:

Originally Posted by Emera (Post 1685696)
A lot of on-line games use this method as a means to keep accounts safe

No, they really don't. I play an extreme amount of online games that surface on the market, and the ONLY things that pestered me about passwords have been Graal and EVE Online, but at least the latter let me chose my own one but with some restrictions.

Crow 02-23-2012 07:13 PM

Quote:

Originally Posted by Emera (Post 1685696)
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.

Eight character passwords are not safe* anymore, and it's been like that for quite a while. It's generally one of the worst ideas to not let customers choose their own passwords.

Edit: I should've explained:
* safe in terms of brute force; doesn't really take that long anymore to brute force an eight character password, as long as the service allows enough attempts per minute.

BlueMelon 02-24-2012 02:01 AM

Quote:

Originally Posted by Hezzy002 (Post 1685619)
Myself being a real programmer, I'm going to call you out, just based on this post, your name, your signature, and avatar, that you're one of those annoying kids.

Calling me out? My knowledge in the field of computer security and programming are quite vast. With over 4 years of experience, I know what I'm talking about when it comes to malicious software. When people say "keylogger" I think of the literal meaning. Yes, I know software now days can log and steal just about whatever but they are no longer called keyloggers they are called a multi-logger or account/information stealer.

If you would like to explain how I come off like a kid to you, please feel free to PM me.

Mark Sir Link 02-24-2012 03:43 AM

Quote:

Originally Posted by Emera (Post 1685696)
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.

lmao wat

DustyPorViva 02-24-2012 04:36 AM

Bottom line that forcing generated passwords on users forces them to store the password somewhere(usually saving the email) meaning it's actually easier to obtain than letting them choose their own and keeping the password in their head.

DARKVILLIN 02-24-2012 06:45 AM

Quote:

Originally Posted by DustyPorViva (Post 1685756)
Bottom line that forcing generated passwords on users forces them to store the password somewhere(usually saving the email) meaning it's actually easier to obtain than letting them choose their own and keeping the password in their head.

^This is True...

Gunderak 02-24-2012 09:00 AM

The moral of this thread is, "let us choose our own password".

Admins 02-25-2012 02:02 PM

Well the new standard seems to be to generate a password, but also allow setting your own password if it meets some security level. We will probably need to add that sometime, but make it inside the game, not on website.


All times are GMT +2. The time now is 11:13 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.