Graal Forums

Graal Forums (https://forums.graalonline.com/forums/index.php)
-   Graal Main Forum (English) (https://forums.graalonline.com/forums/forumdisplay.php?f=4)
-   -   ::READ:: IMPORTANT INFO regarding your forum password (https://forums.graalonline.com/forums/showthread.php?t=69141)

unixmad 10-03-2006 08:58 PM

::READ:: IMPORTANT INFO regarding your forum password
 
To log on forums you now need to use your graal password, it mean that if you change your graal password it will also change your forum password.

MysticX2X 10-03-2006 09:01 PM

oh what a relief. I was just thinking that my forum password was stolen.

bgumeny 10-03-2006 09:03 PM

As was I.

Minoc 10-03-2006 09:05 PM

Goodie, easier to recover.

Mykel 10-03-2006 09:05 PM

Quote:

Originally Posted by unixmad (Post 1225528)
To log on forums you now need to use your graal password, it mean that if you change your graal password it will also change your forum password.

x_x

I liked it when you could have a different password. :cry:

Damix2 10-03-2006 09:12 PM

Well damnit thats annoying.

Moondeath_2 10-03-2006 09:12 PM

Quote:

Originally Posted by Mykel (Post 1225538)
x_x

I liked it when you could have a different password. :cry:

I did too it's easier to remember other passwords instead of computer generated passwords. :\

zephirot 10-03-2006 09:13 PM

Gah.

Magadal 10-03-2006 09:19 PM

So I cant use my 12 character pw now?:(

Rufus 10-03-2006 09:20 PM

Hmm, this means if I want to log into the forums elsewhere I'd have to go through my e-mails, look for my Graal password as I've still not got the hang of it.

Moondeath_2 10-03-2006 09:23 PM

Quote:

Originally Posted by Rufus (Post 1225557)
Hmm, this means if I want to log into the forums elsewhere I'd have to go through my e-mails, look for my Graal password as I've still not got the hang of it.

Same here. :D

WanDaMan 10-03-2006 09:24 PM

True. I'm not a fan of this movement.

Sam 10-03-2006 09:34 PM

Quote:

Originally Posted by Rufus (Post 1225557)
Hmm, this means if I want to log into the forums elsewhere I'd have to go through my e-mails, look for my Graal password as I've still not got the hang of it.

Learn it by heart. Btw: its a bad choice to left it in you e-mail account. The past showed us that stolen accounts where the results of hacked e-mai passwords.

Rufus 10-03-2006 09:35 PM

Quote:

Originally Posted by Sam (Post 1225569)
Learn it by heart. Btw: its a bad choice to left it in you e-mail account. The past showed us that stolen accounts where the results of hacked e-mai passwords.

They can only get into your e-mail if they know your e-mail address.

Mykel 10-03-2006 09:37 PM

Quote:

Originally Posted by Rufus (Post 1225570)
They can only get into your e-mail if they know your e-mail address.

True. And also, it doesn't matter if you have it in there or not. If they hack your e-mail they can just request a new password be sent.

konidias 10-03-2006 09:40 PM

I'm not liking this for the security issue it poses.

I always liked that the forum pass and account pass could be different. Because there seem to be many more ways to get your account pass stolen. For example, if someone obtained your graal account pass and e-mail, you could have the forum account linked to a different pass and e-mail, and then private message an admin to try and help you get your account back.

Also if someone get's your graal account pass, now they could come on the forum and post a bunch of spam or porn or whatever and get your forum account banned really fast. =/

Skyld 10-03-2006 09:44 PM

They are meant to be linked anyway, just like Graal.net is, and the Wiki is.

WanDaMan 10-03-2006 09:45 PM

Woah, that's a huge flaw. Listen to Konidias!

Damix2 10-03-2006 09:50 PM

Excellent, we can start a loriel-esque way to not only get forum passwords but now graal passwords aswell!

unixmad 10-03-2006 10:38 PM

I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...

Quote:

Originally Posted by konidias (Post 1225577)
I'm not liking this for the security issue it poses.

I always liked that the forum pass and account pass could be different. Because there seem to be many more ways to get your account pass stolen. For example, if someone obtained your graal account pass and e-mail, you could have the forum account linked to a different pass and e-mail, and then private message an admin to try and help you get your account back.

Also if someone get's your graal account pass, now they could come on the forum and post a bunch of spam or porn or whatever and get your forum account banned really fast. =/


Googi 10-03-2006 10:48 PM

Quote:

Originally Posted by unixmad (Post 1225610)
and they are really secure

Which is why we just had to change them.

Darlene159 10-03-2006 10:57 PM

Random, auto-generated passwords is a good idea anyway because too many people pick way too easy passwords, and tend to use the same password for everything, or at least several things.

Demisis_P2P 10-03-2006 11:59 PM

Quote:

Originally Posted by unixmad (Post 1225610)
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...

If somebody steals my Graal account by getting into my email address then they have 2 days to do whatever they want. Since password changes can only be sent every 2 days (not to mention that any smart person with access to your email account would change your email password).

I could make a support ticket, if I remember my username and password for that, but by the time it's responded to and acted on it'll probably already be too late. (And when I say 'acted on' I mean having the account temp-globalled.)

Since all my paypal info would also be in my email account, or they would have direct access to it as a consequence of having my email address, then the chances of me ever being able to fully regain control of my account are slim to none.

KuJi 10-04-2006 12:03 AM

Hahaha @ Demisis.

I had all my accounts switched to one email and thats like 5-10 accounts (ask ibonic on this =P).

And recently my IP's been changing a lot aswell (ask Ibonic on that aswell =P)

Anyway.. I don't think anyones accounts even been leaked out (actual password).. it was more for security of something that MAY happen then DID happen @ Googi =o

Minoc 10-04-2006 12:03 AM

Quote:

Originally Posted by Demisis_P2P (Post 1225655)
If somebody steals my Graal account by getting into my email address then they have 2 days to do whatever they want. Since password changes can only be sent every 2 days (not to mention that any smart person with access to your email account would change your email password).

How would that somebody get into your e-mail account?

Lord Sephiroth 10-04-2006 12:03 AM

Quote:

Originally Posted by unixmad (Post 1225610)
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...

There have been a lot of closed/deleted threads regarding the efficiency of the support center though. A lot of people are unhappy with the time it takes to get responses, and sometimes their tickets are just closed by a certain someone with no response what-so-ever.

MysticX2X 10-04-2006 12:04 AM

Yeah i learned to remember my graal password along time ago. its real easier logging into graal

Googi 10-04-2006 12:05 AM

Quote:

Originally Posted by Demisis_P2P (Post 1225655)
I could make a support ticket, if I remember my username and password for that, but by the time it's responded to and acted on it'll probably already be too late. (And when I say 'acted on' I mean having the account temp-globalled.)

Since all my paypal info would also be in my email account, or they would have direct access to it as a consequence of having my email address, then the chances of me ever being able to fully regain control of my account are slim to none.

The truly secure use different E-Mail addresses for everything important.

Mykel 10-04-2006 12:07 AM

Quote:

Originally Posted by Darlene159 (Post 1225616)
Random, auto-generated passwords is a good idea anyway because too many people pick way too easy passwords, and tend to use the same password for everything, or at least several things.

There is little to no harm in someone discovering what someone's forum password is. There is a great deal of harm in finding out someone's graal password. Having the forum password be the same as the graal password only allows one additional way to hack someone's password.

And as you already said, having the same password for multiple things is a security risk.

Quote:

Originally Posted by Googi (Post 1225612)
Which is why we just had to change them.

Haha, good point.

Quote:

Originally Posted by unixmad (Post 1225610)
I don't see any security issues:

If your graal password is stolen you can get it changed by the password changer in 30 seconds, you can also request by the support center giving your payement reference ID.

There are no reasons to get your graal password stolen, graal password are really random and they are really secure, we don't store them unencrypted and they are also salted.

We want to stop account sharing so it will be another good reason to not share his/her account to not have someone posting using your name...

If our Graal password is stolen, chances are we wouldn't find out until after something happens. As I replied to moony, having a password be the same for multiple things only increases risk. Plus, it can be a hassle too.

Once, just once, do a poll or something and actually give the players what they want.

Demisis_P2P 10-04-2006 12:16 AM

Quote:

Originally Posted by Minoc (Post 1225658)
How would that somebody get into your e-mail account?

Email addresses have lots of 'failsafes' like secret questions that can be guessed. Or they're linked to a secondary email address.
If either your primary or your secondary email address expire then they can also simply be re-registered by another person, and they would still be in the database for whatever things you signed up for with that email address.

Alternatively if you use an ISP email address and you change ISPs or move then the email address is lost, and could be re-registered by somebody else that uses that same ISP.

It's also possible for 'graal hackers' to put keyloggers or trojans into their programs and gain access to accounts that way. Of they could make a graal-related website that requires registration and do a Velox.

There are lots of possibilities.

Quote:

Originally Posted by Googi (Post 1225662)
The truly secure use different E-Mail addresses for everything important.

Most people just use the one. It's more convenient (for any would-be hackers aswell, I guess). But most people just don't think about having a database leaked everytime they sign up to a website.

Minoc 10-04-2006 12:27 AM

Quote:

Originally Posted by Demisis_P2P (Post 1225670)
WORDS

Well, you could do the following:
1) Choose a hard to guess password/secret answers.
2) Don't use the same passwords on unrelated websites.
3) Don't use poor free services to store sensitive information.
4) Pay attention to your e-mail account's expiration date.
5) Don't open unknown applications.
6) Use a firewall/anti-virus.

If you fail to do it and your account gets stolen, it's your fault.

Admins 10-04-2006 01:14 AM

Having separate forum passwords was more a insecurity than a help. You were able before to update the forum password by changing the Graal password, so it's not making something worse in that direction.

Mykel 10-04-2006 01:26 AM

Quote:

Originally Posted by Stefan (Post 1225701)
Having separate forum passwords was more a insecurity than a help. You were able before to update the forum password by changing the Graal password, so it's not making something worse in that direction.

How is it more of an insecurity? Have the same password for two separate things is not more secure.

Also, you do realize that we are talking about the security of our account passwords, not our forum passwords. The forum password security isn't nearly as big of a deal as the account passwords.

Infernix 10-04-2006 01:43 AM

Quote:

Originally Posted by Stefan (Post 1225701)
Having separate forum passwords was more a insecurity than a help. You were able before to update the forum password by changing the Graal password, so it's not making something worse in that direction.

What? So now not only when a account gets hacked they can now log onto fourms with your account and post anything they want, and now hackers have 2 ways to steal your account on graal.

This sounds like another horrible mistake and You and Unixmads part. And Please dont give me that George Bush BS and lie about making mistakes and just face up to them and fix them...like this one for example.


@Unixmad, ok yea we can change out passwords and send in support tickets when out account is stolen. But that doesnt change the fact that it is now easier to steal. Id rather not have my account stolen in the first place alright. So this is a Security Issue.

Skyld 10-04-2006 09:28 AM

People can only get your password if you are not careful.

The solution is to check that you are typing your passwords into GraalOnline.com instead of other websites trying to immitate it. You should also keep a spyware scanner up to date and not keep copies of your password in stupid places like "Hotmail" accounts. It's simple and I am not sure what you all find so difficult about that.

As for the accounts database being intruded, the people involved only got hashes of passwords. They could have spent a long time trying to bombard the hashes but it still would have been an unconstructive use of their time, since they are salted anyway.


All times are GMT +2. The time now is 03:36 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.