Graal Forums  

Go Back   Graal Forums > Development Forums > Future Improvements
FAQ Members List Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 02-22-2012, 09:54 AM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
Account changes

Maybe if people want to change their account from the usual Graal###### there should be a payment in the store which allows an account name change.
Also password should be changeable.
Just my thoughts.
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #2  
Old 02-22-2012, 10:47 AM
TSAdmin TSAdmin is offline
Forum Moderator
TSAdmin's Avatar
Join Date: Aug 2006
Location: Australia
Posts: 1,980
TSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud of
Won't happen. Information about your account is tied to the account name. If you change it, you lose everything everywhere because ultimately the account no longer exists by name. This is one of the reasons why community names even exist: So you can change that identifier without losing any account information.
Also, http://graalonline.com/accounts/lostpass is how you change your password.
__________________
TSAdmin (Forum Moderator)
Welcome to the Official GraalOnline Forums! Where sharing an opinion may be seen as a declaration of war!
------------------------
· User Agreement · Code of Conduct · Forum Rules ·
· Graal Support · Administrative Contacts ·
Reply With Quote
  #3  
Old 02-22-2012, 11:29 AM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
I worded that wrong, I meant "custom passwords" instead of like ch67AG87 ones and no that isn't my password.
And why can't the information be linked to your account in some other way, having Graal###### account's suck.
It takes out the creativity.
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #4  
Old 02-22-2012, 11:58 AM
TSAdmin TSAdmin is offline
Forum Moderator
TSAdmin's Avatar
Join Date: Aug 2006
Location: Australia
Posts: 1,980
TSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud of
Quote:
Originally Posted by Gunderak View Post
I worded that wrong, I meant "custom passwords" instead of like ch67AG87 ones and no that isn't my password.
And why can't the information be linked to your account in some other way, having Graal###### account's suck.
It takes out the creativity.
How exactly would you change it? There is always going to be some form of identifier for accounts that you cannot change. The fact that the "Graal" numbers are even still visible is really the only problem. If you had no idea it even existed and it was never referred to as your account name (lets call it an account ID), but you still had the ability to change your community name (although we could call that your account name in the event we dont know "GraalXXXX" exists), then nothing would be different and we would be content with exactly this setup. You could still change your community name and not be any wiser of your internal account id. Basically, people's biggest issue with the "GraalXXXX" numbers is the fact that they can see them, therefore know they exist as their "real" account when in fact it's really just an identifier that shouldn't even be known about.

As for the password thing, I would only agree to custom passwords as long as the person customising their password was forced to use a strong password. Even stronger than the current one. EG: Must include at least 1 capital, at least 1 symbol and at least 1 number and ultimately be over 8 characters long. People come up with the stupidest and most obvious passwords sometimes that it doesn't even give hackers a challenge to decrypt, if they even have to decrypt anything at all. You could just know someone well enough to know they'd be stupid enough to make their password their cat's name.
__________________
TSAdmin (Forum Moderator)
Welcome to the Official GraalOnline Forums! Where sharing an opinion may be seen as a declaration of war!
------------------------
· User Agreement · Code of Conduct · Forum Rules ·
· Graal Support · Administrative Contacts ·
Reply With Quote
  #5  
Old 02-22-2012, 01:10 PM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
Well I agree, the passwords should be forced to be strong.
And It would be changed by all new accounts NOT having Graal###### where as instead you should be able to specify your own; as it used to be as I believe.
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #6  
Old 02-22-2012, 02:29 PM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Would really like to see passwords be changable by users, but it should not cost gelats—that's just ridiculous.

Also, password strength requirements are annoying. As long as it's eight characters or so, let a user be responsible for their own account. Worrying about hackers getting passwords from the hashes is not really an issue unless the passwords database is stolen, at which time Graal should force a password reset for all users anyway.
__________________
Reply With Quote
  #7  
Old 02-22-2012, 02:34 PM
TSAdmin TSAdmin is offline
Forum Moderator
TSAdmin's Avatar
Join Date: Aug 2006
Location: Australia
Posts: 1,980
TSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud ofTSAdmin has much to be proud of
Quote:
Originally Posted by Gunderak View Post
Well I agree, the passwords should be forced to be strong.
And It would be changed by all new accounts NOT having Graal###### where as instead you should be able to specify your own; as it used to be as I believe.
But that negates your efforts to allow people to change their public identifier. You want people to be able to pick and choose their account name, but the way you want it (back to the way it used to be) once you pick it, you're stuck with it. Enter community names. Changeable at reasonable request without the disappointment of starting over because your identifier has changed. The only thing wrong with the current system is the fact that people are being told to upgrade before they are allowed to choose a name which has lead to problems like their Graal#### identifier being public by default.

In line with your desires, it would be better for them to leave the current system in place where people have the option to pick and alter their community name, BUT the Graal number (and other people's Graal numbers) needs to be absolutely hidden from existence. The only exception being for administrative requirements, something players have no need to be involved in. It all comes back to that. Something developers have been trying to get recognised for far too long.
__________________
TSAdmin (Forum Moderator)
Welcome to the Official GraalOnline Forums! Where sharing an opinion may be seen as a declaration of war!
------------------------
· User Agreement · Code of Conduct · Forum Rules ·
· Graal Support · Administrative Contacts ·
Reply With Quote
  #8  
Old 02-22-2012, 07:33 PM
BlueMelon BlueMelon is offline
asdfg
BlueMelon's Avatar
Join Date: Sep 2008
Posts: 1,481
BlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to behold
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.
__________________
http://i.imgur.com/OOJbW.jpg
Reply With Quote
  #9  
Old 02-22-2012, 07:46 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by BlueMelon View Post
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.
I'm assuming that Graal also stores them when they couldn't be used successfully. Therefore, you can easily get the encrypted version for every password. One could probably write a script to brute force that. I suppose using a key logger would be a little easier though
Reply With Quote
  #10  
Old 02-22-2012, 07:57 PM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Quote:
Originally Posted by BlueMelon View Post
Just wanted to mention, graal passwords are stored in the registry of ones computer. They a re then decrypted by the client. If someone wanted to make a password stealer, he would need to find the algorithm at which graal uses to encrypt and decrypt the passwords in the registry.
It could just wait for you to open Graal and steal the password from there. Your email and other accounts are likely to get hijacked before they take your Graal account via a key-logger, especially if you keep the password email there.

Another thing is that after you paste in your password you're going to want to clear it from your clipboard so it's not sitting there waiting to be picked off.
__________________
Quote:
Reply With Quote
  #11  
Old 02-22-2012, 09:12 PM
Demisis_P2P Demisis_P2P is offline
Kanto League Champion
Demisis_P2P's Avatar
Join Date: Jan 2005
Posts: 2,357
Demisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud ofDemisis_P2P has much to be proud of
Quote:
Originally Posted by TSAdmin View Post
How exactly would you change it? There is always going to be some form of identifier for accounts that you cannot change. The fact that the "Graal" numbers are even still visible is really the only problem. If you had no idea it even existed and it was never referred to as your account name (lets call it an account ID), but you still had the ability to change your community name (although we could call that your account name in the event we dont know "GraalXXXX" exists), then nothing would be different and we would be content with exactly this setup. You could still change your community name and not be any wiser of your internal account id. Basically, people's biggest issue with the "GraalXXXX" numbers is the fact that they can see them, therefore know they exist as their "real" account when in fact it's really just an identifier that shouldn't even be known about.
Yeah, community names weren't a bad idea, but they really screwed up the implementation of it something shocking.
__________________
Reply With Quote
  #12  
Old 02-22-2012, 09:52 PM
Bell Bell is offline
Registered User
Bell's Avatar
Join Date: Feb 2007
Posts: 1,824
Bell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud ofBell has much to be proud of
I also wish the Graal### portion wasn't visible to the public but what I find ironic is this. Graal## people complain because they don't have a named account. Graal named accounts people complain cause they can't change their community name. All claim its unfair. The moral of this story is "The grass is always greener on the other side of the fence"
__________________
For support contact
http://support.toonslab.com/
Reply With Quote
  #13  
Old 02-22-2012, 10:33 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by Bell View Post
I also wish the Graal### portion wasn't visible to the public but what I find ironic is this. Graal## people complain because they don't have a named account. Graal named accounts people complain cause they can't change their community name. All claim its unfair. The moral of this story is "The grass is always greener on the other side of the fence"
nop, just do rufus' idea and everything would be solved. never seen a game have so many problems with fundamental crap
__________________
Reply With Quote
  #14  
Old 02-23-2012, 12:02 AM
Unkownsoldier Unkownsoldier is offline
Ignorance has no future
Join Date: Sep 2008
Posts: 1,287
Unkownsoldier is on a distinguished road
Graal could have just followed what many other game companies do, Nexon for example. You have a Nexon ID in which you use to login then you can create characters on the actual game. The players only see your character name and not your actual account name, a lot safer in my opinion.
__________________
Look beyond the monitor.
Reply With Quote
  #15  
Old 02-23-2012, 12:46 AM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Quote:
Originally Posted by Crono View Post
nop, just do rufus' idea and everything would be solved. never seen a game have so many problems with fundamental crap
What is Rufus' idea? If you mean the one he had for giving all players a Graal### account, it's just not possible.

Quote:
Originally Posted by Demisis_P2P View Post
Yeah, community names weren't a bad idea, but they really screwed up the implementation of it something shocking.
This really was (and still is) the largest problem. It took years to get support for them in RC, and the publicly released RC still doesn't support them. There's also no scripting functions for getting the cname of an account (and vica-versa).
__________________
Reply With Quote
  #16  
Old 02-23-2012, 12:49 AM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by cbk1994 View Post
What is Rufus' idea? If you mean the one he had for giving all players a Graal### account, it's just not possible.
completely hide graal#### from users and have it only display their community names.
__________________
Reply With Quote
  #17  
Old 02-23-2012, 01:45 AM
scriptless scriptless is offline
Banned
Join Date: Dec 2008
Location: N-Pulse
Posts: 1,412
scriptless is a splendid one to beholdscriptless is a splendid one to beholdscriptless is a splendid one to beholdscriptless is a splendid one to behold
I read up to the "custom passwords". I have to shake my head quickly and shout "NO". As a majority of graalians don't use the most common sence and often, you guessed it, repeat passwords. Ever wonder why people are getting hacked left and right all the time? Leaked databases, I have seen and forwarded to Graal Staff. Where people hardcore own themselves by using the same password as there email. And some people have lost everything, facebook, myspace, aim, etc.. it's just not secure at all.. Let graal gen you a password, end of story.

As for account names, about Graal#### blah blah names.. Live with it, the problem is the lack of support (from developers) for proper usage. Basically, if you don't like it ignore it because of the following

All account's have an account name, but not all accounts have a community name. Accounts created before Graal###, have there community name set as there account name, ex:

Classic Subscription Account Test Results: (bloodpet)
player.account, returns "bloodpet"
player.communityname, returns "bloodpet"

As far as scripting goes, ALWAYS USE ACCOUNT NAME NOT COMMUNITY... or your script can/will break. (Those accounts that have Graal###, but never bought a community name)...

I don't know why people insist the Graal### names are problems, because its not a compatibility error but a human error on the developers behalf.. GRR


Best solution:
making Graal### invisable, and giving us a feature that is retard proof for scripters.

findplayer() and findplayerbycommunityname(). People don't understand when to use them because they try using communit name's instead of account and it can't find them. It IS messy. But its not rocket science. there should be 0 complaints from anyone about the current system.
Reply With Quote
  #18  
Old 02-23-2012, 03:01 AM
cbk1994 cbk1994 is offline
the fake one
cbk1994's Avatar
Join Date: Mar 2003
Location: San Francisco
Posts: 10,718
cbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond reputecbk1994 has a reputation beyond repute
Send a message via AIM to cbk1994
Quote:
Originally Posted by scriptless View Post
I read up to the "custom passwords". I have to shake my head quickly and shout "NO". As a majority of graalians don't use the most common sence and often, you guessed it, repeat passwords. Ever wonder why people are getting hacked left and right all the time? Leaked databases, I have seen and forwarded to Graal Staff. Where people hardcore own themselves by using the same password as there email. And some people have lost everything, facebook, myspace, aim, etc.. it's just not secure at all.. Let graal gen you a password, end of story.
This is nonsense. Let players be responsible for their own accounts. We don't need to be protecting people from their own stupidity, even those who lack common "sence". Very few other services insist on randomly generating passwords. Making it harder to login to your account is not a good way to retain players.

Quote:
findplayer() and findplayerbycommunityname(). People don't understand when to use them because they try using communit name's instead of account and it can't find them. It IS messy. But its not rocket science. there should be 0 complaints from anyone about the current system.
We are lacking functions to convert between account and commityname, there is still a bug with communityname (which is empty if one has not been chosen; it should instead be the account), and the released Windows RC (which most developers use) does not support community names in the playerlist.
__________________
Reply With Quote
  #19  
Old 02-23-2012, 03:02 AM
BlueMelon BlueMelon is offline
asdfg
BlueMelon's Avatar
Join Date: Sep 2008
Posts: 1,481
BlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to behold
Quote:
Originally Posted by Crow View Post
I'm assuming that Graal also stores them when they couldn't be used successfully. Therefore, you can easily get the encrypted version for every password. One could probably write a script to brute force that. I suppose using a key logger would be a little easier though
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.

Quote:
Originally Posted by fowlplay4 View Post
It could just wait for you to open Graal and steal the password from there. Your email and other accounts are likely to get hijacked before they take your Graal account via a key-logger, especially if you keep the password email there.

Another thing is that after you paste in your password you're going to want to clear it from your clipboard so it's not sitting there waiting to be picked off.
Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often
__________________
http://i.imgur.com/OOJbW.jpg
Reply With Quote
  #20  
Old 02-23-2012, 05:55 AM
Hezzy002 Hezzy002 is offline
Registered User
Join Date: Jul 2011
Posts: 247
Hezzy002 is a jewel in the roughHezzy002 is a jewel in the rough
Solution that won't require account resets or major script modifications:

player.account stays static. No longer visible on profile. It's an identifier only.

For all Graal# accounts, allow them to make a decent username on next login to the list server. That's set to communityname.

For all non-Graal# accounts, set communityname to their player.account value.

Display communityname on the profile.

player.communityname will remain static. Forever. Seriously, what kind of MMO let's you change your username spontaneously? That's what the nickname is for.

Quote:
Originally Posted by BlueMelon View Post
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.



Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often
Myself being a real programmer, I'm going to call you out, just based on this post, your name, your signature, and avatar, that you're one of those annoying kids.
Reply With Quote
  #21  
Old 02-23-2012, 06:19 AM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
Quote:
Originally Posted by BlueMelon View Post
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.

Unless your infected with some kind of multi-virus for example a RAT (Remote administration tool) those things can get pretty nasty, features from keylogging to clipboard logging to remote desktop even.

If you people are up on your security and monitor your outgoing connections, you should be safe. Anyway, graal has also implemented to send an email to allow another computer to play your account. So I would suggest at most to change your password every so often
When people talk about Keyloggers they aren't referring to the literal act of logging your keystrokes and sending them to you. They're referring to malicious RATs.

Phishing and other social engineering methods are how most Graalians are being compromised these days. A majority of graal users probably have their password email still in their inbox.

Manually entering your password and not saving it is as secure as you can be. A memorized password is more secure than a password stored in your email or in a text file, and if they have their graal email they'll also have no problem getting the right password.

The PC ID system is not stable either and is only going to cause further annoyance, also considering that the system has flat out broke at times eliminates any kind of trust I would have in it.

On topic:

The big flaws with the account system need to be fixed and our tools updated to work with it. If it was implemented and finished properly we would of never had to make stupid threads about it.
__________________
Quote:
Reply With Quote
  #22  
Old 02-23-2012, 06:22 AM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Quote:
Originally Posted by cbk1994 View Post
Would really like to see passwords be changable by users, but it should not cost gelats—that's just ridiculous.

Also, password strength requirements are annoying. As long as it's eight characters or so, let a user be responsible for their own account. Worrying about hackers getting passwords from the hashes is not really an issue unless the passwords database is stolen, at which time Graal should force a password reset for all users anyway.
Reply With Quote
  #23  
Old 02-23-2012, 06:25 AM
Fulg0reSama Fulg0reSama is offline
Extrinsical Anomaly
Fulg0reSama's Avatar
Join Date: Sep 2009
Location: Ohio
Posts: 3,049
Fulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant future
Funny thing is I've already memorized my current Graal password.

I don't even use any form of key memorization like in Dusty's comic he posted.
__________________

Careful, thoughts and opinions here scare people.
Reply With Quote
  #24  
Old 02-23-2012, 06:29 AM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Quote:
Originally Posted by Fulg0reSama View Post
Funny thing is I've already memorized my current Graal password.

I don't even use any form of key memorization like in Dusty's comic he posted.
I still remember my password for my Graal account that is 13 years-old because it's a custom-defined password. However I still don't know my password for my current account(that I've had for 9+ years) because it's a generated assortments of letters and numbers that is just beyond memorizing(for me, personally).
Reply With Quote
  #25  
Old 02-23-2012, 06:38 AM
Fulg0reSama Fulg0reSama is offline
Extrinsical Anomaly
Fulg0reSama's Avatar
Join Date: Sep 2009
Location: Ohio
Posts: 3,049
Fulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant futureFulg0reSama has a brilliant future
Quote:
Originally Posted by DustyPorViva View Post
I still remember my password for my Graal account that is 13 years-old because it's a custom-defined password. However I still don't know my password for my current account(that I've had for 9+ years) because it's a generated assortments of letters and numbers that is just beyond memorizing(for me, personally).
Yeah, mine isn't custom defined, I accidentally resetted mine sometime ago :C
__________________

Careful, thoughts and opinions here scare people.
Reply With Quote
  #26  
Old 02-23-2012, 06:51 AM
fowlplay4 fowlplay4 is offline
team canada
fowlplay4's Avatar
Join Date: Jul 2004
Location: Canada
Posts: 5,200
fowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond reputefowlplay4 has a reputation beyond repute
You just need to reset your password until you get one thats all letters, attempt to pronounce the word it makes and remember your hand motions.

After you got that down the only tricky part is remembering which letters are uppercase.
__________________
Quote:
Reply With Quote
  #27  
Old 02-23-2012, 07:07 AM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
Why not just let users set their own passwords and force passwords to have 1 upper case and at least one symbol.
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #28  
Old 02-23-2012, 07:17 AM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Quote:
Originally Posted by Gunderak View Post
Why not just let users set their own passwords and force passwords to have 1 upper case and at least one symbol.
Forcing symbols and crap like that does nothing to improve the security of a password in most cases and only makes it harder to remember for some people to remember, especially since these requirements vary from one site to the next.
Reply With Quote
  #29  
Old 02-23-2012, 09:10 AM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by BlueMelon View Post
Keyloggers are old, and would not be that much of a threat against your account security. Who manually types there graal password anyway? I can barely remember it.
Most keyloggers don't only check typed keys anymore. Many also capture the current clipboard if there's text in it, and some go through obvious password fields in your web browser and copy the contents. Like it's been said, it could just read it from memory.


Quote:
Originally Posted by Gunderak View Post
force passwords to have 1 upper case and at least one symbol.
Unnecessary. Additional possible characters does not make your password more secure.
Reply With Quote
  #30  
Old 02-23-2012, 11:43 AM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
I still think we should be allowed custom passwords.
Graal is the only game that I have played that insists on random jiberish as a password.
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #31  
Old 02-23-2012, 06:25 PM
Emera Emera is offline
Delterian Hybrid
Emera's Avatar
Join Date: Mar 2011
Location: Newcastle Upon-Tyne
Posts: 1,704
Emera is a jewel in the roughEmera is a jewel in the rough
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.
__________________
Reply With Quote
  #32  
Old 02-23-2012, 06:53 PM
Crono Crono is offline
:pluffy:
Join Date: Feb 2002
Location: Sweden
Posts: 20,000
Crono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond reputeCrono has a reputation beyond repute
Quote:
Originally Posted by Emera View Post
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.
I play popular games and all of them let you choose your own password.

Dota 2, HoN, Starcraft 2, Minecraft, (WoW and LoL, two gigantic games that i don't play) let you choose your own password.
__________________
Reply With Quote
  #33  
Old 02-23-2012, 07:04 PM
xXziroXx xXziroXx is offline
Malorian
xXziroXx's Avatar
Join Date: May 2004
Posts: 5,289
xXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant futurexXziroXx has a brilliant future
Quote:
Originally Posted by Emera View Post
A lot of on-line games use this method as a means to keep accounts safe
No, they really don't. I play an extreme amount of online games that surface on the market, and the ONLY things that pestered me about passwords have been Graal and EVE Online, but at least the latter let me chose my own one but with some restrictions.
__________________
Follow my work on social media post-Graal:Updated august 2025.
Reply With Quote
  #34  
Old 02-23-2012, 07:13 PM
Crow Crow is offline
ǝɔɐɹq ʎןɹnɔ
Crow's Avatar
Join Date: Dec 2006
Location: Germany
Posts: 5,153
Crow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond reputeCrow has a reputation beyond repute
Quote:
Originally Posted by Emera View Post
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.
Eight character passwords are not safe* anymore, and it's been like that for quite a while. It's generally one of the worst ideas to not let customers choose their own passwords.

Edit: I should've explained:
* safe in terms of brute force; doesn't really take that long anymore to brute force an eight character password, as long as the service allows enough attempts per minute.
Reply With Quote
  #35  
Old 02-24-2012, 02:01 AM
BlueMelon BlueMelon is offline
asdfg
BlueMelon's Avatar
Join Date: Sep 2008
Posts: 1,481
BlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to beholdBlueMelon is a splendid one to behold
Quote:
Originally Posted by Hezzy002 View Post
Myself being a real programmer, I'm going to call you out, just based on this post, your name, your signature, and avatar, that you're one of those annoying kids.
Calling me out? My knowledge in the field of computer security and programming are quite vast. With over 4 years of experience, I know what I'm talking about when it comes to malicious software. When people say "keylogger" I think of the literal meaning. Yes, I know software now days can log and steal just about whatever but they are no longer called keyloggers they are called a multi-logger or account/information stealer.

If you would like to explain how I come off like a kid to you, please feel free to PM me.
__________________
http://i.imgur.com/OOJbW.jpg
Reply With Quote
  #36  
Old 02-24-2012, 03:43 AM
Mark Sir Link Mark Sir Link is offline
Kevin Azite
Mark Sir Link's Avatar
Join Date: Sep 2005
Posts: 1,489
Mark Sir Link is just really niceMark Sir Link is just really nice
Send a message via AIM to Mark Sir Link
Quote:
Originally Posted by Emera View Post
A lot of on-line games use this method as a means to keep accounts safe, or safer than if the company decided to let players use a password of their choice.
lmao wat
Reply With Quote
  #37  
Old 02-24-2012, 04:36 AM
DustyPorViva DustyPorViva is offline
Will work for food. Maybe
DustyPorViva's Avatar
Join Date: Sep 2003
Location: Maryland, USA
Posts: 9,589
DustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond reputeDustyPorViva has a reputation beyond repute
Send a message via AIM to DustyPorViva Send a message via MSN to DustyPorViva
Bottom line that forcing generated passwords on users forces them to store the password somewhere(usually saving the email) meaning it's actually easier to obtain than letting them choose their own and keeping the password in their head.
Reply With Quote
  #38  
Old 02-24-2012, 06:45 AM
DARKVILLIN DARKVILLIN is offline
Banned
Join Date: Oct 2002
Location: USA
Posts: 271
DARKVILLIN has a little shameless behaviour in the past
Send a message via AIM to DARKVILLIN
Quote:
Originally Posted by DustyPorViva View Post
Bottom line that forcing generated passwords on users forces them to store the password somewhere(usually saving the email) meaning it's actually easier to obtain than letting them choose their own and keeping the password in their head.
^This is True...
Reply With Quote
  #39  
Old 02-24-2012, 09:00 AM
Gunderak Gunderak is offline
Coder
Gunderak's Avatar
Join Date: Jun 2011
Location: Australia
Posts: 795
Gunderak is on a distinguished road
The moral of this thread is, "let us choose our own password".
__________________

Gund for president.

Remote PM {P*}x (Graal813044) from eraiphone -> Stefan: I hav 1 qustion
*Gunderak: he hav 1
*Gunderak: qustion
Reply With Quote
  #40  
Old 02-25-2012, 02:02 PM
Admins Admins is offline
Graal Administration
Join Date: Jan 2000
Location: Admins
Posts: 11,693
Admins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud ofAdmins has much to be proud of
Well the new standard seems to be to generate a password, but also allow setting your own password if it meets some security level. We will probably need to add that sometime, but make it inside the game, not on website.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 04:28 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
Copyright (C) 1998-2019 Toonslab All Rights Reserved.