Login Procedure Change
#21
Fiel Wrote:Incriminate them if they take action. Incriminate them if they don't take action.
Incriminate them if they take responsibility. Incriminate them if they don't take responsibility.

I guess they're screwed no matter what they do, eh

If they took responsibility they would get more lenient responses from me. Everyone makes mistakes.

edit: as a matter of fact, I've made MANY posts standing up for them when they've taken even small actions that were the right ones. Like when they spoke about the server issues. There have been other times, too. I'm not just out to get Nexon all the time, but I think they need to stop being such a shady piece of crap company and deal with things head on instead of whispering in the broom closet like six year olds trying to figure out how to blame their pet on the broken vase. As far that analogy goes, this action would be the equivalent of trying to glue the vase back together and hoping no one ever notices it was broken.
Reply
#22
Fiel Wrote:I guess they're screwed no matter what they do, eh

Well yeah, they were screwed from the first account that lost money/equips due to this issue. Now it's just a matter of scale. How many paying customers can they drive away?
Reply
#23
spideyjvc Wrote:this.
At least i can finally use some of my other accounts that i forgot the pin to and lost the false information needed to request a reset.

yusssssssssssssss.

edit: wait wait, do we still have to login with the pin the first time? If so, ):
Reply
#24
Nexon Wrote:After you have a PIC you will no longer need to enter your old PIN at login.

I don't know what's making you guys think that they would completely remove the security that pins provide for accounts that aren't active.
Reply
#25
BombsAway Wrote:This isn't addressing anything, by the way. It's probably further incriminating them since they're taking inside action, but saying "here's something new" isn't actually addressing the situation and they shouldn't be let off the hook.

It's no authenticator, but it'll let me hop back on Maple without worrying too much about getting hacked. I tread the internets with caution like Greg, and soon I can hop back playing without regrets of losing everything because people broke into the database. Besides, it's a countermeasure against these current hackers. It actually shows they are aware of the hacking epidemic.

*Now if they only acknowledge that there's a hacking problem Nexon will regain face. This is implying there's a hacking problem without actually saying out loud there's a hacking problem. Nexon wants their cake and eat it too; they know acknowledging a hacking epidemic will cause NX sales to plummet because people will suddenly not log on, therefore they're losing money while they fix the problem. They want to try to fix the problem while risking the fact that those who never knew about the hacking problem will never know that their account(s) could have been compromised.*

Thanks to JellyFlower's post:
Jellyflower Wrote:I'm not sure what your exposure unit is, is it 1 billion hashes per computer or organized network or what? Let's just say you're right 72^9/10^9 = time to crack a specific passsword, which is around 520 million second (not sure where you get 3.13e16 at), translated to 1.65 years. You're forgetting the fact that they have more than one specific target. If passwords are uniformally and identically distributed and say 2000 users have 9-letter long passwords, so divide that by 2000 and you get 7.22 hours per successful crack. Suddenly it doesn't look as nice. You can also argue that my method will incorporate multiple checkings so in the end it's still as many comparisons as like targetting one target, but using quicksort or whatever efficient method, you can end up with log n or less comparsions instead of n. (Let's say log 2000/log 2) = 11, multiply this to 7.22 hours and you get 79.42 hours, I sure wouldn't feel safe. But each subsequent letter will increase the average crack time by 72x of previous.

10-letter -> 238.26 days
11-letter -> 47 years
12-letter -> 3384 years

Bottom-line is, it's 'safer' to have longer passwords and what's stopping you to having them? An old guildmate of mine is presumed hacked as well just today and she hasn't logged on for 7 or 8 months now.

Entering a 12 character PIC will screw hackers over. This also means that if you still got hacked after this change, then we can easily narrow it down to something as simple as a close friend or someone you know hacked your account. That or someone is really out go get you, which is highly unlikely unless you really are hated by people on your server.

*And Keyloggers, can't forget those damn keyloggers.
Reply
#26
Greg Wrote:So what is this exactly? Instead of a password and a pin, it's basically two passwords?

To be honest, I'd rather have this along with the pin system. Why'd they have to remove that?

THIS...Imma have to agree to. They shouldve kept the PIN instead of replacing it and add in the PIC feature for a 3-layer security: ID+PW, PIN, PIC.
Reply
#27
I know why they are changing.

The new net based launch launches the game after you login on the website with your username/pass

This means that without a PIC which you enter at the character select screen, you dont need/have a chance to input a pin.

This way, there will be a PI* system that is compatible with weblaunch
Reply
#28
Nightclaw Wrote:*hacks*

seriously, Why add the option to type? gives keyloggers more power

If you have a keylogger aren't you basically screwed regardless...
Reply
#29
Cancambo Wrote:FYI: this new system will probably let you type your PIC in with your own keyboard (and allow you to use the soft keyboard as well), and this might make more people fall victim to keyloggers (I'd imagine).
In no way would it cause more people to fall victim to keyloggers.
If the PIC wasn't there, would more people get keylogged? No.
Does the PIC give keyloggers? No.
This simply adds another layer of protection.

If you can use your keyboard with it, oh well, the PIC does nothing when you get keylogged.
If you can't use your keyboard with it, yay. The PIC has just helped you.
If someone else knows your info but doesn't know your PIC, yay. The PIC has just helped you.
Reply
#30
PIC..? I kinda felt partially safe with the PIN, but since its more typing if you get a keylogger well yay. I'd like it more if they gave the option to choose either a soft keyboard or to type it but that won't happen. Oh well.
Reply
#31
I don't know the last time I heard of someone getting hacked with a keylogger. Seriously, if a keylogger gets on my computer, I seriously doubt they'll go for my maple account over my paypal password. If you get a keylogger on your computer, either you need to stop visiting the sketchiest sites on the web or get better security.

Edit: also, can you change accounts after starting up maplestory with the web-launch, or do you have to go to the site every time you want to change accounts?
Reply
#32
The latter.
Reply
#33
I dont see this as a hacking prevention, but more as a Pservers prevention, Just imagine it, private servers conect directly to their server, this may make it almost impossible to Pservers to keep updating :O
Reply
#34
solarboy Wrote:I dont see this as a hacking prevention, but more as a Pservers prevention, Just imagine it, private servers conect directly to their server, this may make it almost impossible to Pservers to keep updating :O

Buddy, private servers stopped updating back in v0.65.
Reply
#35
ClawofBeta Wrote:Buddy, private servers stopped updating back in v0.65.

you are wrong, they still update, and they will keep going untill Maple dies, but thats off-topic.

I still cant believe this is a patch -.-
Reply
#36
solarboy Wrote:you are wrong, they still update, and they will keep going untill Maple dies, but thats off-topic.

I still cant believe this is a patch -.-

Have you ever Googled "Maplestory Private Server?"

We're still on topic. Tee hee.

*Edit* Highest private server has SOME 0.75 content.
Reply
#37
ClawofBeta Wrote:Have you ever Googled "Maplestory Private Server?"

We're still on topic. Tee hee.

*Edit* Highest private server has SOME 0.75 content.

yup, thats what i meant, even though sometimes they stop updating, they update eventualy, so this may stop them
Reply
#38
solarboy Wrote:you are wrong, they still update, and they will keep going untill Maple dies, but thats off-topic.

I still cant believe this is a patch -.-

I really don't see this being an issue for PServer development. Especially since we might still be able to use GameLauncher.exe, and sign in normally. They'll probably disable PIC like they usually do to PINs.

*v.75 servers are up and running. I played one after I got hacked and it wasn't very buggy, apart from CYGKs getting their 100 and 110 skills right off the bat at 70. Grew bored of it quickly.
Reply
#39
Why can't they just make so that when you login in, it asks you questions like: What's your name/last, birthday, etc.
Reply
#40
CionS101 Wrote:Why can't they just make so that when you login in, it asks you questions like: What's your name/last, birthday, etc.

Because that provides other security issues. I'm not sure if you're from the states, but due to idiots posting everything about themselves on places like mybook and facespace people have been scraping that information and using it to steal accounts. It happened to Sarah Palin and her Yahoo account. It could happen to anyone. Using a meaningless number to log into an account is far more secure than using publicly available information (for some people, anyway).
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)