2010-02-08, 08:38 PM
(This post was last modified: 2010-02-08, 08:43 PM by IllegallySane.)
BombsAway Wrote:This isn't addressing anything, by the way. It's probably further incriminating them since they're taking inside action, but saying "here's something new" isn't actually addressing the situation and they shouldn't be let off the hook.
It's no authenticator, but it'll let me hop back on Maple without worrying too much about getting hacked. I tread the internets with caution like Greg, and soon I can hop back playing without regrets of losing everything because people broke into the database. Besides, it's a countermeasure against these current hackers. It actually shows they are aware of the hacking epidemic.
*Now if they only acknowledge that there's a hacking problem Nexon will regain face. This is implying there's a hacking problem without actually saying out loud there's a hacking problem. Nexon wants their cake and eat it too; they know acknowledging a hacking epidemic will cause NX sales to plummet because people will suddenly not log on, therefore they're losing money while they fix the problem. They want to try to fix the problem while risking the fact that those who never knew about the hacking problem will never know that their account(s) could have been compromised.*
Thanks to JellyFlower's post:
Jellyflower Wrote:I'm not sure what your exposure unit is, is it 1 billion hashes per computer or organized network or what? Let's just say you're right 72^9/10^9 = time to crack a specific passsword, which is around 520 million second (not sure where you get 3.13e16 at), translated to 1.65 years. You're forgetting the fact that they have more than one specific target. If passwords are uniformally and identically distributed and say 2000 users have 9-letter long passwords, so divide that by 2000 and you get 7.22 hours per successful crack. Suddenly it doesn't look as nice. You can also argue that my method will incorporate multiple checkings so in the end it's still as many comparisons as like targetting one target, but using quicksort or whatever efficient method, you can end up with log n or less comparsions instead of n. (Let's say log 2000/log 2) = 11, multiply this to 7.22 hours and you get 79.42 hours, I sure wouldn't feel safe. But each subsequent letter will increase the average crack time by 72x of previous.
10-letter -> 238.26 days
11-letter -> 47 years
12-letter -> 3384 years
Bottom-line is, it's 'safer' to have longer passwords and what's stopping you to having them? An old guildmate of mine is presumed hacked as well just today and she hasn't logged on for 7 or 8 months now.
Entering a 12 character PIC will screw hackers over. This also means that if you still got hacked after this change, then we can easily narrow it down to something as simple as a close friend or someone you know hacked your account. That or someone is really out go get you, which is highly unlikely unless you really are hated by people on your server.
*And Keyloggers, can't forget those damn keyloggers.

