2011-02-04, 08:59 AM
Quote:- What if you lose the device? Nexon's customer service being what it is, their way of getting around that would either be too easy for hackers to use, or so hard you'd pretty much lose your account permanently if you lost the device.A good point to exactly why it could be a bad idea as I motioned at with Nexon "supporting" this in it's implementation and their track record. If Nexon can bork up as much as they do God (or whoever) help you if you lose an Authenticator.
The verified PC method would be easier and just as effective. In fact one company uses it already to thwart piracy. That company is Microsoft and how they validate Windows. My method is similar.
The idea is this:
- Each PC system contains at least 7 Hardware ID and 7 Subsystem ID codes and a MAC address code.
- Of these, 5 IDs for both Hardware and Subsystem have to verified within so many usages for the client to verify the PC is the native client and account PC. For the first week on an account, a user can not perform any transactions other than with an NPC and the Storage.
- On initial installation the information is recorded to the account to a hash file and encrypted using SHA-2 (256 bit) and a copy is recorded to the server for authentication purposes.
- Depending on the user, a user can register a max only 2 PCs, like a desktop and a laptop. If any other PC attempts to log in on the account that isn't verified, the log in is refused, the user is sent a warning e-mail stating ????? from IP address x.x.x.x attempted to log in at xx:xx on your account.
- Log ins to the server are handled using encryption methods similar to WPA2-AES to encrypt the username and password being sent to the server for authentication.
Now with that method the only drawback would be if you had to unregister a PC. However, this could be limited to 1 PC per week and you can not unregister another until the newly added one has been verified for a week, and this can ONLY be performed through a secure section of the website.
Now if your curious as to the steps involved:
- user on a verified PC logins into the server over a secured channel.
- client checks the hash from the previous login, if at least 5 hashes check out with the hash recorded to the server, the user is verified and allowed to login and the new hash is recorded.
- user signs up for account and downloads client and creates a 10 security question bank.
- user installs client and client records initial encrypted hash from the IDs on startup
- user logs in and initial 7 hashes are recorded to the server
- after 1 week of successful authentications with no less than 5 consistent hashes verified the PC goes into verified status upon which a user can add a second PC that must match the IP address and be recorded.
- after initial PC is placed in verified status, user is allowed ability to perform user to user trade interactions as well as item, money dropping, and the ability to use Game Cash.
- If the chance occurs both PCs suffer a failure the account can be placed, at the user's discretion, into a stasis mode until a new PC can be verified. During this time the account can not be logged into using a game client, and upon reactivation from stasis, a user must answer 5 security question from a batch of 10 questions made upon sign up, however user must go through steps 2 - 5 once again.
- No PIC or PIN needed of ANY kind. In fact add using birthdays to the list also.
- No probable and possible way to hack the account unless someone actually STEALS your actual PC and can successfully duplicate your ISP's IP address and fully duplicates your exact hardware, subsystem, and MAC ID codes.
- Nothing to lose or break or replace batteries in.
- E-mail notification of attempted account tampering would be VERY welcome.
- Unless your completely impatient, having to wait a week to get fully verified to have full usage of trading and dealing goods is about it.
- It might take a few nanoseconds longer in the log in process.
Now unless you think I'm talking mumbo jumbo or gobbledygook, go bury your face inside a CompTIA Security+ book and learn something.
