2011-02-04, 08:59 AM
Veneni Wrote:I think the most important thing they should add, though it's not really security related, is the ability to recover deleted chars.
That ability already exists for them, they've done it, rarely, for certain 'famous' users who had that happen.
If they had better security that would be an issue a lot less.
For the people going on and on about shipping; Nexon wouldn't have to handle the shipping themselves. You're generally responsible for buying them and in most cases paying for S&H if there is any and the entire order goes through a 3rd party that actually provides the authenticators.
Nexon wouldn't even be truly involved until you actually paired your shiny new authenticator with your account.
Jamie_Kurosawa Wrote:The verified PC method would be easier and just as effective. In fact one company uses it already to thwart piracy. That company is Microsoft and how they validate Windows. My method is similar.\
Sure. Let's use the method that Microsoft uses. Not like anyone is running dozens of pirated copies of their OS so obviously it's working, right?
Your idea is convoluted, complicated, time consuming and not guaranteed to work. MAC addresses can be changed. Anything that relies on communication to another server can be lied to. Anything that requires verification from another server can be lied to. You can easily setup a proxy, redirect traffic to it and tell your client it got any response you want to from the verification system. They don't need to steal your PC, they can either spoof the MAC address themselves, or just send their own for five days and walk in. IP addresses are not static by the way, so everyone on a leased IP, or a publicly shared IP, are screwed by your idea in slightly different ways. As is anyone who bothers to upgrade their PC in any significant way.
The key pineappleup in your logic is it requires Nexon to design, build and maintain.
Authenticators are configured and setup by 3rd party security specialists who know a hell of a lot more about what they're doing than Nexon, you or me.
Rather than trying to reinvent the wheel with our own highly limited understanding of what constitutes "round" (or in this case technology in general) why don't you admit your ignorance in the matter, stop trying to one up everyone else and actually support a tried and proven method of security?
It's not having what you want - It's wanting what you've got.

