2012-02-22, 01:51 PM
Afrobean Wrote:Don't know what the other person was talking about but I can say this:
It's worthless and stupid. It should be easy for a specialized keylogger to also screenshot on clicks and upload the screencaps to an external location to reveal the passcode, exactly the problem that made the earlier PIN code technically ineffective. A player also reveals their passcode to anyone watching the screen, so that's kind of stupid. There are PLENTY of secondary authorization methods that can be used, but requiring a second password entered via a software keyboard isn't one of them. Don't other systems have a system where you give them your phone number and they text you a unique code every time you log in? I guess that would require additional infrastructure on Nexon's part though, eh? Not as easy as adding one more field to the database to store a second password and adding a step in the client that asks for the second password.
That's all fine and dandy, but if you don't get keylogged, the main problem is that there's no cooldown on PIC's. Yeah.
So basically, they can guess your PIC for however long they want and you're fucked because unless their internet goes down, they'll have until the next SC to figure your PIC out.

