Junior Member
Posts: 9
Threads: 1
Joined: 2011-02
2011-02-04, 12:22 AM
(This post was last modified: 2011-02-04, 02:00 AM by Mr.Amazing.)
Hey everyone,
I'm usually just a lurker around here, but I signed up to let you know that you should tweet Nexon asap.
Why? Nexon is having a "Security Awareness February" event this month and is asking people to tweet them @Maplestory with suggestions on how to keep accounts safe. This is our chance to let Nexon know that we need and want authenticators for our accounts. Don't know what an authenticator is? Google it in relation to other games like WoW, etc. I'm not going to go into a lengthy explanation since I'm typing this from my iPhone. Basically what authenticators do is give you a unique code (kind of like a PIC) that you will need to log in your account.
N00b: "But wait, why on earth would we need more codes to mezmorize?!"
The good thing about these codes are that they refresh about every 60 secs and change making it nearly impossible for hackers to crack it.
Dark Link Wrote:EDIT: Forgot to mention how the authenticator servers work. You only have 60sec to enter your randomized number code. After the allotted time has passed, the code becomes invalid and will not register no matter what you do.
Many other games have implemented this into either physical authenticators that you can purchase for around $5 or even have a free mobile authenticator app for your iPhone or droid. Nexon has already had success developing an app for Maplestory, so we all know that this is possible and within their scope of development.
Tweet them something simple such as "Please give us authenticators!!1" or something simple. You could even post on their FaceBook page or the Nexon forums like other people have. It's simple, Nexon won't take any action unless the community demands it!!
**
TLDR: tweet @Maplestory saying you want an authentication app for your mobile device. They are taking suggestions! If we had authenticators then there would be NO need for their "Account Security Awareness Month". Important: make sure to include #MapleSecurity in your tweet or it will most likely not be read!!
It literally takes a minute to make a twitter account. If this is something you want, PLEASE take some time to make an account just to tweet them. You never have to touch it again afterwards if you are that opposed to using twitter. If we keep quiet about this, Nexon will do nothing. It is better to try to get these implemented now rather then just stay quiet and never get them at all.
Posting Freak
Posts: 18,970
Threads: 319
Joined: 2008-07
I'm not touching twitter but please someone tell them to make an authenticator app.
Posting Freak
Posts: 1,485
Threads: 37
Joined: 2008-08
Gender: Male
Country Flag: canada
IGN: GlaciaIWolf
Server: Broa
Level: 146
Job: Aran
Guild: Forte
Guild Alliance: HighestLevel
I would if I had a twitter. Still going to stay cynical about this whole thing. Nexon America has proven to only occasionally listen to their playerbase. Plus they haven't really done anything independant of Nexon Korea, account security wise.
I'd send them a message anyways, if I had a twitter.
Junior Member
Posts: 9
Threads: 1
Joined: 2011-02
We need as many people as possible to do this, because if they do not see that we want them, they will not take it seriously and not even attempt to make one. We at least need to throw it out there and put the idea in their head. There is absolutely nothing negative about implementing these, as they benefit everyone but hackers.
Member
Posts: 107
Threads: 8
Joined: 2008-10
not to shoot down the idea but what happens to the people that dont have smart phones or dont want to pay for such thing ?
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
Posting Freak
Posts: 9,882
Threads: 342
Joined: 2009-01
Jamie_Kurosawa Wrote:Sadly this won't stop hackers: http://www.southperry.net/showthread.php?t=38990
No level of safety can stop human stupidity. There's no argument here.
Junior Member
Posts: 9
Threads: 1
Joined: 2011-02
Jamie_Kurosawa Wrote:Sadly this won't stop hackers: http://www.southperry.net/showthread.php?t=38990
I replied in your thread already in regards to this. I'll just regurgitate what I said earlier. The authenticator is not at fault here and is definitely NOT the reason those people got hacked. The people the article is referring to are those who downloaded a keylogger from a website which allowed the hackers to have access to their code. Are you implying that there should be no authenticators at all as an extra level of protection just because some newbs downloaded a keylogger and got hacked? What about the smart players who didn't download the keylogger? They still have their account and many of them probably won't get hacked thanks to having an authenticator attached to their account.
Posting Freak
Posts: 18,970
Threads: 319
Joined: 2008-07
Jamie_Kurosawa Wrote:Sadly this won't stop hackers: http://www.southperry.net/showthread.php?t=38990
Quote:So how do players get the keylogger on their PC? It all starts with a sponsored link in Google showing up as a top result for WowMatrix, a free World of Warcraft add-on installer and updater. The problem is that the listing isn't a genuine, leading gamers to the malware. "Several downloads are available and I decided to check out the installer / updater," reads this forum post. "Results are pretty low at virustotal for the executable. The detection of the DLL hooked into our system is even worse, only 1 antivirus suspects some illegal activity."
Clearly doesn't really apply to this game. Hacking an authenticator that is on your phone is pretty hard.
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
You have to look at this from a realistic point of view...
Hackers will find a way to get access to anything. Trying to stop them isn't 100% guaranteed and eventually they will get past things with time. What if next time they break the cyphers used by the Authenticators and find a way to spoof them? Then what? Literally, an authenticator would end up being nothing more than key chain with a random number generator as the hacker could already find a way to get the code, use it, and poof... you've been hacked and you didn't do anything to contribute to it.
Phones aren't immune to malware either... http://www.toptechreviews.net/tech-news/...id-phones/
Junior Member
Posts: 9
Threads: 1
Joined: 2011-02
PirateMG Wrote:not to shoot down the idea but what happens to the people that dont have smart phones or dont want to pay for such thing ?
Well, what do they do in other games? Those people would not have an extra level of security for their account. This isn't meant to be a mandatory thing. It is for people who are willing to pay or those who are lucky enough to have a compatible phone to download it on.
Jamie_Kurosawa Wrote:You have to look at this from a realistic point of view...
Hackers will find a way to get access to anything. Trying to stop them isn't 100% guaranteed and eventually they will get past things with time. What if next time they break the cyphers used by the Authenticators and find a way to spoof them? Then what? Literally, an authenticator would end up being nothing more than key chain with a random number generator as the hacker could already find a way to get the code, use it, and poof... you've been hacked and you didn't do anything to contribute to it.
Phones aren't immune to malware either... http://www.toptechreviews.net/tech-news/...id-phones/
There is absolutely nothing wrong with adding more security to your account. Sure, they might find a way somehow to hack people, but it would not be due to having an authenticator itself. There is always a way around things. It definitely would not hurt, and you also have to think about the hundreds of people who could possibly be saved from having their account stolen from adding an authenticator. This wasn't meant to become an argument thread, but if you do not agree with suggesting that Nexon provide this service to us, then just simply don't tweet them.
Posting Freak
Posts: 1,485
Threads: 37
Joined: 2008-08
Gender: Male
Country Flag: canada
IGN: GlaciaIWolf
Server: Broa
Level: 146
Job: Aran
Guild: Forte
Guild Alliance: HighestLevel
posted a blurb on their facebook. Doubt it'll get read, underneath the pile of useless posts that are completely irrelevant to the subject >.>
Jamie_Kurosawa Wrote:You have to look at this from a realistic point of view...
Hackers will find a way to get access to anything. Trying to stop them isn't 100% guaranteed and eventually they will get past things with time. What if next time they break the cyphers used by the Authenticators and find a way to spoof them? Then what? Literally, an authenticator would end up being nothing more than key chain with a random number generator as the hacker could already find a way to get the code, use it, and poof... you've been hacked and you didn't do anything to contribute to it.
Phones aren't immune to malware either... http://www.toptechreviews.net/tech-news/...id-phones/
Better than nothing right? Most people shouldn't go to suspicious looking sites/download suspicious files anyways. That should be common sense. And technically the authenticator hasn't been hacked yet, people have probably already tried and obviously failed. As of right now, if you follow common sense regarding account security, and have an authenticator, you're virtually unhackable.
I don't really get your point, are you saying it's absolutely pointless to try to have added security?
Posting Freak
Posts: 11,912
Threads: 42
Joined: 2010-06
Gender: Male
Sexual Orientation: Straight
Country Flag: Colorado
IGN: Musiphe
Server: Reboot
Level: 290
Job: Hero
Guild: Delight
Guild Alliance: Cataclysm
Jamie_Kurosawa Wrote:You have to look at this from a realistic point of view...
Hackers will find a way to get access to anything. Trying to stop them isn't 100% guaranteed and eventually they will get past things with time. What if next time they break the cyphers used by the Authenticators and find a way to spoof them? Then what? Literally, an authenticator would end up being nothing more than key chain with a random number generator as the hacker could already find a way to get the code, use it, and poof... you've been hacked and you didn't do anything to contribute to it.
Phones aren't immune to malware either... http://www.toptechreviews.net/tech-news/...id-phones/
The hackers must be freaking stupid then, considering the Blizz Auth. has been out for little over 2.5 years now and only one "attack" was used, which involved a "Man-in-the-middle" attack, which wasn't even a hack / crack to the actual device itself.
I'm honestly surprised that you're even trying to argue against adding an extra layer of GOOD protection against hackers in Maple.
EDIT: Forgot to mention how the authenticator servers work. You only have 60sec to enter your randomized number code. After the allotted time has passed, the code becomes invalid and will not register no matter what you do.
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
Yes it better than nothing but it's not bulletproof in what can happen.
What Nexon could start with is using high encryption levels between the Server and Client using things on par with WPA2-AES's level of encryption or better to where a public/private key has to be downloaded to the client, verify the client is registered to the user such as taking a hash of the MAC address or some other random ID Code from a random piece of hardware and encrypting it using SHA-2. This way only authorized PCs can access the account.
Give them time Link... and they will... and who's to say they aren't working on something far worse? And 60 seconds is more than enough time to hack an account.
However, the final decision will be Nexon's alone on what they can or can't do that is feasible, workable, and even in the end... cost effective.
Posting Freak
Posts: 9,882
Threads: 342
Joined: 2009-01
Jamie_Kurosawa Wrote:Yes it better than nothing but it's not bulletproof in what can happen.
What Nexon could start with is using high encryption levels between the Server and Client using things on par with WPA2-AES's level of encryption or better to where a public/private key has to be downloaded to the client, verify the client is registered to the user such as taking a hash of the MAC address or some other random ID Code from a random piece of hardware and encrypting it using SHA-2. This way only authorized PCs can access the account.
Give them time Link... and they will... and who's to say they aren't working on something far worse?
Your other thread was closed for your reasoning, which Eos himself declared as nothing more than silly. Literally giving access to your authenticator does not mean that it's ineffective. Cracking it is an entirely different story.
NOTHING is bulletproof as long as people will do stupid things, but at least you can stop hackers from easily cracking your account with nothing more than a google search worth of tools.
Also, all I'm seeing in your post is technical mumbo jumbo to sound more convincing.
Posting Freak
Posts: 18,970
Threads: 319
Joined: 2008-07
Jamie_Kurosawa Wrote:Phones aren't immune to malware either... http://www.toptechreviews.net/tech-news/...id-phones/
>Android phones
I have an iPhone. Nexon Americas only mobile app afaik has been for the iPhone, and the majority of people who play this game have an iPhone apparently.
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
Then by all means go work for Nexon, develop something that is cost effective for the company and users alike, and then prove how effective it will be, if ever. Remember Nexon is Free to Play, not Pay to Play.
Administrator
Posts: 17,191
Threads: 2,153
Joined: 2008-09
Gender: Male
Sexual Orientation: Gay
IGN: Aesilyn
Server: Mardia
Level: 200
Job: I/L ArchMage
Guild: Animus
Jamie_Kurosawa Wrote:What Nexon could start with is using high encryption levels between the Server and Client using things on par with WPA2-AES's level of encryption or better to where a public/private key has to be downloaded to the client, verify the client is registered to the user such as taking a hash of the MAC address or some other random ID Code from a random piece of hardware and encrypting it using SHA-2. This way only authorized PCs can access the account.
This idea is absolute crap prone to the exact same problems the existing system has.
1) You either can't register a new computer for access without already having access, which either means there has to be a security hole to let you do so, or only the person who's already compromised your account can choose whether or not you can get back in.
2) If you go the key route anyone who got your key via any number of operating system vulnerabilities and user ignorance would be able to login as you, same hole in SSH keyfile authentication.
You've seen Nexon's existing support for password lockout issues, all this would do is make users even more screwed.
Authenticators are by far the best and most readily available answer. They've a proven track record of success, major corporations use them daily to protect their VPNs. They're well understood, familiar, documented to an extent a trained monkey could implement them, and easily established on an opt-in basis so that only people who want that level of security need to worry about it.
It's not having what you want - It's wanting what you've got.
Account not Activated
Posts: 998
Threads: 43
Joined: 2010-09
So if this is the "magic bullet" here's a good question. How much would this cost not only Nexon to implement and maintain, but also how much would it cost us as well to acquire this service from them? They just aren't going to give it away for free.
Posting Freak
Posts: 8,478
Threads: 128
Joined: 2008-07
Gender: Neuter
Country Flag: canada
IGN: Oooh
Server: Bera
Job: Empress
Farm: Stereo
I wish they would stop compromising security by making poor decisions (like the PIC being used to delete characters)
Could someone tweet about that in particular?
|