|
|
General discussion Topics related to various aspects of Champions of Regnum |
View Poll Results: ?? | |||
Very secure... | 9 | 30.00% | |
Not secure at all | 21 | 70.00% | |
Voters: 30. You may not vote on this poll |
|
Thread Tools | Display Modes |
01-19-2008, 05:10 AM | #1 |
Marquis
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
|
How secure do you feel regnum is?
I suggest that you use a new account for forums so people do not see your login name..... I said this when regnum was still in beta... but im saying it again, because someone I know got hacked... and lost their account..
Last edited by DemonMonger; 01-19-2008 at 12:36 PM. |
01-19-2008, 06:11 AM | #2 |
Banned
Join Date: Jan 2007
Location: Helsinki, Finland
Posts: 221
|
I dont really understand this question but i guess regnum is pretty secure
|
01-19-2008, 06:21 AM | #3 |
Baron
Join Date: Jun 2007
Location: Kelana Jaya
Posts: 920
|
Regnum is never secure as long as DM is running around in it
|
01-19-2008, 07:57 AM | #4 |
Duke
Join Date: Nov 2006
Location: 0x00CAFE
Posts: 3,366
|
No secure at all... Packages aren't ciphered, for instance.
__________________
I don't have a solution, but I admire the problem. |
01-19-2008, 09:09 AM | #5 |
Marquis
Join Date: Jul 2007
Location: The Netherlands
Posts: 2,076
|
Not secure I think, but why would somebody hack Regnum?
__________________
Dky Sven, level 54 knight (Ra) Valhalla Dky the Goat, level 35 conjurer(Ra) Dky Sven, level 51 knight(Horus) Something |
01-19-2008, 09:17 AM | #6 | |
Initiate
Join Date: Jun 2007
Posts: 159
|
Quote:
If you think about signing the installation package (windows only, linux users just download the launcher) with some kind of certificate, I never really understood why this would help. I mean, how many people really do think twice if windows says "This file is not signed, it may not be safe" or whatever the real text is, and click on "Run anyway"? And publishing hash values of the installer on the web site doesn't help because if you are able the redirect the download to a site of your own, you can surely adjust the values accordingly. And you wouldn't get past the check/download procedure mentioned above anyway. Going back to the original question, I think think the only real security issue Regum has is the same that all account-based application/games/web sites have: social engineering. That means getting other people to tell you your account data including the password. This is why there is a bold red text every time you start the game that tells you not to give your password to anyone. Edit: added a few more thoughts
__________________
Ra: Lucinda {Silverbow,Wintersun,Ironfist} Horus: Laleja - Conjurer (42) Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr Last edited by Nikor; 01-19-2008 at 09:29 AM. |
|
01-19-2008, 09:36 AM | #7 | |
Initiate
Join Date: Jun 2007
Posts: 159
|
Quote:
__________________
Ra: Lucinda {Silverbow,Wintersun,Ironfist} Horus: Laleja - Conjurer (42) Retired: Laleja / Faer / Nalys Silverbow / Tain / Vorr |
|
01-19-2008, 12:37 PM | #8 | |
Marquis
Join Date: Mar 2007
Location: Edge of the Abyss
Posts: 2,066
|
Quote:
|
|
01-19-2008, 02:47 PM | #9 |
Initiate
Join Date: Jul 2007
Posts: 101
|
DM, was their password a word that could be found in a dictionary list?
NGD, the forum has a 15 minute lockout if you fail the password 5 times - does the main website (and the game server) have anything to stop a dictionary-list or brute-force attack in a similar way to this? I've tried SQL injection against my own account but couldn't force my way in through the main site or via the client app's login system. To me, the biggest risk is with someone releasing a 0-day hack for vBulletin and for someone to leech all the passwords, converting the hash back to the original password using an MD5 string database (for example) - mainly because I've known sites that have had this happen to them. Last edited by Drah; 01-19-2008 at 03:02 PM. |
01-19-2008, 03:54 PM | #10 | |
Initiate
Join Date: Jul 2007
Location: Germany
Posts: 197
|
Quote:
|
|
|
|