Project 1999

Go Back   Project 1999 > Blue Community > Blue Server Chat

Closed Thread
 
Thread Tools Display Modes
  #11  
Old 02-13-2014, 05:54 PM
myriverse myriverse is offline
Planar Protector

myriverse's Avatar

Join Date: Jan 2013
Location: Swamp of N.O. Hope
Posts: 2,470
Default

Quote:
Originally Posted by Kainzo [You must be logged in to view images. Log in or Register.]
I just hate that something so simple isn't possible.
From what I've heard, it's not as simple as you might think. I don't think passwords are stored in plain text, so much work needs to be done in order to retrieve them.
__________________
Gnawlunzs Phrogphry
Master Angler, Baker, Cadger, Drunk
"If you can't eat a frog, then eat two."
  #12  
Old 02-13-2014, 06:00 PM
tristantio tristantio is offline
Fire Giant

tristantio's Avatar

Join Date: Nov 2010
Posts: 888
Default

Does the login have a limit to failed attempts?

If not, seems like you could figure it out.

Non-plain text password is a good thing, but I wonder how complex the password that is stored is?

Even if they didn't want to spend the time creating a reset password process to change the pass, giving us the crypt used to create it (or hash+salt formula) and the encrypted pass itself, would allow someone to easily discover the plain text pass they used initially by running it through something.
__________________
Realtime auction logger: http://ahungry.com/eqauctions/
  #13  
Old 02-13-2014, 06:04 PM
loramin loramin is offline
Planar Protector

loramin's Avatar

Join Date: Jul 2013
Posts: 10,258
Default

I don't think it's the technical difficulties. It's true that reading a hashed password is really hard, but replacing one hashed password with another (ie. changing your password) is really easy.

The hard part (and I imagine the reason the staff won't do password changes until that cellphone thing is ready) is making sure you're supposed to change the password. After all, I could just say "hey GMs , that account of Bob's is really mine; can you change the password for me?" and take over his account. Unless the GMs know for sure that I'm the owner of the account (ie. if I can shoot them a text message from a phone they know owns that account), they don't know whether they're helping a forgetful person or a malicious scammer.

Technology = easy ... it's the humans that are hard.
  #14  
Old 02-13-2014, 06:09 PM
Ele Ele is offline
Planar Protector

Ele's Avatar

Join Date: Jan 2011
Posts: 5,290
Default

If you petition on the forum nicely, you might be able to get them to reassign the name and guild leadership on a new character under the same Emu account, but separate login account.

Your other stuff is lost for now though. [You must be logged in to view images. Log in or Register.]
  #15  
Old 02-13-2014, 06:11 PM
loramin loramin is offline
Planar Protector

loramin's Avatar

Join Date: Jul 2013
Posts: 10,258
Default

P.S. You would think that you could verify people with email, but email itself can be easily hacked (see: Sarah Palin's email a few years ago). Regardless of whether email actually gets hacked or not, the devs would have to deal with people claiming that their email was hacked, and I imagine that could easily become a nightmare as it ultimately boils down to a "he said, she said" situation.

They avoid hours and hours (if not days and days) of CSR work with their current policy.
  #16  
Old 02-14-2014, 06:18 PM
Kainzo Kainzo is offline
Sarnak

Kainzo's Avatar

Join Date: May 2010
Posts: 254
Default

Quote:
Originally Posted by loramin [You must be logged in to view images. Log in or Register.]
P.S. You would think that you could verify people with email, but email itself can be easily hacked (see: Sarah Palin's email a few years ago). Regardless of whether email actually gets hacked or not, the devs would have to deal with people claiming that their email was hacked, and I imagine that could easily become a nightmare as it ultimately boils down to a "he said, she said" situation.

They avoid hours and hours (if not days and days) of CSR work with their current policy.
Yeah, understandable - I guess I just don't have it in me to re-level and rejoin P99 heh
__________________
Lord Kainzo
GM of Disposable Heroes
҉Are you Disposable?҉
  #17  
Old 02-14-2014, 08:15 PM
baalzy baalzy is offline
Planar Protector

baalzy's Avatar

Join Date: Mar 2011
Posts: 1,860
Default

I wonder how Rog would feel about someone trying to brute-force a LS password lol.
__________________

Baalzy - 57 Gnocro, Baalz - 36 Ikscro, Adra - 51 Hileric, Fatbag Ofcrap - 25 halfuid

Red99
Baalz Less - Humger, Baalzy - Ikscro

If MMORPG players were around when God said, "Let there be light" they'd have called the light gay, and plunged the universe back into darkness by squatting their nutsacks over it.
Picture courtesy of azeth
  #18  
Old 04-03-2014, 11:36 AM
Kainzo Kainzo is offline
Sarnak

Kainzo's Avatar

Join Date: May 2010
Posts: 254
Default

Quote:
Originally Posted by baalzy [You must be logged in to view images. Log in or Register.]
I wonder how Rog would feel about someone trying to brute-force a LS password lol.
Has already happened... heh
__________________
Lord Kainzo
GM of Disposable Heroes
҉Are you Disposable?҉
  #19  
Old 04-03-2014, 12:09 PM
Swish Swish is offline
Planar Protector

Swish's Avatar

Join Date: Nov 2010
Posts: 19,996
Default

Quote:
Originally Posted by Fame [You must be logged in to view images. Log in or Register.]
[You must be logged in to view images. Log in or Register.]
[You must be logged in to view images. Log in or Register.]
[You must be logged in to view images. Log in or Register.]
[You must be logged in to view images. Log in or Register.]
  #20  
Old 04-03-2014, 01:20 PM
Quineloe Quineloe is offline
Sarnak


Join Date: Nov 2009
Posts: 304
Default

Quote:
Originally Posted by myriverse [You must be logged in to view images. Log in or Register.]
From what I've heard, it's not as simple as you might think. I don't think passwords are stored in plain text, so much work needs to be done in order to retrieve them.
there not being a way to reset the password tied to a specific account is pretty much amateur hour, though

But this basically is an amateur project, soooo...

choose passwords you can remember. Write down what you can't. I hate pretty much everything that is related to passwords, but don't let that get the better of you. I didn't play for 4 years and I was able to log in, because master password for everything.

Also, is there really no email account tied to our eqemu accounts?
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 11:12 AM.


Everquest is a registered trademark of Daybreak Game Company LLC.
Project 1999 is not associated or affiliated in any way with Daybreak Game Company LLC.
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.