• Peter: Hacked Account... Authenticators?

    Characters: Rittal[85] Mieville[80] Terlan[80] Caltera[67] Dynia[67]
    Created: 2008-11-04 22:41:07

    Well it was going to happen at some point, and it now has. Sadly Aran's WoW account was compromised, they've sold pretty much all of his kit that sells and they've taken as much out of the guild bank as his rank permitted.

    They managed to get 80g and withdrew nearly 80 stacks of recipes and patterns, as the Member level is set to 20g and 20 stacks, they used two of Aran's characters at 2am and then again at 4am once the daily counts had reset.

    So Aran is now waiting for a GM to get back to him, I don't know if they'll refund the guild bank stuff straight away, or if Sara will have to petition as well. But it's probably worth waiting until Aran's heard one way or another.

    As a result of paranoia Dan, Sara, Aran and I have all just brought Blizzard Authenticators which are one time password generators, they are actually the same make that HSBC use for business banking. They work when you log into the game or account management you are asked for your username and password, and then a six digit random number the Authenticator displays. The idea being even if your details are exposed it's useless to them.

    Now I'm not about to suggest that we force everyone to go out and get authenticators however perhaps having a different rank "Authentic Elder" with the current bank restrictions and stricter restrictions on "Elder".

    We've always said and still maintain that the limits are to prevent things like this being too much of an issue. It'd may be a week or two before everything is sorted out properly, and if it happened during the start of Wrath it'd be a pain. Everyone would be welcome as always to request things above and beyond their stack limits.

    The authenticators are "only" £4.80, but postage is damn steep at £7.80. But if three people band together then it's not too bad.

    But this isn't a post to try and restrict fun, so feel free to shoot me down. Have we had our one hacked account? Should we worry more?

    P.
    "I may not have gone where I intended to go, but I think I have ended up where I needed to be." -- Douglas Adams
    • Carrot: Re: Hacked Account... Authenticators?

      Characters: Glorif[85] Heclan[73] Nathrezim[37] Cuchillo[23]
      Created: 2008-11-04 22:45:29

      I like the idea of only allowing people with authenticators to draw stuff out of the tab with the most valuable gear. As you said, we can always make it visible to others and they can request stuff. Maybe even push it to the latter 2 tabs being set up like that...
      Wash: This is going to get pretty interesting.
      Mal: Define interesting...
      Wash: Oh god, oh god, we're all going to die?
    • Peter: Re: Hacked Account... Authenticators?

      Characters: Rittal[85] Mieville[80] Terlan[80] Caltera[67] Dynia[67]
      Created: 2008-11-04 22:50:00

      I would be inclined to still permit it, but with a low limit of say 5 stacks. I know it's only 30 now, but that's enough to be a royal PIA.
      "I may not have gone where I intended to go, but I think I have ended up where I needed to be." -- Douglas Adams
      • Carrot: Re: Re: Hacked Account... Authenticators?

        Characters: Glorif[85] Heclan[73] Nathrezim[37] Cuchillo[23]
        Created: 2008-11-04 23:51:23

        Aye, it'd be really handy if you could put, say, a 10 stack limit per char, but also a 15 stack limit per acct. After all, people tend to have either 1 main or 1 primary alt they're levelling in any one day, so that would limit the danger of a person with 50 million alts.
        Wash: This is going to get pretty interesting.
        Mal: Define interesting...
        Wash: Oh god, oh god, we're all going to die?
      • Peter: Re: Re: Hacked Account... Authenticators?

        Characters: Rittal[85] Mieville[80] Terlan[80] Caltera[67] Dynia[67]
        Created: 2008-11-04 23:59:11

        Yah, I guess this could be acomplished by having an alt rank which has very little access. But could still be sent stuff via mail. It's finding the balance between safety and ease of use.

        P.
        "I may not have gone where I intended to go, but I think I have ended up where I needed to be." -- Douglas Adams
        • Sara: Re: Re: Re: Hacked Account... Authenticators?

          Characters: Tesandra[85] Sevelyn[82] Elveria[81] Valediren[80] Eláviel[20]
          Created: 2008-11-05 09:50:27

          I had always wondered why most of the big name guilds have "Alt" ranks, maybe this is one of the reasons. I'd never thought of it as a way of policing the guild bank access but I suppose it makes sense.

          I'd be more than happy to set this up, restrict access completely for people's alt characters, as mail between you and your alts is instant after all.
          "And then there's aggro to worry about."
          "What's 'aggro'?"
          "Well, it's complicated. But loosely translated, it means 'The Priest Dies.'"
        • Andy: Re: Re: Re: Hacked Account... Authenticators?

          Characters: Marlen[85] Egeria[81] Davarnon[80] Lyia[61] Krafla[34]
          Created: 2008-11-05 12:57:23

          This sounds like the best idea. Though what about 'bank' characters?
          "My interest in what you're talking about is low to moderate" -- Vork
        • Sara: Re: Re: Re: Hacked Account... Authenticators?

          Characters: Tesandra[85] Sevelyn[82] Elveria[81] Valediren[80] Eláviel[20]
          Created: 2008-11-05 14:53:35

          I was just going to treat bank characters the same way, they're meant to be banks for the person, not banks for the guild. Though really I'm thinking I don't really need mine now; I barely ever log on as her, guess its because I'm currently not saving up money for anything.
          "And then there's aggro to worry about."
          "What's 'aggro'?"
          "Well, it's complicated. But loosely translated, it means 'The Priest Dies.'"
        • Carrot: Re: Re: Re: Hacked Account... Authenticators?

          Characters: Glorif[85] Heclan[73] Nathrezim[37] Cuchillo[23]
          Created: 2008-11-05 15:38:13

          TBH my bank toon doesn't have much cash on it. I tend to store that on mains so I can use it easily, as it takes up no space. I use the bank toon as extra bankspace to store 'stuff'.
          Wash: This is going to get pretty interesting.
          Mal: Define interesting...
          Wash: Oh god, oh god, we're all going to die?
        • Sara: Re: Re: Re: Hacked Account... Authenticators?

          Characters: Tesandra[85] Sevelyn[82] Elveria[81] Valediren[80] Eláviel[20]
          Created: 2008-11-05 15:53:00

          I only really used mine for holding on to motes/primals as I have two tailors, and for saving money so I forget I have it, and hence don't spend it. She's more useful as a gold bank account than extra bag slots. I'm terrible for spending everything.
          "And then there's aggro to worry about."
          "What's 'aggro'?"
          "Well, it's complicated. But loosely translated, it means 'The Priest Dies.'"
    • Andy: Re: Hacked Account... Authenticators?

      Characters: Marlen[85] Egeria[81] Davarnon[80] Lyia[61] Krafla[34]
      Created: 2008-11-05 13:06:53

      Guess I'm going to have to wait to buy an authenticator until I get internet back at home seeing as the Blizzard store is blocked by LCC. Ohwell. Hope you're all having fun without me. I'm having a great time being away from you lot and am soo happy that I'm missing the pre wrath events, and potentially the release!
      "My interest in what you're talking about is low to moderate" -- Vork
      • Peter: Re: Re: Hacked Account... Authenticators?

        Characters: Rittal[85] Mieville[80] Terlan[80] Caltera[67] Dynia[67]
        Created: 2008-11-05 13:19:01

        Yah we're not missing you at all, not having to go instancing, or not completing all of the missing quests we have because they need a tank, or not being able to talk about shite. Not missing that at all....

        Bah!
        "I may not have gone where I intended to go, but I think I have ended up where I needed to be." -- Douglas Adams
    • Lee: Re: Hacked Account... Authenticators?

      Characters: Craylor[85] Cryten[80]
      Created: 2008-11-07 11:55:20

      Just thought i would let everyone know i have now bought one of these for myself and so has Mike James. Just waiting for them to arrive.
    • Sara: Re: Hacked Account... Authenticators?

      Characters: Tesandra[85] Sevelyn[82] Elveria[81] Valediren[80] Eláviel[20]
      Created: 2008-11-07 15:27:08

      As you've probably all noticed, I fudged the guild rankings a bit yesterday. By fudged, I mean fixed, but God it took forever. Poor Mike J was online, getting spammed by all the promotes and demotes.

      Effectively the ranking structure is the same as it was before.

      Station Manager
      Elder
      Elder Alt
      Member
      Member Alt
      Initiate
      Probationer

      All that's happened is I have moved people's main characters to be Elder / Member, which has access to the guild bank at a restricted level. Any other characters which people have are Elder Alt / Member Alt, and at those ranks the powers to do things are the same as the mains (i.e. they can invite, or promote, or change the MOTD if they should be able to) but guild bank access is restricted entirely to view and deposit.

      If you want to get something out of the guild bank, your main should do it and post it to your alts, thats the idea. That way we're restricting access should anything untoward happen in the future.

      What was suggested was that if Elder's buy authenticators, then we could create a new rank for people with extra account security who have a little more freedom. For this purpose a secret cow level placeholder exists, so should we implement this at a later date, I don't have to rename every frigging rank and demote everyone. Again. For the time being however, there is no secret cow level.

      If anyone would have preferred I chose another of their characters as their main, let me know and I can fix. Also comments / suggestions, let me know too.
      "And then there's aggro to worry about."
      "What's 'aggro'?"
      "Well, it's complicated. But loosely translated, it means 'The Priest Dies.'"
      • Andy: Re: Re: Hacked Account... Authenticators?

        Characters: Marlen[85] Egeria[81] Davarnon[80] Lyia[61] Krafla[34]
        Created: 2008-11-07 16:43:54

        I didn't notice
        "My interest in what you're talking about is low to moderate" -- Vork