Do you think I could just leave this part blank and it'd be okay? We're just going to replace the whole thing with a header image anyway, right?
You are not logged in.
Pages: 1
So when will our passwords be encrypted? Is this still a thing?
Because imagine following:
> PC1 is infected by virus
> PC1 grabs Wifi stuff
> You log into EE with PC2, which is in the same Wifi
> Virus has your login information
This can happen even when you're at home.
Because e.g. your grandpa's PC1 is infected.
EE, at least use some kind of encryption. An encryption method,
where the password can't be reverted back (which should be standard since a long time, though).
Because these passwords are for some people the key for every lock in the www.
Paypal, Amazon, Facebook, Forums, Tinder etc.
As user you should think about changing passwords by now though.
Shouldn't this be more important, than inventing campaigns n' stuff?
Offline
Assuming that this is the case, if passwords aren't encrypted, and goods purchased with real money (i.e gems) are associated with our accounts, then that's a no no. At least HTTPS, and have it salted and hashed in the DB.
Offline
Looks important.
Then again, my password for ee was "password" for like four years... Lol
Offline
I don't think EE devs can do anything. Because It's Yahoo/PlayerIO that need to fix it.
I hope they will add HTTPS instead. Not that I care so much because I use different passwords everywhere anyway.
Offline
You can always use md5 or basic stuff @capasha, even if it's not perfect. They don't have to use HTTPS right away though.
Also, Yahoo/PlayerIO are not an acceptable excuse for such major flaw, in my opinion.
Offline
You can always use md5 or basic stuff @capasha, even if it's not perfect. They don't have to use HTTPS right away though.
Yahoo/PlayerIO are not an acceptable excuse for such major flaw, in my opinion.
True.
Offline
That being said, if we have to wait for PlayerIO to speed up, why not find an alternative server solution? Write your own dang connection code.
Besides requiring a lengthy rewrite for a great deal of software...
Those who can't do, teach.
A common mistake that people make when trying to design something completely foolproof is to underestimate the ingenuity of complete fools.
It is a well-known fact that those people who must want to rule people are, ipso facto, those least suited to do it... anyone who is capable of getting themselves made President should on no account be allowed to do the job.
I think fish is nice, but then I think that rain is wet, so who am I to judge?
For a moment, nothing happened. Then, after a second or so, nothing continued to happen.
Offline
Password Hunt 2015
Watch your passwords, they'll change everyday.
This is a false statement.
Offline
Creature wrote:Password Hunt 2015
Watch your passwords, they'll change everyday.
Making my password a gem code.
Imagine this (already happened):
- a hacker gets a player's email (added as friend)
- brings up C#/C++ pass cracker program
- spams letters in pass till it joins
So here is something you should do:
everytime you press the login button, refresh the page automatically:
Hax0rs will no longer work
Offline
yay for being a kongur
Offline
That being said, if we have to wait for PlayerIO to speed up, why not find an alternative server solution? Write your own dang connection code.
Besides requiring a lengthy rewrite for a great deal of software...
Because EE is *very* dependent on Yahoo Games Network. It's not just connection code, they store all the account information, levels, and provide multiplayer support. The game would have to be completely rewritten and every bot ever created would be broken. Also, the player account system is standardized throughout YGN, the Everybody Edits staff didn't design it.
Offline
Which does not change the fact they could salt and hash it.. Or do something to at least fix it a little bit.. @lrussell
/mobile
Offline
I'd like to hear from an admin or moderator regarding this issue, to make sure that we're not misunderstanding something.
It will be addressed sooner or later.
Lame!
Offline
Which does not change the fact they could salt and hash it.. Or do something to at least fix it a little bit.. @lrussell
/mobile
Except it does since they have no control of how passwords are stored or verified. They'd need to nag Yahoo Games Network to get somewhere.
Offline
Mylo wrote:Which does not change the fact they could salt and hash it.. Or do something to at least fix it a little bit.. @lrussell
/mobileExcept it does since they have no control of how passwords are stored or verified. They'd need to nag Yahoo Games Network to get somewhere.
Which is usually like talking to a brick wall.
Discord: jawp#5123
Offline
But doesn't EE decide what passwords they store? Can't they store an already encrypted one? Also, I do think this is way more important than "sooner or later" - it should be more like "ASAP!" with actions following.
/mobile
Offline
But doesn't EE decide what passwords they store? Can't they store an already encrypted one? Also, I do think this is way more important than "sooner or later" - it should be more like "ASAP!" with actions following.
/mobile
As I've already said, EE is powerless to do any of this. Account registration, login, password changes, etc. is all handled by Yahoo Games Network. There is a function to register a new user within the universal API and you can view/delete them from their control panel. At any rate, I'm sure they hash them before storing them anyway. You're making this request to the wrong people. Regardless, a middleman attack would still be difficult to carry out. It's been like this for 5 years, so any potential damage is done.
Check your address bar, did you use HTTPS to login and view the forums? If not, congratulations! Your password may have been taken through a middleman attack.
Offline
Pages: 1
[ Started around 1731990003.5295 - Generated in 0.096 seconds, 11 queries executed - Memory usage: 1.71 MiB (Peak: 1.94 MiB) ]