Page 1 of 1
Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 2:04 am
by gacekssj4
Hello,
Just an idea, a friend of mine got hacked by dictionary attack. Somone had his secret guessed. And was auto added to white group. Which my friend had set as all access.
Not everyone know that and I think it would be more secure if white group (defualt one) couldn't have priviliges set. Only other groups.
Best regards
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 2:13 am
by Pjotr84
I think the best way to remedy this problem is to not set an HS if you don't need it. But how do you know your friend's HS was obtained by a dictionary attack?
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 2:42 am
by Ass_Kraken
What about the people that want to be able to set access without having to force that person to wait til the owner logs on? Maybe they shouldn't have set their homesecret on a claim, or had an obvious homesecret?
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 2:57 am
by Dallane
gacekssj4 wrote:Hello,
Just an idea, a friend of mine got hacked by dictionary attack. Somone had his secret guessed. And was auto added to white group. Which my friend had set as all access.
Not everyone know that and I think it would be more secure if white group (defualt one) couldn't have priviliges set. Only other groups.
Best regards
Need to make a better pword and not have white list set for anyone. More of a user error then anything
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 3:28 am
by colesie
HS: abc123
Works evrytiem
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 3:55 am
by Dallane
colesie wrote:HS: abc123
Works evrytiem
prewipe i had mine as Dallane.
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 9:29 am
by gacekssj4
The thief adminted how he did it. And it wasnt hard. Obvious secret.
Re: Default group priviliges disabled to extend security

Posted:
Sun Jan 27, 2013 9:42 am
by MagicManICT
As many user errors as the OP describes occurred, if anyone thinks there's been a legitimate attempt at a hack or brute force attempt at uncovering passwords, be it on the forum for an account or in game for a character, I'd suggest sending it in a PM to administration. The dev team may not be kosher with this and exact retribution on anyone that tries.