Celtic Heroes

The Official Forum for Celtic Heroes, the 3D MMORPG for iOS and Android Devices

What's OTM's policy on guessing passwords?

#1
Hey guys and OTM, a friend of mine had his password guessed, someone then decided to take a shed load on super combos I gave him and all his gear.
I now for a fact that his password wasn't shared with anyone so I was just wondering what your plan of action is for this situation.

I'm not sure overly fussed about my stuff that is gone but a minor cannot easily buy what was taken from him.

Thanks


Donko
D0nk0 Lvl143 warrior
D1nk1 lvl90 druid (retired)
D2nk2 lvl70 ranger (retired)
D3nk3 lvl128 druid (dual log)
D4nk4 Lvl142 ranger (tri log)
D6nk6 lvl80 mage (retired)

General of PRIME
Proud owner of 2 full darkflame sets

D5nk5 lvl85 rogue (arawn)

Re: What's OTM's policy on guessing passwords?

#2
They need to up there security defainitly 100%

(there probably a going to reply to this whole posts with your information is safe on our servers)

#1 A cool down period if a password is entered incorrectly so many times too quickly the account gets locked for 24 hours and a email notification sent to the owner telling them someone tried to acsses there account this gives owner a chance to change password to something more difficult .(currently do not have this i believe as I entered my password incorrectly 6-7 a few days ago then got it correct and logged in with out any warning)

2# If your account is logged in from a different device you have not used before u should be warned via email or a i game message to warn you there may be a breach.

3# I have always believe that our bank should have a 4 digit pin code ( e.g 3728) for people to place there items in when there offline as a extra precaution to those who are weary then if someone does gain access to your account they won't know your combination to your bank to steal items.(I don't know if anything has been mentions about this before or if they are implementing it apologies if it has)

#4 Password reset system it is quick and effective at the minute but easy to exploit,if someone gains your password they can change it too easily even if you do receive a email telling you it was changed. when you want to reset your password you should be sent a link to your email address you then click the link to change password, and then only you can change password via your own email meaning if anyone gains unauthorised access to your account they can't change password and with #3 option above aswell they faint gain items.

#5 email verification make every one that makes a CH account have a email and it MUST be verified befor they can begin to play the game.

#6 when first making your account on your first device you should be asked a security question
E.g (alot of games have this implemented)
Where was you mother born
what was your first school called
who was your best friend
what is your DOB
Your favourite town

Something along those lines and then when you log into your account on a different device you have to enter correct username,password, and security code to be able to play on the new device simple things making people feel sale and making them safer

No doubt as the games grows bigger and bigger over they years you will attract more people and just like every single game you will get people trying to crack and hack more best be prepared in advance then get caught out.

I am not aware that they have any of the above implemented if they already do apologies but that's just a few things that can make it harder for people to gain accesses to accounts and take things.

OTM please don't reply with the bull unfathomable of your passwords are safe on out 1000 bit encrypted servers and the only way you can get hacked is if you give out info yes we already know that however things could be improved still.
Ghandi--Druid

Who is online

Users browsing this forum: No registered users and 4 guests