1. Here you will find official announcements and updates. These announcements are also linked in the Official SotA Discord server.
    We encourage comments from the community! To keep the announcements official, we ask that comment threads be created in the General forums for player input.

                                                 Thanks!

Password Change Request Due to Other Sites Being Compromised

Discussion in 'Announcements' started by Berek, Aug 11, 2016.

Thread Status:
Not open for further replies.
  1. King Robert

    King Robert Avatar

    Messages:
    522
    Likes Received:
    1,501
    Trophy Points:
    63
    Gender:
    Male
    Thank you portalarium for working so hard on the game we love and the security we need.
     
  2. Nox Haven

    Nox Haven Avatar

    Messages:
    113
    Likes Received:
    240
    Trophy Points:
    30
    Gender:
    Male

    I use 1Password to manage passwords (mac/win). It basically generated a 26 character length password of caps, symbols, letters and numbers. So 26 characters works fine here.
     
    John Markus likes this.
  3. gadget

    gadget Avatar

    Messages:
    66
    Likes Received:
    60
    Trophy Points:
    8
    Gender:
    Male
    Location:
    Hayward, CA
    2FA with support for yubikey
    batten down the hatches
    force on users from the get go
    makes everyone'e experience better
     
  4. MeddlingMonk

    MeddlingMonk Avatar

    Messages:
    14
    Likes Received:
    38
    Trophy Points:
    3
    I made my new password 32 characters long, which is my preferred length, and the site didn't complain it was too long. No idea what the upper limit is, supposing there is one (there usually is).
     
    Beaumaris likes this.
  5. Rebelweasel

    Rebelweasel Avatar

    Messages:
    109
    Likes Received:
    234
    Trophy Points:
    18
    Location:
    Las Vegas, Nevada
    The only caveat I would put on an authentication system is what others have said, don't make it cost the players extra money because not all can afford it and you'd effectively lock them from their game. In addition, I know it's hard to believe, but keep in mind not everyone on the planet gets a smart cell phone. There are still many many people who use standard phones or even neanderthal cell phones, so the forces use of a smartphone app will also isolate some people from the game.
     
    Saosis and Fister Magee like this.
  6. Mitch [MGT]

    Mitch [MGT] Avatar

    Messages:
    489
    Likes Received:
    1,042
    Trophy Points:
    43
    Gender:
    Male
  7. Wintermute of CoF

    Wintermute of CoF Avatar

    Messages:
    1,372
    Likes Received:
    2,432
    Trophy Points:
    113
    Gender:
    Male
    Location:
    London, United Kingdom
    NIST is actively warning against using SMS, not phones with 2FA apps.
     
    Black Tortoise likes this.
  8. agra

    agra Avatar

    Messages:
    1,501
    Likes Received:
    3,489
    Trophy Points:
    113
    It will happily accept 50 characters at least. :)
     
    Beaumaris likes this.
  9. nakunaru

    nakunaru Avatar

    Messages:
    1
    Likes Received:
    7
    Trophy Points:
    3
    For the person who is responsible for the mail who was sent out. Please reconsider the use of tracking links in such important mails.
    You send out mails to people that they should change their password and provide a link to your website. But the link doesnt point to your website "shroudoftheavatar.com", rather it points to "http://shroudoftheavatar.us4.list-manage.com" which will be redirectet later to your orginal site.
    Thats exactly the same like scamming mails works, like the paypal ones i am getting daily which are saying "please change your password - login here paypal.bad-scammer.com"

    Just simple rule for people - never click on links in mails - go to the website manually and dont use the same username/password combination all the time.
    And for companys - dont provide password change links who dont point to your own site direkty, they are just not trusthworty and thats the least you want, that people cant trust your very important mails.
     
  10. Kytail

    Kytail Avatar

    Messages:
    198
    Likes Received:
    433
    Trophy Points:
    18
    Location:
    Arizona
    Does Steam actually require 2FA? Because it's not required on my Wife's Steam account.

    Nonetheless, I don't even know my SotA password. I set it to some ridiculously-long random string of characters, and put that away inside my password database. At least the Steam login has 2FA. ;)
     
  11. Tahru

    Tahru Avatar

    Messages:
    4,800
    Likes Received:
    12,170
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Spite
    I have to say that I really don't like capcha.
     
  12. stidesx

    stidesx Avatar

    Messages:
    46
    Likes Received:
    91
    Trophy Points:
    8
    Took me 4 tries on the stupid cantcha, hate 2 factor even more, especially with a game that has me switching between friends only and mmo.

    That said, it's shitty to have to try to protect against such things, and it's really really difficult to balance convenience and security. Good luck to the team.
     
  13. Ronan

    Ronan Avatar

    Messages:
    1,792
    Likes Received:
    2,614
    Trophy Points:
    113
    Location:
    Wild in Westend!
    The capcha is probably temporary. Quick to put in place to ward off multiple attacks.
     
    Duchess Fionwyn and Tahru like this.
  14. Tahru

    Tahru Avatar

    Messages:
    4,800
    Likes Received:
    12,170
    Trophy Points:
    165
    Gender:
    Male
    Location:
    Spite
    Google has mastered captcha with the "I am not a robot" button. That feature is free to everyone on the Internet to use.
     
  15. Wintermute of CoF

    Wintermute of CoF Avatar

    Messages:
    1,372
    Likes Received:
    2,432
    Trophy Points:
    113
    Gender:
    Male
    Location:
    London, United Kingdom
    Tahru likes this.
  16. Satan Himself

    Satan Himself Avatar

    Messages:
    2,702
    Likes Received:
    12,806
    Trophy Points:
    165
    My login name is 2fa and my password is yubikey melikey. So far no hacking. :rolleyes:
     
    Tahru likes this.
  17. Black Tortoise

    Black Tortoise Avatar

    Messages:
    1,961
    Likes Received:
    3,655
    Trophy Points:
    125
    Gender:
    Male
    Location:
    Storm's Reach
    I still get these wrong sometimes too. "Oh, I could have sworn that was a french fry!" and "Oh, that did not look like a car" etc...

    But yes generally theyre much nicer than old school recaptcha
     
    Tahru likes this.
  18. Kytail

    Kytail Avatar

    Messages:
    198
    Likes Received:
    433
    Trophy Points:
    18
    Location:
    Arizona
Thread Status:
Not open for further replies.