Mouse input, combined with a randomized keypad on every log-in (The numbers are in different positions every time), will work to trump any keylogging attempts and possibly bot programs that log into the game automatically.
I think that every character has a different passkey, so even if someone "shares" a buffer, the other main characters will remain locked out from access.
This is already used in AION NA/EU. To be honest it's very annoying as you have to enter this everytime you log in your character and no you cannot use keybord! You have to do this with mouse and the numbers are randomly distributed every time. But this probably saves **** load of money on costumer support as accounts does not gets hacked.
Many MMORPG's are using this type of system now for added security. You have to enter a security pin number of your choosing, once you have it set you have to type it in every time you want to log in.
Very good thing imo. But to make it more comfortable, should be like this - you must enter code only once per each character for each account login. So changing character of same account (without actual relog) would be much much faster.
a different pin per character.. that would be so bad.. I have enough trouble with all my real life passwords and pins without adding another 7 to my life..
a different pin per character.. that would be so bad.. I have enough trouble with all my real life passwords and pins without adding another 7 to my life..
1 pin should be enough...
7 ??? What about ppl with 3 accounts ? 5 ? 11 ??
However, I am willing to test this if bots will have a trouble bypassing it. If it is clientside stuff, bot will be able to catch the packets once and send them knowing the encryption key. If the keypad is server generated and click locations instead of numbers are sent to the server, then it will be a bit hard for OOG clients, but the ingame ones shouldnt have a problem.
M
Many MMORPG's are using this type of system now for added security. You have to enter a security pin number of your choosing, once you have it set you have to type it in every time you want to log in.
Good idea in my opinion. :)
Agreed, one exanple of this kind of system is found in Requiem The Bloodymare. It actually works quite well.
If it is the same system as in Aion (the NA Aion servers already have this right now), it works like this:
- it is ONE PIN for ALL characters on an account
- you only have to enter the PIN the first time you log in and choose a character. If you relog to character selection, you do not have to reenter it. If you restart the game (login screen), you have to enter it again
- and yes, the numbers on the buttons change each time, so even a trojan which registers mouse movement cannot defeat this system
The only flaw which I see is that you can reset the PIN from your master account. And the login to the master account can still be stolen via a keylogger.
If it is the same system as in Aion (the NA Aion servers already have this right now), it works like this:
- it is ONE PIN for ALL characters on an account
- you only have to enter the PIN the first time you log in and choose a character. If you relog to character selection, you do not have to reenter it. If you restart the game (login screen), you have to enter it again
- and yes, the numbers on the buttons change each time, so even a trojan which registers mouse movement cannot defeat this system
The only flaw which I see is that you can reset the PIN from your master account. And the login to the master account can still be stolen via a keylogger.
This way there IS one method for bots to continue botting through this sytem, though I won't tell it. We have more than enough bots already...
It is not intended as an anti-bot feature, it is an anti-keylogger feature. And as many stolen accounts as I have heard of recently, it is definitely needed.
Someone mentioned it as anti-bot feature as well, but it won't work that good for such purpose.
As anti-keylogger sounds really cool. No doubts so far :)
This way there IS one method for bots to continue botting through this sytem, though I won't tell it. We have more than enough bots already...
Do you think they dont know it already ? Ingame clients will have no problem as the actual login is done by ppl, but OOG ones will have some trouble. It will be harder to run the whole train on only one computer and at sieges will be even harder given the lag and all. That is, if the keypad is server side, not local, because if the client sends directly the code instead of mouse clicks, then oog clients will have only minor reprogramming issues, nothing serious.
M
Yeah, me too ... got four of those sitting on my desk here right now. Those sure would make things quite a bit safer, though (especially if you could also link them to your master account login). But I see how they would make account sharing somewhat impossible :D
But I see how they would make account sharing somewhat impossible :D
And why would that be a bad thing... If that would not be allowed in a verifiable way, then the game would have more difficulty, more ppl will seek party, it will be more of a MMO. I wouldnt go as far as allowing only one account per person, however, more than 2 is already bad. I use both of these features, but not because i like it that way, but because it is allowed and it makes life easier, but if all ppl have same interdiction (no more than 2 accounts, no more sharing) I think the game would improve overall.
M
o yeah and the day you get a heavy cold you can´t log in...
What about deaf and/or mute ppl ? Or have to choose between the local derby or L2 in the week-end, not only during the actual game, but 2 days after till your voice is back a bit...
Fingerprint reader FTW, ask for another read every 20 minutes or be logged out except in shop mode, etc :) Then dont break your finger, burn it, or register all fingers...
Seriously, fingerprint readers are cheap, that could be a solution also. Then, no-hands ppl will the only ones left out :P
M
Well, you should be in bed, dont ya think ?
Ehhh.. who am I kidding..
And you cant play L2 in bed ??? Doesnt mean that if you are in bed you can only sleep... AFAIK most ppl play L2 in their sleep too, so that wouldnt be a problem either.
M
Yeah, me too ... got four of those sitting on my desk here right now. Those sure would make things quite a bit safer, though (especially if you could also link them to your master account login). But I see how they would make account sharing somewhat impossible :D
The keys are active for a minute, plenty of time to MSN the fob owner and get the secure id #. I mean who doesn't have their phone attached to their hip these days? or constantly on MSN on your desktop or phone?
So now the keylogger has to catch the mouse click and simultaneously take a screenshot of the 50 pixels or so around the mouse.
I know 12 year olds that could get that up and running in no time at all, hell I'm pretty certain that once the image is taken, an OCI library can be used to translate the image into a number so that the images themselves don't even have to be collected.
My bank used to do something similar and even they removed it after a few months. This is not an added security layer at all, there is zero point in implementing it.
The people that come up with these ideas need to start asking the advice of actual penetration testers, preferably those with a background in data mining and malware development.
I'm not 12 years old any more, so I don't know if you are right Priest. I suspect that it would not be possible to make a key logger that could record mouse clicks, get and temporarily store the image, do an image comparison and squeeze all that into as small a package as the current key loggers are. To say nothing of the problem they have identifying the specific screen they want mouse clicks from, or will they record every mouse click you do once they are active? I would suspect the load on the CPU would be noticeable unless you are lucky (wealthy) enough to have the latest greatest most powerful CPUs on the market. In which case, I would assume you can afford the security to keep key loggers off your L2 computers.
And if it doesn't work, then NC will just have to do more.
The first line of your statement makes very little sense to me.
The rest of it though I can respond to.
Retrieving a list of open windows is simple, even my graphics card's management software automatically detects when L2 is running and adjusts profile settings accordingly. It's a few lines of code thanks to windows APIs.
Windows again handily provides the necessary functionality to take a screenshot of any part of the screen and then store it either in memory or on the local disk drive, windows APIs also allow simple tracking of mouse coordinates and click states with only a few lines of code.
OCI libraries are also available from within windows vista and 7 as default, windows APIs allow one to interact with those libraries at will.
A standard keylogger with some sort of delivery function (ftp, email, reverse connection, sms, etc) would likely not bloat up by more than a few kilobytes when all is said and done.
Doing more doesn't help anybody very much, doing less but doing it right is the way to go.
The keys are active for a minute, plenty of time to MSN the fob owner and get the secure id #. I mean who doesn't have their phone attached to their hip these days? or constantly on MSN on your desktop or phone?
me my cell never comes in my house if im not on the job it not on me i have no use for them and wouldnt have one if i didnt have to have it for job as it is i dont have one it belongs to the company
Ultimate security option would be: Face reading software. No passwords would be needed.
I said fingerprint reader, but that is ultimately useless, as there are hardware emulators for keyboards and mice so you dont actually need to run any software to bot, the fingerprint can be saved and used in a fingerprint reader emulator, same with face, etc.
M
Thanks Priest. I more or less stopped taking an interest in computer programming years ago. I forgot that MicroSoft would have added all the necessary software to make security almost impossible on machines running their OS. Makes their machines easy to program, so anyone with nothing better to do can craft trojans and malware, as well as those programmers who are creating items of value.
I personally find it funny that if you read this entire thread, everyone cares about what everyone else has to say except MaoMao. Which I'm fine with, because from what I've seen, MaoMao doesn't really say much of anything helpful on this thread, or anywhere else. On topic, at least manually clicking would help a bit with getting rid of automated software!
... the fingerprint can be saved and used in a fingerprint reader emulator, same with face, etc.
M
Yes, because I'm going to stalk someone to steal his fingerprint, just so I can get into his L2 account.