New Security features-great! Alittle too late!

General Discussion Started Last reply 19 posts
Finally NCsoft decides to make their accounts much more secure like a bank! But thats much too late after being victimized twice! LAME!:mad:
Finally NCsoft decides to make their accounts much more secure like a bank! But thats much too late after being victimized twice! LAME!:mad:

you are a little late.. there is already a QQ thread about this.
Finally NCsoft decides to make their accounts much more secure like a bank! But thats much too late after being victimized twice! LAME!:mad:

What bank does this with dynamic IP?

This wouldent have saved your accounts for whatever reason.
doublepost :/
99.9% of people that get hacked/scammed on the internet just lack common sense. Would not matter if they had 10 secret questions someone will still get hacked

dont cry when something is improved
What bank does this with dynamic IP?

This wouldent have saved your accounts for whatever reason.
Patelco Credit Union, for example. They do it not for a single IP, but for the whole ISP's block of IP addresses (and they tell you which ISP is that).

But they don't do that to "save your account". They do that to meet the regulator's requirements on online banking.

And of course they don't ask questions that someone around you can guess (or, the other way around, can capture and use to compromise your security in other way). They ask which on the addresses (email, sms) from your profile they should use to send you the one-time password.
Great?

If your computer gets hacked with a keylogger that can pick up your password, guess what they get? oh yah.... the answers you type in.

If they can **** your account, not only do they get your password for a game, they get your RL address, your email for spam lists, your payment method, and everyone's favorite question, mother's maiden name too?

How intelligent is it to actually give real info to a hackable system that can use the contents of your game account to open a new credit card # or steal your identity?

The point is, MOST thinking people will not disclose accurate personal info to a system that is not AT LEAST SSL certified (notice when you bank online, it lights up in green and is not http://, but https://... that's a scrambled connection). L2 does not have a SSL type of login.

The PROBLEM has never been security questions. This fixes NOTHING. The PROBLEM is their former lack of email notification that anything in your master account was even changed. NOW that's been fixed... which IS a good thing.

What's not a good thing is that they are asking people to remember answers to questions from up to 7 years ago. If you are 20 today, 7 years ago you were 13, and your parents paid for your account. Think they wrote down their credit card #'s from 7 years ago? They probably got new #'s by now, and if they are normal parents, they have more than 2 credit cards... they can remember this? Not. Over years, many people move, lives change. Few people are going to remember some flippant hint question or answer to a game they thought would be like a Nintendo game, play a month, toss.

It says a LOT for Lineage 2 as a game that we keep coming back, that we CARE this much about it. But staking someone's years of investment on a few questions, answered when they didn't yet appreciate the game makes no sense. People don't remember what they ate for lunch on any given day, just a week ago. Why should anyone remember a distracted moment years ago, when they didn't think the answer mattered? To lose years of hard work to something so silly is a pain and suffering lawsuit waiting to happen.

That said, I got my password problem sorted out by NCSoft. Thank you NCSoft.

However, I still think it needs to be reset for everyone, because I dont' want to play this game only with new players and people who bought accounts from intentional sellers (who therefore did write down the answers for their customers, unlike normal humans).
i dont know why u guys are so up on the dynamic ip issue.... yes the ip changes, but the location doesnt. This is done so that they know if some one from the same local area is accessing ur acct or from another country. IE an asian based IP accessing a canadian based IP master acct.

I think this further strengthens acct security, and can potentially stop acct buying and selling to different locations, and stop acct hacking as they can exchane IP info between master acct and game acct logins.
Some time ago (not long) I received information from google, that someone logged into my gmail account from a chinese IP. It could have been disaster, if I didn't get this information in time.
So I find any form of checking IP quite useful.
Great?

If your computer gets hacked with a keylogger that can pick up your password, guess what they get? oh yah.... the answers you type in.

If they can **** your account, not only do they get your password for a game, they get your RL address, your email for spam lists, your payment method, and everyone's favorite question, mother's maiden name too?

How intelligent is it to actually give real info to a hackable system that can use the contents of your game account to open a new credit card # or steal your identity?

The point is, MOST thinking people will not disclose accurate personal info to a system that is not AT LEAST SSL certified (notice when you bank online, it lights up in green and is not http://, but https://... that's a scrambled connection). L2 does not have a SSL type of login.

The PROBLEM has never been security questions. This fixes NOTHING. The PROBLEM is their former lack of email notification that anything in your master account was even changed. NOW that's been fixed... which IS a good thing.

What's not a good thing is that they are asking people to remember answers to questions from up to 7 years ago. If you are 20 today, 7 years ago you were 13, and your parents paid for your account. Think they wrote down their credit card #'s from 7 years ago? They probably got new #'s by now, and if they are normal parents, they have more than 2 credit cards... they can remember this? Not. Over years, many people move, lives change. Few people are going to remember some flippant hint question or answer to a game they thought would be like a Nintendo game, play a month, toss.

It says a LOT for Lineage 2 as a game that we keep coming back, that we CARE this much about it. But staking someone's years of investment on a few questions, answered when they didn't yet appreciate the game makes no sense. People don't remember what they ate for lunch on any given day, just a week ago. Why should anyone remember a distracted moment years ago, when they didn't think the answer mattered? To lose years of hard work to something so silly is a pain and suffering lawsuit waiting to happen.

That said, I got my password problem sorted out by NCSoft. Thank you NCSoft.

However, I still think it needs to be reset for everyone, because I dont' want to play this game only with new players and people who bought accounts from intentional sellers (who therefore did write down the answers for their customers, unlike normal humans).

finally someone else that has a clue

Anyone thinking that their account is more secure due to this "new" security system is unfortunately blissfully ignorant... nieve ... or a complete fool...
i dont know why u guys are so up on the dynamic ip issue.... yes the ip changes, but the location doesnt. This is done so that they know if some one from the same local area is accessing ur acct or from another country. IE an asian based IP accessing a canadian based IP master acct.

I think this further strengthens acct security, and can potentially stop acct buying and selling to different locations, and stop acct hacking as they can exchane IP info between master acct and game acct logins.

while the initial concept is well.... thoughtful at most....

it's still a joke because through the use of proxies... that make the hole "IP" denied system a pitiful joke.. and at most only slows down a hacker for a moments notice...

either way it doesn't apply to a player in game.. just to the master account.. which is at high risk with utterly no change to possibility of theft due to the fact that like mentioned above... keyloggers see right through it.
i beleive (have no proof lol) that this is put in place so they can match ip locations between master and logged in accts better.

i believe this was done to stop the " im going to sleep log me in at ur location so i can get xp" and also when some one says "the acct is mine" they can better match acct ownership. i agree this really wont help much on the keylogging front...

but it SHOULD help on the rmt, afk xp front.
i beleive (have no proof lol) that this is put in place so they can match ip locations between master and logged in accts better.

i believe this was done to stop the " im going to sleep log me in at ur location so i can get xp" and also when some one says "the acct is mine" they can better match acct ownership. i agree this really wont help much on the keylogging front...

but it SHOULD help on the rmt, afk xp front.

AFK xp front... no... because if the accoutn is already active.... they just log in anyways as you can still log in even if the computer/ip hasn't been registered on the master account.. (main failasy of this implementation is that it's backwards)

Plus, IPS are logged anyways.. it's just not "reporting" those ips and logging them more clearly...

Everytime someone logs into the game the ip is recorded and sustained logging of that ip is continued, even the disconnection requests are logged...


However, the RMT is a good possibility.... but it's still mostly irrelivant....
yes but they could ban easier because they can now PROVE ur master acct (wich ur play accts are attached to) was accesed from another country. So unless u can prove u were in that country at that time, they can prove acct sharing and ban easier.
i beleive (have no proof lol) that this is put in place so they can match ip locations between master and logged in accts better.

i believe this was done to stop the " im going to sleep log me in at ur location so i can get xp" and also when some one says "the acct is mine" they can better match acct ownership. i agree this really wont help much on the keylogging front...

but it SHOULD help on the rmt, afk xp front.

GM's can already see through IP logs from where a char is logged in, they have always been able to do so..
yes but they never could prove the IP of the master acct...

this is all about matching IP between master and game accts
yes but they could ban easier because they can now PROVE ur master acct (wich ur play accts are attached to) was accesed from another country. So unless u can prove u were in that country at that time, they can prove acct sharing and ban easier.

Good Luck with that in Europe as that's an infringement of our privacy protected by law.

Ow and if NC Soft starts banning account sharing then just pull the plug out of the servers and stop pretending cause the combination of what's going on right now with that & the Godess of Destruction update is enough to ensure the end of L2 in NA/Europe.
The point is, MOST thinking people will not disclose accurate personal info to a system that is not AT LEAST SSL certified (notice when you bank online, it lights up in green and is not http://, but https://... that's a scrambled connection). L2 does not have a SSL type of login.

When I go on NCSoft Website, my connexion is SSL certified
http://img263.imageshack.us/img263/4741/sslr.png

But except this one, I agree with the rest of your post :)
Indeed all sites that request a master/game account password should REQUIRE full SSL encryption..

but they don't....