dont release PASSWORDS

Discussion forum related to Nostalrius Begins in general.

dont release PASSWORDS

by shakey1 » Wed Apr 06, 2016 10:19 pm

"we will be releasing the source code, and anonymized players data (encrypting personal account data)"
Last edited by shakey1 on Wed Apr 06, 2016 10:41 pm, edited 2 times in total.
Divana - Druid <AKA the Bomb>
<Infamous> Officer
shakey1
Private
Private
 

Re: dont release PASSWORDS

by Slyox » Wed Apr 06, 2016 10:22 pm

passwords are saved as hashcodes, even if i would have your hashcode of the passcode, i couldnt log in. Get down mate.
Slyox
Tester
 

Re: dont release PASSWORDS

by Elu » Wed Apr 06, 2016 11:49 pm

But it does let people try to bruteforce passwords.

I hope they at least remove the emails, because I'm sure a lot of people are stupid enough to use the same password for their emails and nost accs.
Elu
Grunt
Grunt
 

Re: dont release PASSWORDS

by r00ty » Wed Apr 06, 2016 11:54 pm

Probably the best way to make it possible to recover accounts without giving away anything useful would be to only supply account id (to connect to character DB), hash of account name and hash of email address. No password hashed or otherwise.

That way, someone picking up the database could offer a form where a player enters their login name, and email address. The hash for both would match only one record. They could then build a new real record with the entered data (after email verification of course) and set a new password.

That's one way at any rate, which would preserve anonymity but provide a way to recover your account.

Character database I could would need to be clear text, so you could link characters to a single account. Actually that could be "kinda" anonymized I guess.

At any rate, provided they do it right, they CAN make your data recoverable without even disclosing your password hash. So, sit easy :)
Casual and proud.
User avatar
r00ty
Sergeant
Sergeant
 

Re: dont release PASSWORDS

by Plask » Thu Apr 07, 2016 12:03 am

Slyox wrote:passwords are saved as hashcodes, even if i would have your hashcode of the passcode, i couldnt log in. Get down mate.

Passwords under 8 digits without special chars are fairly easy to bruteforce
Sidesprang wrote:Defcap is overrated at current state of the game.
Plask
Sergeant Major
Sergeant Major
 

Re: dont release PASSWORDS

by r00ty » Thu Apr 07, 2016 12:07 am

Plask wrote:
Slyox wrote:passwords are saved as hashcodes, even if i would have your hashcode of the passcode, i couldnt log in. Get down mate.

Passwords under 8 digits without special chars are fairly easy to bruteforce
Yeah, it's made worse by the fact that passwords aren't case sensitive for Blizzard logins.
Casual and proud.
User avatar
r00ty
Sergeant
Sergeant
 

Re: dont release PASSWORDS

by Plask » Thu Apr 07, 2016 12:20 am

r00ty wrote:
Plask wrote:
Slyox wrote:passwords are saved as hashcodes, even if i would have your hashcode of the passcode, i couldnt log in. Get down mate.

Passwords under 8 digits without special chars are fairly easy to bruteforce
Yeah, it's made worse by the fact that passwords aren't case sensitive for Blizzard logins.

If the pws are just hashed i will brute my friends pws and fuck with them for fun. Srs note though some ppl have same pw for EVERYTHING.. Im happy i dont
Sidesprang wrote:Defcap is overrated at current state of the game.
Plask
Sergeant Major
Sergeant Major
 

Re: dont release PASSWORDS

by Snagprophet » Thu Apr 07, 2016 1:49 am

This is why I use different passwords on here, that I wouldn't use on email or Facebook etc. I don't mind if I lose a vanilla account but I'd hate to have everything else compromised.
Snagprophet
Grunt
Grunt
 

Re: dont release PASSWORDS

by Aslan » Thu Apr 07, 2016 1:55 am

What about previous passwords that were changed to new ones?
Scar - Endurance
Aslan - The tales of a Shaman...
Raid streams; As soon as the lag is adjusted (rip)
http://www.twitch.tv/scarnostalrius
User avatar
Aslan
Stone Guard
Stone Guard
 

Re: dont release PASSWORDS

by Codeine » Thu Apr 07, 2016 2:23 am

passwords in the database are encrypted, or they should be.
Codeine
Sergeant Major
Sergeant Major
 


Return to General discussion