Security Suggestions

Security Suggestions

in Suggestions

Posted by: Masterpyro.4310

Masterpyro.4310

These are some ideas I have about security for the game. One day I dream of a game that has zero gold seller spam and zero hacked accounts. This is a really significant challenge, but I believe it possible one day with the right methods implemented.

Idea #1
Limit amount of logins from 1 IP to 5-10 attempts within 15 minutes. This severally limits how many random accounts a spammer can attempt to crack and makes scanning a list of stolen accounts nearly impossible without a huge botnet.

Idea #2
Add an optional button to the login client(after account login) that generates an encrypted private key and stores it on that user’s desktop with a public key that is attached to the players account. If such a key exists on their account, then make it completely impossible by any method at all to login to that account without that key or a call to support. Kinda like an SSH private key.

Idea #3
Region locking. Let me enable an option to disable my account outside of my own country, or even state if available. I’m never going to china and needing to play Guild Wars there, so my game should not work from there.

Idea #4
Rift had something called Coin Lock that was fairly useful. It made it so you could earn coin, but in no way use it without entering a code from your email or authenticater (or something similar). If it’s not patented, something like this would be great.

Will add more if I come up with more. I think some of these are a bit over the top, but at the same time couldn’t hurt. Unless you are really bad at entering your password or travel a lot, none of these should prevent a legitimate user from accessing their own account easily.

Bot killing techniques

Idea #1
Some bots seem to have hacked clients that can send impossible movements to jump around to mobs and kill them. Have some way of knowing on the server side that says, hey he moved too far, and automatically kick them from the server. Flag them for further investigation. Obviously if implemented be very careful of false positives like with legitmate player teleport skills especially mesmer portal/blink.

(edited by Masterpyro.4310)

Security Suggestions

in Suggestions

Posted by: robinsiebler.3801

robinsiebler.3801

I support this.

A Member of the Blondes Who Hate Hackers Society

Security Suggestions

in Suggestions

Posted by: nachtnebel.9168

nachtnebel.9168

#1
Bad, there are people out there that share the same IP. Additionally you can change you IP easily, it wouldn’t stop spammers.

#2
Solid suggestion.

#3
Don’t we have this (or something similar) already? I had to enable my region the first time I logged into GW2.

#4
As long as it is optional.

Salix Babylonica (Necro), Tharnath (Guardian), N Faculty (Mesmer),
Occam Pi (Ele), Acaena Elongata (Warrior), Finja Salversdotir (Ranger),
Bytestream (Engineer), Vim Whitespace (Thief)