Tuesday, April 17, 2012

Password security

Is this going to be fixed anytime soon? This was maybe acceptable in the beta but should have never made into the release version. After a whole month with several updates the Impulse password is still saved in plain text for everybody to see!!!



Not to mention it is in one of the files even newbie users might open, right at the top and clearly marked as what it is.|||/signed, agreed, etc.|||Col. Jessep|||Leyline|||I don't see this as an issue because I have a secure personal computer.|||Right, I'm sure you also have encrypted your harddrive and stuff like that. Otherwise all I need is 5 minutes and an external hard drive case and I know your password.|||Fine. I can recover all my details by CD-Key and Email. Go ahead and have my password. And first, you actually have to be here with your 5 minutes and external HDD case.|||DeadMG's point is pretty good; i mean seriously, it's your DG password, not exactly on the level of PIN numbers.|||No it's not a PIN but it should be save to use anyway and it isn't. There really is no reason I can think of not to obfuscate a password. It's the most basic security measure I can think of.|||True, and i agree, but i just can't get myself worked up over it.|||Having your Impulse Account Password unencrypted in your Game.prefs is unacceptable. There are plenty of instances where it is advised to change something in your Game.prefs and players that are new to the game are exposed to evil people who tell them to post content of their Game.prefs or send them to someone.|||Very good point Spooky! And what if somebody uses the password not only for Demiogd and Impulse?|||Col. Jessep|||Z32|||Z32|||Image|||DeadMG|||You might remember how Rockstar was sued in the US because a modder enabled the 'hot coffee' content. I would imagine in a country where you can get in major legal trouble over something that silly, you'd be more careful if it comes to security issues.|||Col. Jessep|||Z32|||Yes, this will definately get media attention.



Heck, it might even go to the supreme court and get Brad hung for treason!|||Drama Llama Time.



Image|||i don't understand why people are so against something that's come to be expected... I don't know about you all, but I regularly play computer games with actual people in real life watching me. Sure I could just pick a completely separate password for the game, or get more trustworthy friends, but I really don't feel that I should have to.|||Just because you cannot imagine the impacts of this does not mean that its harmless. At the very least it is a total unnecessary risk. Unfortunately it seems that a real discussion here is no longer possible :(|||IMO; put in the registry instead of game.prefs.



if it's there, it can stay unencrypted.

No comments:

Post a Comment