Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Internet Gambling > Internet Gambling
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #41  
Old 02-16-2007, 05:11 PM
RedBean RedBean is offline
Senior Member
 
Join Date: Apr 2005
Posts: 2,358
Default Re: Security tips for avoiding account hackers

Can't believe it has been suggested yet, but the easiest method to come up with a strong password is to identify a sentence, then use the first letter of each word as your password. It's easier to remember the sentence, and makes a strong password.

Example:

"I really do like Lee Jones, he listens to his users!"

makes the password:

IrdlLJ,hl2hu.
Reply With Quote
  #42  
Old 02-16-2007, 05:20 PM
ImsaKidd ImsaKidd is offline
Senior Member
 
Join Date: Aug 2005
Location: CHOO CHOO
Posts: 11,074
Default Re: Security tips for avoiding account hackers

[ QUOTE ]
Can't believe it has been suggested yet, but the easiest method to come up with a strong password is to identify a sentence, then use the first letter of each word as your password. It's easier to remember the sentence, and makes a strong password.

Example:

"I really do like Lee Jones, he listens to his users!"

makes the password:

IrdlLJ,hl2hu.

[/ QUOTE ]

This is a weird sentence though. One of the tips I heard was to remember a song title or phrase. Raindrops keep falling on my head =

rkf0mh

or something like that.
Reply With Quote
  #43  
Old 02-16-2007, 05:23 PM
Percula Percula is offline
Senior Member
 
Join Date: Jun 2004
Location: Phoenix
Posts: 2,050
Default Re: Security tips for avoiding account hackers

Lee,

While this post is a good, and contains some good advise, I think there is a lot more that PokerStars can do to help protect their customers.

The very first thing I think you and your IT staff should be looking at is using secure tokens for authentication. If EBay/PayPal can do it, so can you. This step in and of its self eliminates theft from all but physical thefts.

(For more information on secure tokens, refer to this URL... VeriSign )

The next thing you should be looking at is requiring strong passwords, expiring passwords with a history, and unlinking the username that controls money from the screen name that is displayed while playing.

Do these two things, and you will be the most secure poker site on the net.
Reply With Quote
  #44  
Old 02-16-2007, 05:35 PM
MicroBob MicroBob is offline
Senior Member
 
Join Date: Sep 2003
Location: The cat is back by popular demand.
Posts: 29,344
Default Re: Security tips for avoiding account hackers

Agree 100%.

Don't think it appropriate that the name everyone sees at the table should also be the log-in name to get into the site.
Everybody already has half the equation right there to try to break into your account.

Prima and some other sites have completely different log-in's from the name you use at the table.


My bank has the 'expired pass-words' thing for accessing my online-account.
Many sites I know require a certain length or number of digits or SOME minimum requirement for password-security.

If I tried to set my password as LeeJones the site wouldn't let me because it woudl say that the password is not secure enough, I have to have at least 3 digits, whatever.

Doing something like this would force many people to be safer with their passwords.
Yes, most should be smart enough to know how to do this on their own. But Stars can also push their customers in the right direction like some other sites seem to do just to avoid as many headaches as possible.
Reply With Quote
  #45  
Old 02-16-2007, 06:18 PM
Rainbow Warrior Rainbow Warrior is offline
Senior Member
 
Join Date: Sep 2002
Location: The Great White North
Posts: 586
Default Re: Security tips for avoiding account hackers

[ QUOTE ]
[ QUOTE ]
You'd trust an on-line downloadable program with all your passwords??
Sounds insane.
I'd rather write them down in my own home with a numeric code(plus or minus shift on numbers/letters) that only me and one other person know.

[/ QUOTE ]

KeePass, one of the programs mentioned, is very reputable and safe.

[/ QUOTE ]

(playing paranoid devil's advocate because 100% safe means what??)

"...and Keepass is FREE!! So, therefore, they make money by...hmmm...let's see now...OH NO!!!"



Actually, I'm unfamiliar with Keepass and have no reason to trust or distrust them. AFAIK none of the hacked accounts we've read about on 2+2 used Keepass.

However, it's just another case of us giving outsiders with brilliant PC skills (eg: PT, PAHUD, etc.) access to computers that they know have important monetary data.
I allow my e-mails to be scanned daily. I trust, but I wonder.

Have I stepped over the line here??
Reply With Quote
  #46  
Old 02-16-2007, 07:23 PM
wonderwes wonderwes is offline
Senior Member
 
Join Date: May 2003
Location: Austin, TX
Posts: 3,551
Default Re: Security tips for avoiding account hackers

Dear Lee,

As you can see the 2+2 community always welcomes to hear your posts. Obviously you wrote out the recommendations given by your security staff, some of these could be a bit revised.

One security program you forgot to mention was SnoopFree. It is an excellent program to warn you if any particular .exe is trying to gain access to your machine.

One thing Pokerstars should do is also keep a listing of security question. Ultimate Bet has this feature. If you had 2 security questions per user, it would help verification a lot.

It can't be easy to stay ahead of hackers but I hope you will revise this and post some kind of FAQ later on the poker stars website.
Reply With Quote
  #47  
Old 02-16-2007, 07:33 PM
HostJacob HostJacob is offline
Member
 
Join Date: Nov 2006
Location: PokerStars Support
Posts: 49
Default Re: Security tips for avoiding account hackers

Since it's late at night in IOM and Lee is likely asleep, I'll answer a few questions...

[ QUOTE ]
Don't think it appropriate that the name everyone sees at the table should also be the log-in name to get into the site.

[/ QUOTE ]

This is only really a problem against dictionary hacks (unless I'm missing something). We have a different defense against that, in that if you enter the wrong password too many times (and it's not a huge number), your account will be locked entirely until you contact support. No dictionary hack could succeed on Stars.

[ QUOTE ]
If I tried to set my password as LeeJones the site wouldn't let me because it woudl say that the password is not secure enough, I have to have at least 3 digits, whatever. Doing something like this would force many people to be safer with their passwords

[/ QUOTE ]

Our site requires this as well - your password must be at least 8 characters long, and contain both numbers and letters. You cannot set your password to "LeeJones" on PokerStars - feel free to try, and you'll see the error message.
Reply With Quote
  #48  
Old 02-16-2007, 07:39 PM
HostJacob HostJacob is offline
Member
 
Join Date: Nov 2006
Location: PokerStars Support
Posts: 49
Default Re: Security tips for avoiding account hackers

[ QUOTE ]
What happens if I die and no one knows how to log into my PokerStars account?

[/ QUOTE ]

Your family should contact PokerStars support. They will let your family know what is necessary to provide in order for us to cash out your funds and send them to your family.
Reply With Quote
  #49  
Old 02-16-2007, 07:52 PM
Percula Percula is offline
Senior Member
 
Join Date: Jun 2004
Location: Phoenix
Posts: 2,050
Default Re: Security tips for avoiding account hackers

[ QUOTE ]
Since it's late at night in IOM and Lee is likely asleep, I'll answer a few questions...

[ QUOTE ]
Don't think it appropriate that the name everyone sees at the table should also be the log-in name to get into the site.

[/ QUOTE ]

This is only really a problem against dictionary hacks (unless I'm missing something). We have a different defense against that, in that if you enter the wrong password too many times (and it's not a huge number), your account will be locked entirely until you contact support. No dictionary hack could succeed on Stars.

[/ QUOTE ]

Opps, big mistake. So now if I want to mess up someone that I know is going to be playing say the Sunday million MTT, all I have to do is try and login as their screen name with the wrong password until the account is locked out.

No big deal IF support is VERY fast in verifying and reactivating the account, but if they are not, I have just done a denial of service attack on another player. Hell a decent script kiddy could get their hands on a good sized PT DB and dos a few thousand accounts at once.

Edit to add...

And it is a none issue if the screen name and account names are different.
Reply With Quote
  #50  
Old 02-16-2007, 08:44 PM
_And1_ _And1_ is offline
Senior Member
 
Join Date: Nov 2003
Location: Lalaland
Posts: 777
Default Re: Security tips for avoiding account hackers

[ QUOTE ]
Don't think it appropriate that the name everyone sees at the table should also be the log-in name to get into the site.
Everybody already has half the equation right there to try to break into your account.

Prima and some other sites have completely different log-in's from the name you use at the table.

[/ QUOTE ]

Word, the fact that your screenname and login is the same is just cr*p, Lee/you/PS should implement a diffrent login/screenname.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 03:50 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.