Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Internet Gambling > Internet Gambling
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 02-23-2007, 11:05 PM
NoahSD NoahSD is offline
Senior Member
 
Join Date: Aug 2005
Posts: 8,925
Default Password Security Suggestion--Key Fobs

(This is not my idea. It was originally posted by shawny boy in this thread about a poster who was hacked.)

A key fob is basically a little key chain with a digital display. The display shows a number that changes about every 30 seconds, and in order to log into your account someone would need your screen name, password, and this number.

So, a keylogger would no longer do anything because the hacker would only receive your username, password, and a number that's no longer valid. We also wouldn't have to worry about letting our friends use our computers, as long as we don't give them access to the key.

It sound like it might be really hard to implement, but PayPal's offering them to clients for $5 each, so it can't be that hard. (link)

Is there any reason why the poker sites shouldn't be working to implement this as soon as possible?
Reply With Quote
  #2  
Old 02-23-2007, 11:27 PM
Freakin Freakin is offline
Senior Member
 
Join Date: Sep 2004
Posts: 6,022
Default Re: Password Security Suggestion--Key Fobs

[ QUOTE ]
(This is not my idea. It was originally posted by shawny boy in this thread about a poster who was hacked.)

A key fob is basically a little key chain with a digital display. The display shows a number that changes about every 30 seconds, and in order to log into your account someone would need your screen name, password, and this number.

So, a keylogger would no longer do anything because the hacker would only receive your username, password, and a number that's no longer valid. We also wouldn't have to worry about letting our friends use our computers, as long as we don't give them access to the key.

It sound like it might be really hard to implement, but PayPal's offering them to clients for $5 each, so it can't be that hard. (link)

Is there any reason why the poker sites shouldn't be working to implement this as soon as possible?

[/ QUOTE ]

There is absolutely no reason. But it really should be something that is widely sold in stores, then registered with whatever accounts you want to protect. There should not be individual ones for every service that wants to be more secure.

So you could have you one unit with a unique serial or other address then you can register it with PP, or FTP or paypal, or your bank or whatever
Reply With Quote
  #3  
Old 02-23-2007, 11:30 PM
mbillie1 mbillie1 is offline
Senior Member
 
Join Date: Dec 2006
Location: crazytown
Posts: 6,665
Default Re: Password Security Suggestion--Key Fobs

Agreed... a nice idea would be for the sites to offer them for a certain # of action points, which would effectively make sure that the people who needed them had access to them.
Reply With Quote
  #4  
Old 02-23-2007, 11:33 PM
BigBiceps BigBiceps is offline
Senior Member
 
Join Date: Mar 2004
Posts: 3,571
Default Re: Password Security Suggestion--Key Fobs

My password is FTPisrigged##!
Reply With Quote
  #5  
Old 02-24-2007, 12:39 AM
TreyOfLight TreyOfLight is offline
Senior Member
 
Join Date: Sep 2004
Location: You have what I\'m repping
Posts: 545
Default Re: Password Security Suggestion--Key Fobs

[ QUOTE ]
So you could have you one unit with a unique serial or other address then you can register it with PP, or FTP or paypal, or your bank or whatever

[/ QUOTE ]If FTP or paypal can derive the fob's sequence from a serial number, so can the bad guys.
Reply With Quote
  #6  
Old 02-24-2007, 01:11 AM
Percula Percula is offline
Senior Member
 
Join Date: Jun 2004
Location: Phoenix
Posts: 2,050
Default Re: Password Security Suggestion--Key Fobs

[ QUOTE ]
[ QUOTE ]
So you could have you one unit with a unique serial or other address then you can register it with PP, or FTP or paypal, or your bank or whatever

[/ QUOTE ]If FTP or paypal can derive the fob's sequence from a serial number, so can the bad guys.

[/ QUOTE ]

Here is a link to the VeriSign sight, where you can do more research on how secure tokens work and some of the options available.
VeriSign Site

And here is a link to Wikipedia on secure tokens...
Wikipedia Secure Tokens

We want the "one time" or "single use" type for poker sites.
Reply With Quote
  #7  
Old 02-24-2007, 02:19 AM
Dazarath Dazarath is offline
Senior Member
 
Join Date: Nov 2004
Location: (>\'.\')>
Posts: 3,394
Default Re: Password Security Suggestion--Key Fobs

I think this is a very good idea. It should also be optional, though. I think something like this may scare away fish if they are required to use it. But for the security-conscious, having the option to use such a token would sure make me sleep better at night.
Reply With Quote
  #8  
Old 02-24-2007, 03:05 AM
Paul B. Paul B. is offline
Senior Member
 
Join Date: Mar 2005
Location: Thailand soon?
Posts: 5,160
Default Re: Password Security Suggestion--Key Fobs

older thread discussing secure tokens. I'd really like to see Stars and Full Tilt implement them.
Reply With Quote
  #9  
Old 02-24-2007, 02:39 PM
Percula Percula is offline
Senior Member
 
Join Date: Jun 2004
Location: Phoenix
Posts: 2,050
Default Re: Password Security Suggestion--Key Fobs

[ QUOTE ]
I think this is a very good idea. It should also be optional, though. I think something like this may scare away fish if they are required to use it. But for the security-conscious, having the option to use such a token would sure make me sleep better at night.

[/ QUOTE ]

They do it the same way Ebay/PayPal is doing it. PayPal business customers get one for free, regular users have to pay $5 to get one.

The poker sites do the same, when an account reaches $X balance they automatically get the choice of have a free token, if the balance is less than $X then the player can buy one for $5 or for Y number of points.

It will take a fairly significant investment on the poker sites part to implement this, but the true value in implementing something this is that a) players when well educated will feel and be much safer and b) any government or regulatory body can see they are serious and accountable, making the industry look better from the outside.

I would be VERY VERY surprised if the poker sites do this in the near future. Looking from the outside in, it does not appear that these poker sites actually "own" their IT. What I mean is that they do not seem to have their own people working on all aspects of their infrastructure or they do not have the skill sets themselves. PS seems to have their software inside, but FTP appears to have it contracted out. All seem to rely on the datacenter in Canada for networking and server "hands on" work.
Reply With Quote
  #10  
Old 02-23-2007, 11:57 PM
wtfsvi wtfsvi is offline
Senior Member
 
Join Date: Feb 2005
Location: Norway
Posts: 2,532
Default Re: Password Security Suggestion--Key Fobs

This is a very good idea.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 04:57 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.