PDA

View Full Version : New account management system


Ramjesty
10-22-2009, 05:16 PM
Today's spotlight will focus on some imminent changes to our Account Management page. We spoke to the Web Programmers working for Aventurine and they laid down some of the improvements and additions that the community will be seeing very soon in their account management pages.

First of all even though the visuals are more or less unaltered, they explained that the coding behind it all has changed almost entirely. The purpose of this was to make the whole system more stable and improve some areas that caused problems to the subscribers.

The account system will now be taking you through a series of easy to follow steps in order to create your account, enter your billing information and buy the game.

Also the “forgot my password” function has been streamlined and it no longer requires the user to follow any links but instead just sends a new randomly generated password to the email that is associated with the account. Thus, former issues with expired or erroneous links will be eliminated.

Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.

Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.

More details will be available through our official news forum.

Thes
10-22-2009, 05:18 PM
First :D

nice to see that the old forumfall posters who don't play the game will "Bye bye"

Wyndal
10-22-2009, 05:25 PM
Also the “forgot my password” function has been streamlined and it no longer requires the user to follow any links but instead just sends a new randomly generated password to the email that is associated with the account. Thus, former issues with expired or erroneous links will be eliminated.

Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.

Hope these two modifications keep security in line with simplicity.

Glad to hear linkage between forum and game accounts is being implemented!!

Tibernicus
10-22-2009, 05:26 PM
Sounds like everyone is busy improving every last aspect possible.

Ayn Eziert
10-22-2009, 05:28 PM
this news make :D

coder1024
10-22-2009, 05:33 PM
Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.
love it! finally some forums where only people actually paying for the game can post. should be a nice change :)

thedrumchannell
10-22-2009, 05:37 PM
Very, very NICE, actual Darkfall player forums. Mwuaaaah Ha Ha. :)

Keno
10-22-2009, 05:39 PM
Sounds good to me, excited for the change. But, transfers, we want a date! :P
Expansion Notes would be nice to.

Tyki Mykk
10-22-2009, 05:41 PM
Good news!

warriorswar
10-22-2009, 05:41 PM
we have waited so much.... :ninja:

Uncletouchme
10-22-2009, 05:46 PM
A new quiet constructive forum for us. Oh the joy :D.

DwellerBelow
10-22-2009, 05:46 PM
First :D

nice to see that the old forumfall posters who don't play the game will "Bye bye"

It's not that I want the unsubs to go away, I just want to know who is actually playing, and who quit.

Those who left had good reason to do so, but they no longer know the current state of the game, and it shows in their comments.

KOS allgriefers
10-22-2009, 05:56 PM
Sounds good to me, excited for the change. But, transfers, we want a date! :P
Expansion Notes would be nice to.

This. Great news on sub only forums but what about the transfers?

Captain Kirk
10-22-2009, 05:58 PM
Great news, I love it!

Now we dont have to listen to scrubs that dont have what it takes to play the game! :D

kil_2k
10-22-2009, 06:00 PM
A new quiet constructive forum for us.

Lol, nope. Will just be less people posting.

Vif
10-22-2009, 06:02 PM
Pffffff there will be people paying an account just to spam our new suscriber only forums i bet!

chokke
10-22-2009, 06:11 PM
Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.

This doesn't sound like safe. What if someone steals my account?

Kasmos
10-22-2009, 06:13 PM
Very exciting, I for one will be happy to start seeing poll results from subscribers only as I fear a lot of the polls created nowadays is voted on by primarily non-subscribers.

Plus, it won't be filled with so unbelievably many trolls and crybabies.

Junkaboy
10-22-2009, 06:17 PM
users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week


Very good news!!!

BUT


Will the "posting rights" be removed when the user's game account goes inactive?


Very important detail to make sure this forums stay "clean"...

Cyric1966
10-22-2009, 06:21 PM
Sounds good to me, excited for the change. But, transfers, we want a date! :P
Expansion Notes would be nice to.

Why is it so hard to get a date on this? I mean your talking to the developers about account stuff, why not ask them then and tell us how long?

Arkh
10-22-2009, 06:22 PM
Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.
What a good idea.
If someone gets my account password, he can now just change the email account associated with it easily.

Slaker
10-22-2009, 06:24 PM
love it! finally some forums where only people actually paying for the game can post. should be a nice change :)

Yup I can't wait.

good news!

Junkaboy
10-22-2009, 06:27 PM
Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.

This doesn't sound like safe. What if someone steals my account?

1 - Put a reliable "non-subject to ISP change" e-mail add on your subscription (like gmail, yahoo, hotmail...)
2 - Dont ever give out your e-mail password to anyone.
3 - Dont ever give out your game password to anyone.
4 - Keep your anti-virus/spyware software up to date.

If you follow these easy steps, you can rest assured that in order to steal your account, you will need someone very experienced / skilled.

Then why would someone with such capabilities use them for stealing a DFO account?

Deen0229
10-22-2009, 06:35 PM
What will Haeso do?

kil_2k
10-22-2009, 06:40 PM
What a good idea.
If someone gets my account password, he can now just change the email account associated with it easily.

If they've got your password, and it's not someone you can trust, you're fucked anyway.

Dasmas
10-22-2009, 06:44 PM
Lol, nope. Will just be less people posting.

Less QQ's from people that don't need to post. They won't be missed.

coder1024
10-22-2009, 06:44 PM
What a good idea.
If someone gets my account password, he can now just change the email account associated with it easily.
yea using a password of "password" might not have been the best choice ;)

KOS allgriefers
10-22-2009, 06:50 PM
If they've got your password, and it's not someone you can trust, you're fucked anyway.

Except that they can change your email address and then change your password. If you had to confirm an email adress change then this could not happen unless they knew your email adress password too. This is a downgrade in security and huge one at that.

Strife
10-22-2009, 06:50 PM
Hmm.. I wonder if it will show your in game name on your forum account :)

Adûn_East
10-22-2009, 06:57 PM
Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.

Really nice.

coder1024
10-22-2009, 07:06 PM
Hmm.. I wonder if it will show your in game name on your forum account :)
I doubt it, but you never know. I would think they would avoid that as it would encourage people to go after someone on the forums if they didn't like getting killed and looted by them :)

Junkaboy
10-22-2009, 07:09 PM
Will the "posting rights" be removed when the user's game account goes inactive?




No one else wondering about this detail???

Remember that most DFO trollers are ex-paying customers...

Strife
10-22-2009, 07:15 PM
I doubt it, but you never know. I would think they would avoid that as it would encourage people to go after someone on the forums if they didn't like getting killed and looted by them :)

Yea I know, but it would be great if people could stop hiding behind their forum names... And I'm always in favor of pot stirring on the forums due to in game antics.

ISVRaDa
10-22-2009, 07:19 PM
users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.

Was necessary, thx.

neon sheild
10-22-2009, 09:39 PM
going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.

yay!!! :) :) :)

Alberton
10-22-2009, 10:08 PM
Has anyone else tried to associate their current forum account with their game account.

Mine gives me an error saying its an invalid account (and yes I logged out from these forums and back in to confirm I had the right password).

I thought it was just a matter of associating my game account with this account Alberton <password>.

Have I misread this?

DeManiac
10-22-2009, 10:58 PM
I haven't used the e-mail change system, but if it actually just requires you to enter a new mail after you have logged into the account management pages, I don't like it.

If the old one was such that it generated a code and sent it to you so you had to past that one along with the new e-mail adress, but the out dated time for this one was to short, I dunno if this was the best solution.

I'm glad the password retrieval system is changed that's nice, but if you for some reason were hacked, and they could change the password and e-mail without any info being sent to the old e-mail address, that's a major flaw.

For some reason I feel like this is a typo or it's a stupid system, because there would be so many more ways to solve this issue, rather then just dropping security, for one, not have outdated problem.

changing the way the code is generated is one of em, and saving a referee value set to the last sent one always, if you press the change e-mail, and write a new e-mail address, a code generated is sent to the old address, once you pressed change, you change to a new page.
In this new page it's a new form, new e-mail address( to verify against the one you entered before) and code.
This code is then checked against the referee code that was saved once you pressed the send confirmation email.
Once you then enter the right values, a new message is sent to old, and to new e-mail.
You have now successfully changed e-mail associated with account ( account name) to (new e-mail address).
Using this code you can reverse the change within (set amount of days)

That would be nice, no reason for outdated ones etc etc.

bongloads
10-22-2009, 11:02 PM
Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.


awesome

raffraff
10-23-2009, 01:24 AM
Has anyone else tried to associate their current forum account with their game account.

Mine gives me an error saying its an invalid account (and yes I logged out from these forums and back in to confirm I had the right password).

I thought it was just a matter of associating my game account with this account Alberton <password>.

Have I misread this?

It's not up yet...

Corpsepoker
10-23-2009, 01:28 AM
Booya!

peertje
10-23-2009, 01:33 AM
okay, I linked my accounts - its no a matter of waiting on those other forums? no other things to notice? like character info on the forum acc, etc?

ninogan
10-23-2009, 01:43 AM
Sounds great. Gonna wait to link it until I know there won't be any stupid bugs that may mess stuff up. Sorry AV but I don't trust your coders well enough for that :P

Neilk
10-23-2009, 01:44 AM
I wouldnt trust them either when they give normal users access to moderator forums xD

stingerII
10-23-2009, 01:45 AM
tup tup ....wondering if there'll be any noticeable changes

Captain Kirk
10-23-2009, 02:50 AM
Looks like they made a major fuckup on this one, My account is 16 char long (made back shortly after launch) and now they've changed it to only 15 character long account names so i cant log in..... Am i wrong or is it in fact AV that has made a major mistake here? :rolleyes:

Keno
10-23-2009, 02:52 AM
Looks like they made a major fuckup on this one, My account is 16 char long (made back shortly after launch) and now they've changed it to only 15 character long account names so i cant log in..... Am i wrong or is it in fact AV that has made a major mistake here? :rolleyes:

I get the same error LOL, good job AV!

Captain Kirk
10-23-2009, 02:53 AM
I get the same error LOL, good job AV!

Its an easy fix, but they have to do it ASAP! :rolleyes:

Resfelm
10-23-2009, 08:49 AM
It seems that a few of you are concerned about any security risks the new email change system can pose. The security is exactly the same. In the old system the confirmation email would be sent to your NEW email and not the old one. So basically as people have already said, if someone has your account password then your account is compromised anyway. The new email change system does not make your account more vulnerable.

chokke
10-23-2009, 09:24 AM
The last login seems wrong, it shows the current logged intime..

ninogan
10-23-2009, 09:37 AM
Looks like they made a major fuckup on this one, My account is 16 char long (made back shortly after launch) and now they've changed it to only 15 character long account names so i cant log in..... Am i wrong or is it in fact AV that has made a major mistake here? :rolleyes:

See I knew something like this would happen >_>

sockpuppet
10-23-2009, 09:46 AM
It seems that a few of you are concerned about any security risks the new email change system can pose. The security is exactly the same. In the old system the confirmation email would be sent to your NEW email and not the old one. So basically as people have already said, if someone has your account password then your account is compromised anyway. The new email change system does not make your account more vulnerable.

Then there was a problem with the old system as well, but that doesn't make it a good idea.

Right now, if someone steals my session, they can easily gain control of my account by changing me email, then getting sent a new one. No password neccesary... Hell, it could even be possible to gain complete control of my account with an XSRF which would require absolutely no effort from what I've seen.

Can we please get password confirmation for changing info?...

chokke
10-23-2009, 10:07 AM
Then there was a problem with the old system as well, but that doesn't make it a good idea.

Right now, if someone steals my session, they can easily gain control of my account by changing me email, then getting sent a new one. No password neccesary... Hell, it could even be possible to gain complete control of my account with an XSRF which would require absolutely no effort from what I've seen.

Can we please get password confirmation for changing info?...

Luckily they cant get our credit information through this.. Yet.

aenimka
10-23-2009, 10:10 AM
very nice change, and very important also, game is great atm so devs could focus on account management system.

thank you

Shino-PIC
10-23-2009, 10:33 AM
Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.


Question: "game account" = "active game account"?

Drago Palmas
10-23-2009, 10:40 AM
There is a space in my name so I can not tie it to the account.

katahlyn
10-23-2009, 10:43 AM
Question: "game account" = "active game account"?

Good question. Not sure if game account info is already available on the forums anyway...
Edit: It's not.
Also, there's and address validation that is broken. My real address failed validation, so I replaced it with two letters and it passed!

chokke
10-23-2009, 10:48 AM
There is a space in my name so I can not tie it to the account.

I can't find an option to do it :d

Captain Kirk
10-23-2009, 01:32 PM
See I knew something like this would happen >_>

They fixed it now so i can log in again! :D

Drago Palmas
10-23-2009, 05:19 PM
I can't find an option to do it :d

I made it!! I just had to delete my second First Name and put my house number in field Address 2 :D

Now that I made it I can tell you it has no effect untill now, so don´t hurry.

Ice Bull
10-23-2009, 07:41 PM
The security is exactly the same. In the old system the confirmation email would be sent to your NEW email and not the old one.


Yes Resfelm, you are right.

The security is the same of the old one.

But is better improve the securtity send a confimation email link to the old email, that way, if a hacker steal my password game account, he dont have my email password account. So i can recover my account with my email, like world of warcraft security system.

To change your email of your game account in WOW, you need confirm in a link send to your old email... Old email a hacker never had...

Bad things happens.

xinteractx
10-23-2009, 08:36 PM
Today's spotlight will focus on some imminent changes to our Account Management page. We spoke to the Web Programmers working for Aventurine and they laid down some of the improvements and additions that the community will be seeing very soon in their account management pages.

First of all even though the visuals are more or less unaltered, they explained that the coding behind it all has changed almost entirely. The purpose of this was to make the whole system more stable and improve some areas that caused problems to the subscribers.

The account system will now be taking you through a series of easy to follow steps in order to create your account, enter your billing information and buy the game.

Also the “forgot my password” function has been streamlined and it no longer requires the user to follow any links but instead just sends a new randomly generated password to the email that is associated with the account. Thus, former issues with expired or erroneous links will be eliminated.

Changing the email associated with the account also no longer requires any confirmation through emails and it will be a simple “enter new email – click submit” kind of affair.

Going into some more exiting news, users will be able to associate a forum account with their game account, thus gaining posting rights into certain forums that will open next week. Still we were told that forums open to the general public will still be available, and even subscriber only forums will be readable by anyone.

More details will be available through our official news forum.

Most of these changes will make the system more hackable, and player account hijacking will be easier as well.

IE, If I brute force my way into someones account, I can just simple change the email address without having to login to their email act to confirm it. This will make it harder for them to recover their act.

Second problem, If i know someones act login then I can simple reset their password and cause them to have login problems.

The forum integration is a good idea, however forums are prone to hijacking. As good as VB is, it is not 100% hackable and if someone finds a exploit in it then they could posible exploit it to gain direct access to the games database if they are linked. So I would be very carfull on how this integration takes part.'

= Computer programmer, Done all kinds of work and I forsee a few issues with these changes, However if inter-graded correctly with security in mind then they can be beneficial to everyone. Good luck, and rethink the the idea behind the password reset, you should have to confirm it via email or some hidden questions the player can set.

Tiak
10-23-2009, 10:03 PM
Yes Resfelm, you are right.

The security is the same of the old one.

But is better improve the securtity send a confimation email link to the old email, that way, if a hacker steal my password game account, he dont have my email password account. So i can recover my account with my email, like world of warcraft security system.

To change your email of your game account in WOW, you need confirm in a link send to your old email... Old email a hacker never had...

Bad things happens.

Honestly, that isn't much better...

Right now, someone can completely take over an account if they have:
-The account name and password.
-The account holder's email name and password
-Someone who is logged into the account system's session.
-The ability to get someone who is logged in to the account system to send arbitrary packets.

The last two are the huge no-nos, but there isn't anything all that wrong with the first two. Honestly, emails are much easier to get into than accounts. Email addresses are publicly available with a google 99.9% of the time, and email accounts with services like yahoo are easy to get reset for you with even the most minimal of personal information (also google-able). Meanwhile, account usernames are hidden from everyone but the account-holder. The only real ways someone is going to get your account info is by either you telling them (in which case, it is sort of your fault) or a keylogger (which would be just as likely to also grab your email info).