Results 1 to 10 of 208

Hybrid View

  1. #1
    Player
    tdb's Avatar
    Join Date
    Jun 2017
    Posts
    859
    Character
    Mikayla Rainstone
    World
    Lich
    Main Class
    White Mage Lv 80
    Quote Originally Posted by RitsukoSonoda View Post
    Issue is numerous people have proven repeatedly all over the internet that they aren't qualified to make that choice. As such in the case of SE they decided not to give that choice to avoid issues later.
    It's actually possible to lock the autologin down pretty tight, so it works only from that particular IP address and doesn't reveal your password. An attacker would basically have to get access to your computer to be able to use it (there are some other, mostly theoretical possibilities which require the attacker to be in a high enough position in a specific organization - and they'd still need some sort of access to your computer to steal the autologin token). Now, gaining remote access to someone's computer is not unheard of - there's a whole category of scammers who try to trick you into allowing them access on the pretense of providing technical support to some made-up problem. As well as various malware. But if you fall for a scam like that then you're vulnerable to a good old phishing attack as well.
    (0)

  2. #2
    Player
    RitsukoSonoda's Avatar
    Join Date
    Apr 2014
    Location
    Kugane (No that red crayon is totally legitimate) >.>
    Posts
    3,147
    Character
    Ritsuko Sonoda
    World
    Ultros
    Main Class
    Samurai Lv 90
    Quote Originally Posted by tdb View Post
    It's actually possible to lock the autologin down pretty tight, so it works only from that particular IP address and doesn't reveal your password. An attacker would basically have to get access to your computer to be able to use it (there are some other, mostly theoretical possibilities which require the attacker to be in a high enough position in a specific organization - and they'd still need some sort of access to your computer to steal the autologin token). Now, gaining remote access to someone's computer is not unheard of - there's a whole category of scammers who try to trick you into allowing them access on the pretense of providing technical support to some made-up problem. As well as various malware. But if you fall for a scam like that then you're vulnerable to a good old phishing attack as well.
    Honestly a very miniscule amount of account takeovers or unauthorized accesses are a result of actual hacking or malicious programs. The primary driving cause is usually human error or just natural stupidity and lack of common sense. Since people can't just go to a facility and install a better brain or more memory in themselves we aren't allowed to have nice things.
    (3)

  3. #3
    Player
    tdb's Avatar
    Join Date
    Jun 2017
    Posts
    859
    Character
    Mikayla Rainstone
    World
    Lich
    Main Class
    White Mage Lv 80
    Quote Originally Posted by RitsukoSonoda View Post
    Honestly a very miniscule amount of account takeovers or unauthorized accesses are a result of actual hacking or malicious programs. The primary driving cause is usually human error or just natural stupidity and lack of common sense. Since people can't just go to a facility and install a better brain or more memory in themselves we aren't allowed to have nice things.
    Indeed. For people who have at least half a clue autologin (or persistent session for websites) might actually be more secure. If something pretending to be the game or website is asking for credentials when it should have logged in automatically, it should raise some flags and prompt for checking extra carefully who is requesting the information. But of course most people don't do that and will give the scammer their password.
    (0)

Tags for this Thread