Verified:

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 9:32:20

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:49:19
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 10:00:44

well thank God you made the grammatical changes!

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 10:05:28

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:49:27
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 10:10:18

never!!

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 10:16:50

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:49:38
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 10:34:27

oh i thought you were talking about grammatical changes ! lol :)

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 10:39:39

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:49:48
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 10:53:21

celphi man, how does one use ascii codes in a pw?? i'm technology nubs

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 11:04:32

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:50:02
Resistance is futile. You will be assimilated.

tellarion Game profile

Member
3908

Jan 30th 2015, 16:06:24

Banned for exploiting.

tellarion Game profile

Member
3908

Jan 30th 2015, 16:08:45

Seriously though, have you messaged qz? I notice you didn't post on sugs forum.....

I messaged qz, but this is exactly the type of fluff you absolutely should spam the fluff out of them to fix....Posting on express talk isn't gonna do fluff.

KoHeartsGPA Game profile

Member
EE Patron
30,508

Jan 30th 2015, 16:12:12

If we all spam qz it's more annoying and he might do something about it :P
Mess with me you better kill me, or I'll just take your pride & joy and jack it up
(•_•)

https://youtu.be/...pxFw4?si=mCDXT3t1vmFgn0qn

-=TSO~DKnights~ICD~XI~LaF~SKA=-

S.F. Giants 2010, 2012, 2014 World Series Champions, fluff YEAH!

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 16:35:57

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:50:30
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 16:38:06

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:50:17
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 16:48:45

celphi, I think tella was joking about banning you :p

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 17:05:29

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:50:44
Resistance is futile. You will be assimilated.

Vic Game profile

Member
6543

Jan 30th 2015, 17:07:56

We all can :p

mrford Game profile

Member
21,417

Jan 30th 2015, 17:08:28

WHAT DO YOU MEAN "WE ALL" MOTHERfluffER? YOU DONT KNOW ME!
Swagger of a Chupacabra

[21:37:01] <&KILLERfluffY> when I was doing FA stuff for sof the person who gave me the longest angry rant was Mr Ford

deezyboy Game profile

Member
964

Jan 30th 2015, 17:18:08

yea tella is funny guy celphi

qzjul Game profile

Administrator
Game Development
10,270

Jan 30th 2015, 17:49:58

*sigh*

I do fix anything critical basically right away; just message me about it first =/
Finally did the signature thing.

Vic Game profile

Member
6543

Jan 30th 2015, 19:44:32

Originally posted by mrford:
WHAT DO YOU MEAN "WE ALL" MOTHERfluffER? YOU DONT KNOW ME!


lol

martian Game profile

Game Moderator
Mod Boss
7845

Jan 30th 2015, 19:46:46

you don't make any sense.
An exploit would yield a password regardless of how complex the password was or wasn't.
Any modern encryption method pretty much ensures that using
"fluff" as a password vs using a random ascii string of 10,000 characters would be equally difficult to guess
if all you had was the encrypted version, no key and no other strategy.

Defeating any kind of "intelligent" password search would not be hard either. Using @#*( doesn't make your password better in that sense (see xkcd on this subject).
The password thefatcatsatonthemat is probably more effective than tT7tyZL8 (which was a "secure" password assigned to me for a specific computer course many years ago).

Stop attention seeking.
you are all special in the eyes of fluff
(|(|
( ._.) -----)-->
(_(' )(' )

RUN IT IS A KILLER BUNNY!!!

KoHeartsGPA Game profile

Member
EE Patron
30,508

Jan 30th 2015, 19:51:46

Says the guy making spam posts on AT...
Mess with me you better kill me, or I'll just take your pride & joy and jack it up
(•_•)

https://youtu.be/...pxFw4?si=mCDXT3t1vmFgn0qn

-=TSO~DKnights~ICD~XI~LaF~SKA=-

S.F. Giants 2010, 2012, 2014 World Series Champions, fluff YEAH!

Marshal Game profile

Member
32,589

Jan 30th 2015, 20:21:24

Originally posted by KoHeartsGPA:
Says the guy making spam posts on AT...


+1
Patience: Yep, I'm with ELK and Marshal.

ELKronos: Patty is more hairy.

Gallery: K at least I am to my expectations now.

LadyGrizz boobies is fine

NOW3P: Morwen is a much harsher mistress than boredom....

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 20:23:12

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:51:22
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 20:37:03

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:51:38
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 20:49:57

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:51:55
Resistance is futile. You will be assimilated.

martian Game profile

Game Moderator
Mod Boss
7845

Jan 30th 2015, 20:58:06

on difficulty of password you missed my point but that's ok.

In short, what you are saying is the vulnerability is centered on the ability to guess a lot of combinations quickly, and using a dictionary to create a high probability match.. ie brute force is easier. It's fine to point that out and *that* argument makes sense.
but saying that using "@" or "$" in my password makes it more secure vs a more sophisticated attack is completely wrong. The possibility that it can be used does. The fact that a "shorter" password could be guessed first is purely a function of how you run the brute force attack.

But you aren't going to convince me that you have a better chance of guessing my password if I don't use those characters or combinations of small and uppercase letters as long as that option exists. You will convince that if I use words or commonly used passwords (like the infamous 2qt4u) you have a better shot at getting it.
But if I string 20 random lower case letters together, I wish you luck brute forcing that.

"http://calc.opensecurityresearch.com/";
assuming you have n choices and k length, the combinations is n^k.
Your strategy is to increase n. I will tell you increasing k is way more effective.
passwords are useless if you can't remember them or have to write them down btw.

The bigger and more serious potential vulnerability is getting the key and at least partially breaking it (for lack of a better way of putting that)..



you are all special in the eyes of fluff
(|(|
( ._.) -----)-->
(_(' )(' )

RUN IT IS A KILLER BUNNY!!!

elvesrus

Member
5063

Jan 30th 2015, 21:01:42

http://xkcd.com/936/ is what martian was referring to
Originally posted by crest23:
Elves is a douche on every server.

martian Game profile

Game Moderator
Mod Boss
7845

Jan 30th 2015, 21:04:09

http://rumkin.com/tools/password/passchk.php
will illustrate my point.
type in
thefatcatsatonthemat
for example:P
you are all special in the eyes of fluff
(|(|
( ._.) -----)-->
(_(' )(' )

RUN IT IS A KILLER BUNNY!!!

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 21:17:10

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:52:09
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 21:21:58

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:52:40
Resistance is futile. You will be assimilated.

Furious999 Game profile

Member
1452

Jan 30th 2015, 21:26:25

Is there some reason all of this has particular relevance now? (Attention seeking left to one side, I mean.)

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 21:28:14

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:52:57
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 21:43:42

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:53:13
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 30th 2015, 21:56:29

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:53:59
Resistance is futile. You will be assimilated.

Untagged Hunter

Member
452

Jan 30th 2015, 22:20:58

why in the world, would anybody want to hack a stinking numbers game? you have too much time on your hands dude

Marshal Game profile

Member
32,589

Jan 30th 2015, 22:40:35

Originally posted by Untagged Hunter:
why in the world, would anybody want to hack a stinking numbers game? you have too much time on your hands dude


you should ask that from those who hacked earthers accounts during mehul's era and rders who tried to hack bc etc and tc etc who did other hackings.

even i got hacked once, somebody had logged into my alliance-country sometime before i logged in (noticed it that no 6 bonus turns when i logged in) but didn't do anything.
Patience: Yep, I'm with ELK and Marshal.

ELKronos: Patty is more hairy.

Gallery: K at least I am to my expectations now.

LadyGrizz boobies is fine

NOW3P: Morwen is a much harsher mistress than boredom....

tellarion Game profile

Member
3908

Jan 31st 2015, 11:49:47

Originally posted by Celphi:
So, do you want me to provide a step by step guide in (SUGS)? Because then you give every EE board reader an opportunity to hack passwords. I've posted an effective solution to the exploit by offering advice as to how to minimize your risk of being hacked.

I'm not in the business of chasing down mods. Mods find me. And if you doubt the exploit, I can provide a demonstration if you'd like.


Mods find you? How self-centered are you?

You posted about a potentially serious exploit on ONE of the subboards for this site, which also happens to be the smallest community of all the servers. Apparently you didn't message qz(you know, the admin?), and you didn't make ANY post on the sugs/bugs board. I'm not saying you should have made a post explaining HOW to do it; that's what the PRIVATE messages are for. I'm saying you should have made 'A' post referring to a serious issue in order to increase the likelihood that qz would see it and be able to react.

If I hadn't seen this post, it's pretty unlikely that he would have been made aware of the issue, since he usually doesn't read this forum(as I've told you and others many times). The fact that you pretty much only informed a few players on one forum without alerting the admins is absolutely mind-blowing. If you want them to do something about it, YOU SHOULD TELL THEM FFS.

Originally posted by Celphi:
On a side note:

I'm helping you moderators. Why attack my character? I gave a legitimate warning to the community and you paint me to be the bad guy.


Because you gave a legitimate warning to 'a small portion' of the community that didn't happen to include the person(or people) that could actually FIX the problem. I'm not attacking your character, I'm calling you out for letting your current jaded attitude towards us(the mods) effect your better judgement. I KNOW you know you should tell the admin if you've found an exploit, but you're too stubborn because you don't like how other(less important) things were handled.

Edited By: tellarion on Jan 31st 2015, 11:57:36
See Original Post

h2orich Game profile

Member
2245

Jan 31st 2015, 12:09:02

so even if we have all our passwords with capital/numbers etc it's still breakable because there's no time out? it would just take longer I guess.

UpTheIrons Game profile

Member
463

Jan 31st 2015, 13:08:20

How many simultaneous authorization transactions can the servers handle without degrading performance or otherwise making it obvious that something is wrong?

whooze Game profile

Member
EE Patron
968

Jan 31st 2015, 13:34:38

Seriously, if you find an exploit you keep quite and tell the gameadmins or at least a mod. You give them as detailed instructions as possible, then you shut the F up about it. By posting on these public boards that there is an exploit will only put everybody at risk.

Any other way to deal with security-issues IS attention seeking.

bstrong86 Game profile

Member
2482

Jan 31st 2015, 13:39:53

Celphi, while there may or may not be an actual exploit, bringing it up on a non bugs related board and.not notifying staff is just ridiculous. You are as guilty as the next person who might exploit it(if it is even a concern)
The Death Knights

XI

Celphi Game profile

Member
EE Patron
6501

Jan 31st 2015, 13:53:50

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:54:32
Resistance is futile. You will be assimilated.

Celphi Game profile

Member
EE Patron
6501

Jan 31st 2015, 13:57:24

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 15:06:22
Resistance is futile. You will be assimilated.

NukEvil Game profile

Member
4328

Jan 31st 2015, 21:26:55

Wait...is the entire point of this post the fact that it's possible to bruteforce shorter and less complex passwords in a reasonable period of time?

If so, I could have sworn that I had implemented a small waiting period before an IP address was able to log in when a player gt his/her password wrong enough times. Unless that was also taken out when the authentication for the forums was moved to the game, I don't really see an issue.
I am a troll. Everything I say must be assumed to be said solely to provoke an exaggerated reaction to the current topic. I fully intend to bring absolutely no substance to any discussion, ongoing or otherwise. Conversing with me is pointless.

Furious999 Game profile

Member
1452

Jan 31st 2015, 21:39:33

Absent an explanation as to why any of this has particular relevance right now I think you can put the thread down to Celphi's obsession with Celphi.

No doubt changing passwords on a regular basis and jumbling them up well is a good idea - to-day as on any other day (something the German Enigma machine distributors might have emphasised). But unless there is someone currently at work busily hacking EE accounts I'll get around to that in my own time rather than on Master Celphi's self important prompting.

Celphi Game profile

Member
EE Patron
6501

Jan 31st 2015, 21:56:53

[ Irrelevant ]

Edited By: Celphi on Feb 11th 2015, 14:53:35
Resistance is futile. You will be assimilated.

ssewellusmc

Member
2431

Jan 31st 2015, 22:52:33

celphi - you need a meaningless calculation to complete this thread...Then you can tell everyone they are wrong. Thank god you only are a weekend warrior or you wouldn't have time for this nonsense.

Getafix Game profile

Member
EE Patron
3423

Jan 31st 2015, 23:18:16

lol