Loading...

Top
PFQ Banner

This is PokéFarm Q, a free online Pokémon collectables game.

Already a user? New to PFQ?

Account Breach incident

Forum Index > Core > Announcements > News Archive >

Pages: 123··· 1516171819··· 222324

selocon's Avatarselocon
selocon's Avatar
elite.pngc.png
For those who use Chrome: A recent update gave you the ability to have it auto-gen you a strong password and for it to auto-remember it (not good if you're using a public computer!!) this password has all the positives about a strong password: it's long (I think at least 16 characters), has a mix of upper and lowercase letters, numbers, and symbols.. Also: pins are...for lack of a better word, dumb. The less numbers in a pin the easier it is to crack, and thhose randomly generated "ensure you aren't a bot, and answer this stupid math question" thing really only works for sign ups. If I have to go get a pin everytime I log in from a new location/device I'd have to stop playing PFQ. I have so many different IPs I cross through while at work, it's no longer funny. Now assume I log in from 12 of those (2 stable) that's 12 pins on day one and 10 pins every other time until I finally log in enough that it's rarer to get a pin. Now imagine how frustrating that would be to have to get a new pin everytime you log in? Most 2 step verifications don't require you have to go back and forth--it's usually something right there. Plus, security questions aren't all that secure. Let's say we need to add three questions, and my three are as follows: "What's your pet's name? What's your mother's maiden name? What city were you born in?" Anyone who knows me well enough (or has found my online family tree, which is semi-public), can have the answers to those in about 5 minutes. They only really work to ensure that you utterly give up, especially if you answered different to that first question than you would now. I'm all for 2FA but please, for the love of Sally, do not use pins or security questions, it's just too much hassle..
Avatar by the best lizard ever, Bananalizard #standwithEMS #ELM
Score: 0
Finally finished reading through the rest of this announcement and I'm glad the thief was named, even though I already knew who it was thanks to some other people who found out before I did. I'm beyond disgusted they could do something like this instead of saving up and earning their melans themselves, instead of resorting to the 'easy way out'. Guess they got their 'dream team', but at the cost of getting banned. I always thought "wow that user could afford to dish out such a huge amount on just ONE melan legend, I wish I could get a job that paid that well." I legit just thought it was some person with a high end job lmao.




Avatar is my sona, drawn by Saapricots!
m.pngsummon_mol.png×7/1000summon_mol.pngm.png


Lovino's AvatarLovino
Lovino's Avatar
ultra.pngc.png

QUOTE originally posted by selocon

For those who use Chrome: A recent update gave you the ability to have it auto-gen you a strong password and for it to auto-remember it (not good if you're using a public computer!!) this password has all the positives about a strong password: it's long (I think at least 16 characters), has a mix of upper and lowercase letters, numbers, and symbols.. Also: pins are...for lack of a better word, dumb. The less numbers in a pin the easier it is to crack, and thhose randomly generated "ensure you aren't a bot, and answer this stupid math question" thing really only works for sign ups. If I have to go get a pin everytime I log in from a new location/device I'd have to stop playing PFQ. I have so many different IPs I cross through while at work, it's no longer funny. Now assume I log in from 12 of those (2 stable) that's 12 pins on day one and 10 pins every other time until I finally log in enough that it's rarer to get a pin. Now imagine how frustrating that would be to have to get a new pin everytime you log in? Most 2 step verifications don't require you have to go back and forth--it's usually something right there. Plus, security questions aren't all that secure. Let's say we need to add three questions, and my three are as follows: "What's your pet's name? What's your mother's maiden name? What city were you born in?" Anyone who knows me well enough (or has found my online family tree, which is semi-public), can have the answers to those in about 5 minutes. They only really work to ensure that you utterly give up, especially if you answered different to that first question than you would now. I'm all for 2FA but please, for the love of Sally, do not use pins or security questions, it's just too much hassle..
redacted
profile picture sprites created by https://pokefarm.com/user/sojussimblr
selocon's Avatarselocon
selocon's Avatar
elite.pngc.png

QUOTE originally posted by Lovino

QUOTE originally posted by selocon

For those who use Chrome: A recent update gave you the ability to have it auto-gen you a strong password and for it to auto-remember it (not good if you're using a public computer!!) this password has all the positives about a strong password: it's long (I think at least 16 characters), has a mix of upper and lowercase letters, numbers, and symbols.. Also: pins are...for lack of a better word, dumb. The less numbers in a pin the easier it is to crack, and thhose randomly generated "ensure you aren't a bot, and answer this stupid math question" thing really only works for sign ups. If I have to go get a pin everytime I log in from a new location/device I'd have to stop playing PFQ. I have so many different IPs I cross through while at work, it's no longer funny. Now assume I log in from 12 of those (2 stable) that's 12 pins on day one and 10 pins every other time until I finally log in enough that it's rarer to get a pin. Now imagine how frustrating that would be to have to get a new pin everytime you log in? Most 2 step verifications don't require you have to go back and forth--it's usually something right there. Plus, security questions aren't all that secure. Let's say we need to add three questions, and my three are as follows: "What's your pet's name? What's your mother's maiden name? What city were you born in?" Anyone who knows me well enough (or has found my online family tree, which is semi-public), can have the answers to those in about 5 minutes. They only really work to ensure that you utterly give up, especially if you answered different to that first question than you would now. I'm all for 2FA but please, for the love of Sally, do not use pins or security questions, it's just too much hassle..
theres no win for anyone with multi 2fa. i have multiple gmails with multiple step verifications just to get on to my account it goes from the system im on, hving to get a text putting in that text going into my email searching through whcih folder the confirmation would be in then clicking it then logging out of my gmail. so it would be a pain for everyone. my school when i was in it had to memorize a few 12 digit numbers to get in most got it after a month so pins arent that hard to memorize but i do see your point with the question part
Thing is, how secure would a static pin be? I guarentee you there are sophisticated enough RNGs out there that can generate hundreds--if not thousands--of random 12 digit coombinations which a user could then just paste into the box. Even with the waiting, they could go do something else until the time is up--like watch a music video on YT. Pins are only secure if they're generated every time. Like Yahoo. If I forget my password, in order to chain it, I have to get a code they send me and enter all 8 alpha-numeric characters into the box. But it's not static. And having to get a new code every X amoutn of time is about as memorable as sites that require you to use an entirely new password every 30 days, you finally just resort to storing them somewhere and trying all of them.
Mirzam's Avatarhypermode-12.pngMirzam
Mirzam's Avatar
helpinghand.pnghypermode.pngcomplete.pnga.png
The 2FA I use for most of my accounts is the kind that generates a new 6 digit (numbers only) code in an app every 30 seconds or so. You enter that number every time you log in on a new device (it's typically cookie-based, not IP). Most people use an app on their phone like Google Authenticator to generate the codes, but these days there are a lot of options including some that run on desktop or sync your codes across devices (technically less secure, but very convenient). The purpose is that if someone guesses or tricks you into giving up your password, they won't have your app-generated code, and there's no way to effectively guess or collect it since it changes so often. It's still technically vulnerable to certain types of social engineering etc but that can get pretty tricky to pull off. Static PINs you have to memorize are no better than a password. Same with security questions.

Example

Niet [Adam]'s Avatarhypermode-12.pngNiet [Adam]
Niet [Adam]'s Avatar
admin1.pngbooster.pnghypermode.pngcomplete.pngd+.png
The point is, it basically makes it so that you are required to have your phone on you (or whatever device has your registered authentication app) in order to log in successfully. Preliminary review of things looks like it should be possible to implement on PFQ as an option.
Clip from Pokémon anime, re-lined by me
-- OMNOMNOM!
Featured story: Injustice Feedback welcome!
x Arlecchinø's Avatarx Arlecchinø
x Arlecchinø's Avatar
master.pngd.png
Oh my God, am I glad I am not too rare. Although I do remember some eggs being mysteriously hatched some time back while I was offline. I hope she didn't guess my password I definitely didn't procrastinate changing. I'd die if my bacon baby was stolen, and report it on the spot. Thank you everybody who helped
cy/fev. he/they pronouns. find me at @scorkaji on discord if you need me
King's Shield

King's Shield

Forme-Change Item

(item.png: 0)

A mysterious shield that enervates attackers. Aegislash could make good use of this.

Sells for 500

Lv. 100 — +11,309,648
Aspear BerryAspear Berry
Aspear Berry (SOUR)
Cheri BerryCheri Berry
Cheri Berry (SPICY)
Chesto BerryChesto Berry
Chesto Berry (DRY)
Pecha BerryPecha Berry
Pecha Berry (SWEET)
Rawst BerryRawst Berry
Rawst Berry (BITTER)
Likes:
Bitter food
ElectricDark
Happiness 27%
Calm nature
Lv. 100 — +12,658,409
Aspear BerryAspear Berry
Aspear Berry (SOUR)
Cheri BerryCheri Berry
Cheri Berry (SPICY)
Chesto BerryChesto Berry
Chesto Berry (DRY)
Pecha BerryPecha Berry
Pecha Berry (SWEET)
Rawst BerryRawst Berry
Rawst Berry (BITTER)
Likes:
Dry food
DarkFlying
Happiness 27%
Rash nature
Lv. 100 — +7,506,748
Aspear BerryAspear Berry
Aspear Berry (SOUR)
Cheri BerryCheri Berry
Cheri Berry (SPICY)
Chesto BerryChesto Berry
Chesto Berry (DRY)
Pecha BerryPecha Berry
Pecha Berry (SWEET)
Rawst BerryRawst Berry
Rawst Berry (BITTER)
Likes:
Sour food
Fairy
Happiness 27%
Impish nature

avatar is official Honkai:Star Rail art, edited by me. pkmnpanel code
Duusu's AvatarDuusu
Duusu's Avatar
grandmaster.pngs.png

QUOTE originally posted by Duusu

Was karenkhor IP locked as well? While she may have been account locked, what is stopping her from making another account?
I just want to bring this forward because I don't believe that there was an answer on this and it was skipped over?
Icon is from "Obey Me!", by NTT Solmare Corp.! || My Trade Shop! || Delta Hoarders United!
s.pngCollector of special water deltas!s.png
Lv. 86 — 10,180 / 22,447
Aspear BerryAspear Berry
Aspear Berry (SOUR)
Cheri BerryCheri Berry
Cheri Berry (SPICY)
Chesto BerryChesto Berry
Chesto Berry (DRY)
Pecha BerryPecha Berry
Pecha Berry (SWEET)
Rawst BerryRawst Berry
Rawst Berry (BITTER)
Likes:
Spicy food
Water
Happiness 27%
Naughty nature
ICEBÜNN's Avatarhypermode-12.pngICEBÜNN
ICEBÜNN's Avatar
graphics.pnghypermode.pnggrandmaster.pngb+.png
Oh wow. I seriously expected not to recognize the user at ALL, but that is a name I have seen far too often. I don’t remember trading with them in the past few months, but I have most DEFINITELY traded with them over the past few years. Quite frankly I’m shocked, and it makes me wonder if they were pulling similar things back then as well.
  • Main
  • Credits
Bunn, He/Him This is Frida
Avatar by me of my sona (full image), Signature by myself!
MochaFox's AvatarMochaFox
MochaFox's Avatar
retiredstaff.pngarceus.pngb.png

QUOTE originally posted by Duusu

QUOTE originally posted by Duusu

Was karenkhor IP locked as well? While she may have been account locked, what is stopping her from making another account?
I just want to bring this forward because I don't believe that there was an answer on this and it was skipped over?
I can answer that right quick. While I don't know the code behind it, ( halp, Niet ) if anyone tries to make an account on an IP with a locked account on it that will be blocked from creating another account onto that IP. Say there's an account ( PokemonFan1357 for example ) on your IP. Maybe it was your brother. You think "okay, I'm gonna make an account too!", but as you are creating your account a box pops upthat says - in condensed terms - "oh no! We cannot complete your registration process because there is a locked account on this IP!" Turns out, PokemonFan1357 was locked because they broke a rule too many times. Darn.
✦ ✦
73/500+
167/500+
✦ ♥ Jacob Daniel born 7/17/18 ♥ ♥ Zander Leon due 8/1/24 ♥
✧ Template: [✦] | Avatar: [✦] | Background: [✦] | Font: [✦]

Pages: 123··· 1516171819··· 222324

Cannot post: Please log in to post

© PokéFarm 2009-2024 (Full details)Contact | Rules | Privacy | Reviews 4.6★Get shortlink for this page