Stopping Account Sharing/Selling/Hacking
Posted: Wed Mar 08, 2006 2:55 pm
Account sharing/selling have been a evil since the early days of A3 CLosed beta itself (no personal comments... keep flaming/*censored* outside this thread). Here is a way that i came across while registreing for a internet website recently, which if applied with appropriate modifications can prevent all the abuse of accounts.
At the time of registration, Sify may issue/give a 10 caracters alpha-numeric code or may be 5 such sets so as to make it more secure. Such a verification code set would be a permanent and not changeable by user in normal circumstances. Moreover such a set would not be visible even in the profile. The actual user only gets this verification code set once in his mail box at the time of registration.
First thing that a buyer of account does is to change the password. Now if a person knows that original owner of account can get his account back, he will most probably not buy it. Secondly, when account is hacked, the owner can simply type his verification code and get into profile and regain his account.
So far as hacking of verification code is concerned,its not possible because ,
1.Its sent only once in lifetime of account.
2.Its never used while logging in game/forum/profile etc.
Was wondering whether this is workable or not. If you think no , then please give reason.
At the time of registration, Sify may issue/give a 10 caracters alpha-numeric code or may be 5 such sets so as to make it more secure. Such a verification code set would be a permanent and not changeable by user in normal circumstances. Moreover such a set would not be visible even in the profile. The actual user only gets this verification code set once in his mail box at the time of registration.
First thing that a buyer of account does is to change the password. Now if a person knows that original owner of account can get his account back, he will most probably not buy it. Secondly, when account is hacked, the owner can simply type his verification code and get into profile and regain his account.
So far as hacking of verification code is concerned,its not possible because ,
1.Its sent only once in lifetime of account.
2.Its never used while logging in game/forum/profile etc.
Was wondering whether this is workable or not. If you think no , then please give reason.