Forum Account Recovery

Discussion in 'General Discussion' started by Dial, Sep 20, 2012.

?

Which options? Please read the thread first.

  1. Option #1

    17.6%
  2. Option #2

    5.9%
  3. Option #3

    58.8%
  4. Option #4 (post it)

    17.6%
Forum Account Recovery
  1. Unread #1 - Sep 20, 2012 at 11:47 PM
  2. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Forum Account Recovery

    I'm looking for your opinions on what you'd rather see for account recovery. Say you forget your password for your Sythe account, how would you rather recover it?

    1. Go to a page on the forum, enter my username and answer 3 security questions that I made during registration.
    2. Go to a page on the forum, enter my username and answer 5 security questions that I made during registration.
    3. Go to a page on the forum, enter my username and enter a pin that I made during registration.
    4. Other option (please post it below).

    This has nothing to do with Sythe, but for an upcoming project that I'm working on. Just want to know what you guys think is the most secure way. Obviously having many security questions is the most secure way, but it may be annoying and/or hard to remember them all.

    Note: This is instead of the usual e-mail recovery method.
     
  3. Unread #2 - Sep 20, 2012 at 11:50 PM
  4. sith kid
    Joined:
    May 24, 2007
    Posts:
    997
    Referrals:
    0
    Sythe Gold:
    0

    sith kid Apprentice
    $5 USD Donor New

    Forum Account Recovery

    Option 3 is what seems the most secure in the sense that it cannot be guessed.
     
  5. Unread #3 - Sep 20, 2012 at 11:50 PM
  6. James
    Joined:
    Dec 12, 2007
    Posts:
    7,744
    Referrals:
    16
    Sythe Gold:
    68
    Facebook Promoter Sythe RSPS Player St. Patrick's Day 2013 Heidy Easter 2013 Oktoberfest 2013 Sythe's 10th Anniversary Tier 1 Prizebox St. Patrick's Day 2014 Tortoise Penis
    Halloween 2013

    James OK, Just a little pinprick-There'll be no more-ah!
    Village Drunk Retired Sectional Moderator

    Forum Account Recovery

    I'll tell you right now that I have no clue what security sentence I used upon registering this account...if any.
    I think that's the problem with this system.

    However I do not have another system in mind.
     
  7. Unread #4 - Sep 20, 2012 at 11:51 PM
  8. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Forum Account Recovery

    Well I'm also looking for other ideas. I want to figure out the most secure way, yet a way where people remember what they put.
     
  9. Unread #5 - Sep 20, 2012 at 11:56 PM
  10. Anet390
    Joined:
    Jun 3, 2010
    Posts:
    2,223
    Referrals:
    1
    Sythe Gold:
    291
    Cryptocurrency Discussion Participant Paper Trading Competition Participant

    Anet390 Grand Master
    $5 USD Donor New

    Forum Account Recovery

    I think the best way is to actually have option 1 and 3 mixed. I say 3 questions and a Pin. The pin can only be reset upon admins approval. So if I forgot my pin or questions, I would have to post in the dispute forum and get an admin to verify that the IP's match to make sure it is really you. If the admin feels that IP verification is not enough, he may ask the user a few questions about his or her acc. The questions would be answers and if like 2/3 are correct, you would be asked to enter ur pin, once that is answered u can recover ur acc. Dialatic - I am glad that someone is actually doing something to fix this. After my "send an email from the verified email to recover the acc" suggestion got closed, I lost faith in a good recovery process. I'm glad you are doing this!
     
  11. Unread #6 - Sep 21, 2012 at 12:42 AM
  12. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Forum Account Recovery

    2/3 of you think that a pin would be better? You think you would remember that over personal questions?

    This is not for Sythe.
     
  13. Unread #7 - Sep 21, 2012 at 12:47 AM
  14. mage3158
    Joined:
    Jan 27, 2007
    Posts:
    2,415
    Referrals:
    0
    Sythe Gold:
    330
    Discord Unique ID:
    148244190378196992
    Discord Username:
    Crabby#0989
    Not sure if srs or just newfag...

    mage3158 Grand Master

    Forum Account Recovery

    Option 3, as security questions can be social engineered.
     
  15. Unread #8 - Sep 21, 2012 at 1:05 AM
  16. Jack
    Joined:
    Feb 20, 2011
    Posts:
    12,268
    Referrals:
    37
    Sythe Gold:
    871
    Member of the Month Winner Sythe's 10th Anniversary Wubba Lubba Dub Dub The Mortyest Morty Sythe Awards 2012 Winner Le Kingdoms Player Two Factor Authentication User Spam Forum Participant I'm LAAAAAAAME
    Signature of the Month Winner

    Jack The Infamous Spam Forum King
    Retired Administrator Cool Cat Legendary

    Forum Account Recovery

    Despite the social engineering who would really remember their unique pin? Some would write it down and lose it. Others may write it digitally but then if they get a RAT etc it could get bad also. If one was implemented there would definitely need to be like "get it wrong so many times and you get frozen out for x minutes" to prevent bots guessing it, etc
     
  17. Unread #9 - Sep 21, 2012 at 1:32 AM
  18. mage3158
    Joined:
    Jan 27, 2007
    Posts:
    2,415
    Referrals:
    0
    Sythe Gold:
    330
    Discord Unique ID:
    148244190378196992
    Discord Username:
    Crabby#0989
    Not sure if srs or just newfag...

    mage3158 Grand Master

    Forum Account Recovery

    I would ;(
     
  19. Unread #10 - Sep 21, 2012 at 1:45 AM
  20. Coin Casino
    Joined:
    May 26, 2012
    Posts:
    34
    Referrals:
    0
    Sythe Gold:
    0

    Coin Casino Member

    Forum Account Recovery

    I think maybe having one security question, a PIN, as well as having of course to reset through email aswell would be very secure IMO. Only idiots would lose their accounts.
     
  21. Unread #11 - Sep 21, 2012 at 9:57 AM
  22. Dial
    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Forum Account Recovery

    Having that much information would be secure, yes. But it would also be a hassle for users to remember.

    Still looking for ideas!
     
  23. Unread #12 - Sep 21, 2012 at 10:08 AM
  24. BGlave
    Joined:
    Nov 11, 2011
    Posts:
    1,933
    Referrals:
    0
    Sythe Gold:
    0

    BGlave Guru
    Banned

    Forum Account Recovery

    A pin is more easy to remember when three questions.
     
  25. Unread #13 - Sep 21, 2012 at 10:16 AM
  26. Laptop65
    Joined:
    Dec 19, 2010
    Posts:
    7,919
    Referrals:
    4
    Sythe Gold:
    436
    Sythe RSPS Player Sythe Awards 2012 Winner Sythe's 10th Anniversary St. Patrick's Day 2013

    Laptop65 Hero
    $50 USD Donor New

    Forum Account Recovery

    How about 5 security questions AND the pin?
     
  27. Unread #14 - Sep 21, 2012 at 12:31 PM
  28. R
    Joined:
    Apr 4, 2011
    Posts:
    19,571
    Referrals:
    16
    Sythe Gold:
    572
    In Memory of Jon <3 n4n0 Sythe Awards 2013 Winner

    R Legend
    Retired Administrator Roary Donor Mudkips Legendary

    Forum Account Recovery

    I'd say a PIN number. They're easier to remember than security questions or phrases, I don't know what my recovery questions are on Runescape nor do I remember any security phrases on Sythe... Hell, I don't even know the e-mail address I used to sign up to Sythe... PIN numbers are used in daily situations, making it the same as your work PIN number or card PIN number would make it memorable - for example, my RS PIN is the same as my college PIN.
     
  29. Unread #15 - Sep 21, 2012 at 9:35 PM
  30. SexayMistahBee
    Joined:
    Feb 28, 2006
    Posts:
    2,410
    Referrals:
    0
    Sythe Gold:
    27
    Discord Username:
    SexayMistahBee

    SexayMistahBee Sexiest Bee On Earth
    $50 USD Donor New

    Forum Account Recovery

    I have a four digit pin that I use for everything, so a pin would probably be the most convenient for me

    But if the server got hacked and somebody figured out my pin, I'd have a problem bigger than a simple community accunt hacking to deal with...
     
  31. Unread #16 - Sep 22, 2012 at 9:36 AM
  32. Brendan
    Joined:
    Sep 19, 2009
    Posts:
    8,418
    Referrals:
    4
    Sythe Gold:
    18
    Sythe Awards 2012 Winner Christmas 2015 Valentine's Day 2016 Easter 2016 MushyMuncher Tier 1 Prizebox

    Brendan Your friendly neighbourhood cuck
    $50 USD Donor Retired Sectional Moderator

    Forum Account Recovery

    I think many people would forget their pin number or security question answers. When I sign up for a website that I don't expect to use often, I type in random stuff for the questions. I didn't expect to use Sythe when I signed up either. I say lets leave it with the emails, however not permit hotmails.
     
  33. Unread #17 - Sep 22, 2012 at 9:45 PM
  34. The Last Demon
    Joined:
    Sep 22, 2012
    Posts:
    84
    Referrals:
    0
    Sythe Gold:
    0

    The Last Demon Member
    Banned

    Forum Account Recovery

    Option three is pretty good, the security options don't work well because people can easily manipulate others into retrieving their security questions.

    i.e; "where do you live" someone can easily find that out by asking the user.
     
  35. Unread #18 - Sep 23, 2012 at 1:52 PM
  36. Noam
    Joined:
    Jul 27, 2011
    Posts:
    2,993
    Referrals:
    1
    Sythe Gold:
    0
    Discord Unique ID:
    688859853535313930
    Discord Username:
    sarbaz#8969
    Two Factor Authentication User Gohan has AIDS

    Noam Apostle of the Setting Sun
    $50 USD Donor New Competition Winner

    Forum Account Recovery

    3 questions and a pin, as long as the pin isn't hashed on your end. It needs a stronger algorithm for something short and numerical
     
  37. Unread #19 - Sep 23, 2012 at 1:59 PM
  38. Shall Skill
    Joined:
    Jul 24, 2008
    Posts:
    3,404
    Referrals:
    4
    Sythe Gold:
    512
    Paper Trading Competition Participant ???

    Shall Skill Sigma Alpha Mooooo
    $100 USD Donor

    Forum Account Recovery

    I don't understand how everybody thinks it'll be hard to remember their 4 digit pin. Every debit card user knows their 4 digit pin and there are a whole lot of debit card users. It's not hard to remember at all and it's a lot safer than security questions.

    So in short, option 3.
     
  39. Unread #20 - Sep 23, 2012 at 2:01 PM
  40. Got UPGRADES
    Joined:
    Sep 18, 2012
    Posts:
    78
    Referrals:
    0
    Sythe Gold:
    0

    Got UPGRADES Member
    Banned

    Forum Account Recovery

    I like option 3 the best :)
     
< Have You Ever.. | Latest Marijuana Trend >

Users viewing this thread
1 guest


 
 
Adblock breaks this site