Adblock breaks this site

Forum Account Recovery

Discussion in 'General Discussion' started by Dial, Sep 20, 2012.

?

Which options? Please read the thread first.

  1. Option #1

    17.6%
  2. Option #2

    5.9%
  3. Option #3

    58.8%
  4. Option #4 (post it)

    17.6%
  1. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Forum Account Recovery

    I'm looking for your opinions on what you'd rather see for account recovery. Say you forget your password for your Sythe account, how would you rather recover it?

    1. Go to a page on the forum, enter my username and answer 3 security questions that I made during registration.
    2. Go to a page on the forum, enter my username and answer 5 security questions that I made during registration.
    3. Go to a page on the forum, enter my username and enter a pin that I made during registration.
    4. Other option (please post it below).

    This has nothing to do with Sythe, but for an upcoming project that I'm working on. Just want to know what you guys think is the most secure way. Obviously having many security questions is the most secure way, but it may be annoying and/or hard to remember them all.

    Note: This is instead of the usual e-mail recovery method.
     
  2. sith kid

    sith kid Apprentice
    $5 USD Donor New

    Joined:
    May 24, 2007
    Posts:
    997
    Referrals:
    0
    Sythe Gold:
    0
    Forum Account Recovery

    Option 3 is what seems the most secure in the sense that it cannot be guessed.
     
  3. James

    James OK, Just a little pinprick-There'll be no more-ah!
    Village Drunk Retired Sectional Moderator

    Joined:
    Dec 12, 2007
    Posts:
    7,744
    Referrals:
    16
    Sythe Gold:
    68
    Facebook Promoter Sythe RSPS Player St. Patrick's Day 2013 Heidy Easter 2013 Oktoberfest 2013 Sythe's 10th Anniversary Tier 1 Prizebox St. Patrick's Day 2014 Tortoise Penis
    Halloween 2013
    Forum Account Recovery

    I'll tell you right now that I have no clue what security sentence I used upon registering this account...if any.
    I think that's the problem with this system.

    However I do not have another system in mind.
     
  4. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Forum Account Recovery

    Well I'm also looking for other ideas. I want to figure out the most secure way, yet a way where people remember what they put.
     
  5. Anet390

    Anet390 Grand Master
    $5 USD Donor New

    Joined:
    Jun 3, 2010
    Posts:
    2,223
    Referrals:
    1
    Sythe Gold:
    291
    Cryptocurrency Discussion Participant Paper Trading Competition Participant
    Forum Account Recovery

    I think the best way is to actually have option 1 and 3 mixed. I say 3 questions and a Pin. The pin can only be reset upon admins approval. So if I forgot my pin or questions, I would have to post in the dispute forum and get an admin to verify that the IP's match to make sure it is really you. If the admin feels that IP verification is not enough, he may ask the user a few questions about his or her acc. The questions would be answers and if like 2/3 are correct, you would be asked to enter ur pin, once that is answered u can recover ur acc. Dialatic - I am glad that someone is actually doing something to fix this. After my "send an email from the verified email to recover the acc" suggestion got closed, I lost faith in a good recovery process. I'm glad you are doing this!
     
  6. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Forum Account Recovery

    2/3 of you think that a pin would be better? You think you would remember that over personal questions?

    This is not for Sythe.
     
  7. mage3158

    mage3158 Grand Master

    Joined:
    Jan 27, 2007
    Posts:
    2,415
    Referrals:
    0
    Sythe Gold:
    330
    Discord Unique ID:
    148244190378196992
    Discord Username:
    Crabby#0989
    Not sure if srs or just newfag...
    Forum Account Recovery

    Option 3, as security questions can be social engineered.
     
  8. Jack

    Jack The Infamous Spam Forum King
    Retired Administrator Cool Cat Legendary

    Joined:
    Feb 20, 2011
    Posts:
    12,268
    Referrals:
    37
    Sythe Gold:
    871
    Member of the Month Winner Sythe's 10th Anniversary Wubba Lubba Dub Dub The Mortyest Morty Sythe Awards 2012 Winner Le Kingdoms Player Two Factor Authentication User Spam Forum Participant I'm LAAAAAAAME
    Signature of the Month Winner
    Forum Account Recovery

    Despite the social engineering who would really remember their unique pin? Some would write it down and lose it. Others may write it digitally but then if they get a RAT etc it could get bad also. If one was implemented there would definitely need to be like "get it wrong so many times and you get frozen out for x minutes" to prevent bots guessing it, etc
     
  9. mage3158

    mage3158 Grand Master

    Joined:
    Jan 27, 2007
    Posts:
    2,415
    Referrals:
    0
    Sythe Gold:
    330
    Discord Unique ID:
    148244190378196992
    Discord Username:
    Crabby#0989
    Not sure if srs or just newfag...
    Forum Account Recovery

    I would ;(
     
  10. Coin Casino

    Coin Casino Member

    Joined:
    May 26, 2012
    Posts:
    34
    Referrals:
    0
    Sythe Gold:
    0
    Forum Account Recovery

    I think maybe having one security question, a PIN, as well as having of course to reset through email aswell would be very secure IMO. Only idiots would lose their accounts.
     
  11. Dial

    Dial Experienced Web Developer
    $200 USD Donor New Pirate PHP Programmers

    Joined:
    Jul 12, 2010
    Posts:
    5,739
    Referrals:
    32
    Sythe Gold:
    126
    Sythe's 10th Anniversary Two Factor Authentication User MushyMuncher Member of the Month Winner Easter 2015
    Forum Account Recovery

    Having that much information would be secure, yes. But it would also be a hassle for users to remember.

    Still looking for ideas!
     
  12. BGlave

    BGlave Guru
    Banned

    Joined:
    Nov 11, 2011
    Posts:
    1,933
    Referrals:
    0
    Sythe Gold:
    0
    Forum Account Recovery

    A pin is more easy to remember when three questions.
     
  13. Laptop65

    Laptop65 Hero
    $50 USD Donor New

    Joined:
    Dec 19, 2010
    Posts:
    7,919
    Referrals:
    4
    Sythe Gold:
    436
    Sythe RSPS Player Sythe Awards 2012 Winner Sythe's 10th Anniversary St. Patrick's Day 2013
    Forum Account Recovery

    How about 5 security questions AND the pin?
     
  14. R

    R Legend
    Retired Administrator Roary Donor Mudkips Legendary

    Joined:
    Apr 4, 2011
    Posts:
    19,571
    Referrals:
    16
    Sythe Gold:
    572
    In Memory of Jon <3 n4n0 Sythe Awards 2013 Winner
    Forum Account Recovery

    I'd say a PIN number. They're easier to remember than security questions or phrases, I don't know what my recovery questions are on Runescape nor do I remember any security phrases on Sythe... Hell, I don't even know the e-mail address I used to sign up to Sythe... PIN numbers are used in daily situations, making it the same as your work PIN number or card PIN number would make it memorable - for example, my RS PIN is the same as my college PIN.
     
  15. SexayMistahBee

    SexayMistahBee Sexiest Bee On Earth
    $50 USD Donor New

    Joined:
    Feb 28, 2006
    Posts:
    2,410
    Referrals:
    0
    Sythe Gold:
    27
    Discord Username:
    SexayMistahBee
    Forum Account Recovery

    I have a four digit pin that I use for everything, so a pin would probably be the most convenient for me

    But if the server got hacked and somebody figured out my pin, I'd have a problem bigger than a simple community accunt hacking to deal with...
     
  16. Brendan

    Brendan Your friendly neighbourhood cuck
    $50 USD Donor Retired Sectional Moderator

    Joined:
    Sep 19, 2009
    Posts:
    8,418
    Referrals:
    4
    Sythe Gold:
    18
    Sythe Awards 2012 Winner Christmas 2015 Valentine's Day 2016 Easter 2016 MushyMuncher Tier 1 Prizebox
    Forum Account Recovery

    I think many people would forget their pin number or security question answers. When I sign up for a website that I don't expect to use often, I type in random stuff for the questions. I didn't expect to use Sythe when I signed up either. I say lets leave it with the emails, however not permit hotmails.
     
  17. The Last Demon

    The Last Demon Member
    Banned

    Joined:
    Sep 22, 2012
    Posts:
    84
    Referrals:
    0
    Sythe Gold:
    0
    Forum Account Recovery

    Option three is pretty good, the security options don't work well because people can easily manipulate others into retrieving their security questions.

    i.e; "where do you live" someone can easily find that out by asking the user.
     
  18. Noam

    Noam Apostle of the Setting Sun
    $50 USD Donor New Competition Winner

    Joined:
    Jul 27, 2011
    Posts:
    2,993
    Referrals:
    1
    Sythe Gold:
    0
    Discord Unique ID:
    688859853535313930
    Discord Username:
    sarbaz#8969
    Two Factor Authentication User Gohan has AIDS
    Forum Account Recovery

    3 questions and a pin, as long as the pin isn't hashed on your end. It needs a stronger algorithm for something short and numerical
     
  19. Shall Skill

    Shall Skill Sigma Alpha Mooooo
    $100 USD Donor

    Joined:
    Jul 24, 2008
    Posts:
    3,404
    Referrals:
    4
    Sythe Gold:
    512
    Paper Trading Competition Participant ???
    Forum Account Recovery

    I don't understand how everybody thinks it'll be hard to remember their 4 digit pin. Every debit card user knows their 4 digit pin and there are a whole lot of debit card users. It's not hard to remember at all and it's a lot safer than security questions.

    So in short, option 3.
     
  20. Got UPGRADES

    Got UPGRADES Member
    Banned

    Joined:
    Sep 18, 2012
    Posts:
    78
    Referrals:
    0
    Sythe Gold:
    0
    Forum Account Recovery

    I like option 3 the best :)
     
< Have You Ever.. | Latest Marijuana Trend >


 
 
Adblock breaks this site