These forums have been archived and are now read-only.

The new forums are live and can be found at https://forums.eveonline.com/

EVE General Discussion

 
  • Topic is locked indefinitely.
12Next page
 

Why is login and character info stored in plain text?

First post
Author
MinefieldS
1 Sick Duck Standss on something
#1 - 2012-11-20 00:17:09 UTC
Don't you think it should be encrypted, CCP? Now it suddenly makes sense why Dust is PS3 only...

By the way you can find all this info in your ........Local Settings\Application Data\CCP\EVE\...... directory(ies).
Tippia
Sunshine and Lollipops
#2 - 2012-11-20 00:19:45 UTC
So encrypt your local folder?
Mars Theran
Foreign Interloper
#3 - 2012-11-20 02:01:09 UTC
Tippia wrote:
So encrypt your local folder?


Must have a means. Question: Will EVE be able to read it after? ..or will it just write another one?
zubzubzubzubzubzubzubzub
James Amril-Kesh
Viziam
Amarr Empire
#4 - 2012-11-20 02:04:59 UTC
I don't see any plaintext login info in any of these files.

Enjoying the rain today? ;)

Demolishar
United Aggression
#5 - 2012-11-20 02:36:27 UTC
Finally a way to clear my username list bloat?
Shaera Taam
Khanid Prime Free Irregulars
#6 - 2012-11-20 02:56:00 UTC
Demolishar wrote:
Finally a way to clear my username list bloat?


One can hope... Even *I* have that problem, and i dont play the alt game (any more, hehe)...

Thus Spake the Frigate Goddess!

Zero Audier
Garoun Investment Bank
Gallente Federation
#7 - 2012-11-20 03:57:04 UTC
Shaera Taam wrote:
Demolishar wrote:
Finally a way to clear my username list bloat?


One can hope... Even *I* have that problem, and i dont play the alt game (any more, hehe)...


Yet you still find time to get on the forums. Roll
SmilingVagrant
Doomheim
#8 - 2012-11-20 03:59:18 UTC
Mars Theran wrote:
Tippia wrote:
So encrypt your local folder?


Must have a means. Question: Will EVE be able to read it after? ..or will it just write another one?


Truecrypt.
Surfin's PlunderBunny
Sebiestor Tribe
Minmatar Republic
#9 - 2012-11-20 04:06:43 UTC
Or do what I do, just ignore it Big smile

"Little ginger moron" ~David Hasselhoff 

Want to see what Surf is training or how little isk Surf has?  http://eveboard.com/pilot/Surfin%27s_PlunderBunny

Danica Duan
#10 - 2012-11-20 06:16:30 UTC
SmilingVagrant wrote:
Mars Theran wrote:
Tippia wrote:
So encrypt your local folder?


Must have a means. Question: Will EVE be able to read it after? ..or will it just write another one?


Truecrypt.

True dat.
Mars Theran
Foreign Interloper
#11 - 2012-11-20 06:30:56 UTC
Danica Duan wrote:
SmilingVagrant wrote:
Mars Theran wrote:
Tippia wrote:
So encrypt your local folder?


Must have a means. Question: Will EVE be able to read it after? ..or will it just write another one?


Truecrypt.

True dat.


Thanks, I'll have to look into that. Smile
zubzubzubzubzubzubzubzub
Shaera Taam
Khanid Prime Free Irregulars
#12 - 2012-11-20 07:16:19 UTC
Zero Audier wrote:
Shaera Taam wrote:
Demolishar wrote:
Finally a way to clear my username list bloat?


One can hope... Even *I* have that problem, and i dont play the alt game (any more, hehe)...


Yet you still find time to get on the forums. Roll


Sad

here i am, on a long wait in PHX airport, posting on my main, remembering back to several failed trial accounts, and i get flamed...

sigh...

oh well, time to go see if i can get rid of those extra names...

Thus Spake the Frigate Goddess!

Ptraci
3 R Corporation
#13 - 2012-11-20 10:21:23 UTC
MinefieldS wrote:
Don't you think it should be encrypted, CCP? Now it suddenly makes sense why Dust is PS3 only...

By the way you can find all this info in your ........Local Settings\Application Data\CCP\EVE\...... directory(ies).


Pretty much the first rule of security is that if someone has physical access to your system, then your system is compromised and there's nothing you can do about it.

This is a computer game, not an online banking website. Why would the login be encrypted? Think yourself fortunate CCP are smart enough not to store your password for you, in plain text, as well.
Chribba
Otherworld Enterprises
Otherworld Empire
#14 - 2012-11-20 10:50:18 UTC  |  Edited by: Chribba
We talking about the account name? Tbh probably more a risk of you taking a screenshot of the new login screen forgetting to wipe the name than someone accessing the files there to read your login name.

And while account name could potentially do harm, I would say I would be more worried about if someone accessed my system that there is a risk of a keylogger there already stealing my password.

But then, even if CCP decides to encrypt/scramble the files someone would probably figure out a decoder pretty quickly. If anything (assuming we're talking account security here) I would like to see additional account security features, like hardware dongle, IP-restrictions etc that we can enable if we chose to do so.

edit/Also I believe our browser cookies/saved forms are a greater threat in terms of finding account names...

/c

★★★ Secure 3rd party service ★★★

Visit my in-game channel 'Holy Veldspar'

Twitter @ChribbaVeldspar

Wodensun
Caldari Provisions
Caldari State
#15 - 2012-11-20 11:03:58 UTC  |  Edited by: Wodensun
Your login isnt stored there. Only character data thats being cached.

And the reason isnt not encrypted is because you'd have to decrypt it every time you started up the game which adds more processor cycles to the startup.

Do not give me likes them 101 likes arent a accident...

CCP Stillman
C C P
C C P Alliance
#16 - 2012-11-20 11:08:09 UTC
The only login information that is stored is your username. We removed the functionality for the client to remember your password many years ago, because there's no safe way of doing it.

And yes, we cache character data on your drive, together with other semi-static data.

Just a random dude in Team Security.

Wodensun
Caldari Provisions
Caldari State
#17 - 2012-11-20 11:10:11 UTC
/thread

Do not give me likes them 101 likes arent a accident...

Pierced Brosmen
The Scope
Gallente Federation
#18 - 2012-11-20 11:20:08 UTC
CCP Stillman wrote:
The only login information that is stored is your username.

On that note. Is there a decent way to remove names that are stored?

Last summer a friend of mine used my lap-top to log in and switch skill training on some of his accounts and it's annoying to have his account names listed whenever I'm logging into eve on that machine (I have started new accounts since that and now his account names are in between mine wich is annoying as hell).

Input fields in eve (like the contract window's name field for private contracts, the search field in the market and such) has a right-click option to "Clear history"... Why can't something like that be implemented for the account name field at log-in?
Wodensun
Caldari Provisions
Caldari State
#19 - 2012-11-20 11:22:06 UTC
just clear the cache? aint rocket science...

Do not give me likes them 101 likes arent a accident...

Pierced Brosmen
The Scope
Gallente Federation
#20 - 2012-11-20 11:37:23 UTC
Don't recall clearing cache in the past has done anything with the account names at log-in
12Next page