Page 1 of 1

Account Security

Posted: June 11th, 2008, 11:48 am
by Han
Here is the text of a new policy for our officers, and all guild members are strongly encouraged to follow these suggestions:   Anyone who is of rank Organizer must never ever type their account name, then tab, then password when logging into WoW.  No matter how secure you think your pc is, there can be a new iteration of a keylogger nobody knows about.  Everyone should have the "remember my account name" feature enabled.  Just checking that box means you will never type your account name unless you are switching accounts.  For the password, Either type your password in a txt doc and save it on your desktop, then ctrl+c and ctrl+v it into the password field, or worst case scenario if you are at some other pc, type a bogus password, highlight the characters with your mouse (keyloggers dont pick this up), and then just type your real password over it. Assuming your real password was "pass1" and the bogus one was "pass2", the keylogger would pick up "pass2pass1" as the password, thus keeping you safe.  Now that its happened to several organizers, we need to just prevent it from happening again.  Don't take the "It wont happen to me" attitude, because it can and it will without adequate precautions.  Antivirus, antikeylogger software is not enough.  These simple steps prevent the possibility of any keylogger ever getting your username and password. This is not meant to bash anyone (trust me I know how horrible it feels to have been compromised), just a new policy to prevent future mishaps.  Thank you all.

Account Security

Posted: June 11th, 2008, 1:15 pm
by Akumabarai
I think it's been mentioned before, but I'll throw out some more FireFox love, just in case:
Adblock Plus

Adblock Filterset.G

NoScript

With these addons running, you should avoid 99% of all adds, preventing one of the ways you can obtain a keylogger. This does not prevent all of the ways though, so the aforementioned rules still apply.

And yes, I'm a large follower of the mixing some mouse clicks into your password to thwart keyloggers. Recording mouse clicks and positions relative to certain screen resolutions is exceedingly difficult compared to just recording keyboard input. That's not to say it can't be done though.

For my password, I have some numerics/symbols followed by alpha characters. I type in the alpha characters first, and then click on the password prompt to re-position the cursor so I can type in the numerics/symbols.