Quote:
Originally Posted by counthomer
Actually this is a very common misconception about random key generators - if someone has control over your machine they are no defence, as all I have to do is get you to put your code into something you think is your poker client, display some error prompt that makes you think there is a problem with the site and intercept any emails you send to support. Of course, I will only have six seconds or so to retransmit that login data, but that is a lifetime in computer security terms.
However, this brings me back to my original point - if I have control over your computer (such as through a key logger) why would I make an effort to build a mock copy of FTP, intercept your emails to support etc? The answer is that I wouldn't - I would go after your bank, share and maybe ewallet accounts.
Note I never said that it was all up to the player (the sites certainly need to do their bit) but if you are so concerned there are ways you can guarantee your own security 100% now by yourself.
|
Here is my point...security ID's WOULD in fact make it significantly more difficult to hack an account. My main point, however, is that unless you are a top level hacker yourself, you probably don't know enough to make the claims you do. That is my problem. I do everything I think I should, but because I myself am not a master in that field, I can't know what people who are that proficient are capable of. From my limited reading in the subject, a talented and motivated hacker can easily get by a person like me, who does what he should that is standard but doesn't understand the deeper vulnerabilities.
I also think an important addition to security that would be good would be some kind of approved IP address situation. You can only sign on using approved IP addresses unless you give FT some kind of warning that you will be signing on elsewhere. This of course would be a problem if the hacker has your email address, but if they don't know that rule, FT can be alerted when a random IP is signing on. Just a thought.
Really the NUMBER ONE thing they could do which they refuse do to spinelessness, is having LIVE PHONE SUPPORT for emergencies. They can have people who only answer the phone for emergency situations and when the thousands of calls come in that aren't emergencies, they can just direct them to email support and be just as obnoxious as TILT PAY.