For Neopets ONLY discussion.
Topic locked

Thu Feb 09, 2006 5:27 pm

It's great. My only concern is if someone falls for a cookie grabber - then does the scammer get their pin code along with their password?

Thu Feb 09, 2006 6:11 pm

Better yet suppose if someone changes your pin number?.

Thu Feb 09, 2006 6:13 pm

Shifty wrote:It's great. My only concern is if someone falls for a cookie grabber - then does the scammer get their pin code along with their password?


No, they wouldn't. That's not stored in the cookie.

Thu Feb 09, 2006 6:31 pm

After playing with the PIN for the past few days it's become clear that it's a hindrance in places you visit frequently. It's turned off only for my bank and shop stock, and on for everything else. If I leave for more than a couple of days I will turn on the bank and shop stock.

It just makes me feel like, should anyone break into my account, things would be protected for a little while; hopefully long enough for me to notice and contact TNT.

Thu Feb 09, 2006 7:03 pm

Shifty wrote:It's great. My only concern is if someone falls for a cookie grabber - then does the scammer get their pin code along with their password?


The pin is not in a cookie, so there's a help! Yes, it can be a slight inconvenience, but it only takes a few seconds to type that pin in the box. I'll take that small inconvenience over having to worry that someones's going to cg me, etc. and take everything I've earned.

The concern over someone getting the pin was why, when the beta testing started, so many of us asked for either the adding of the pin needed or a different pin (which I guess would be really hard to implement) for email changes. When the pin beta was first introduced the pin was good, but all someone needed to do was get into your account, change the email and have the pin emailed to that new (scammer's) email.

So, if heaven forbid you do get scammed, cracked, cg'ed, etc. - yes they can change your password but if you've set up and enabled the pin for your email, unless they can guess or try to brute force your pin, they can't change the email. No email change, no pin.

The only kind of odd thing I noticed last night, having had np in my till, was that the pin for your shop is only for stock, not your till. That surprised me, I thought it would be for both stock and till. So, if you're using a pin for your shop and/or your bank be sure to empty your shop till and deposit the np on a regular basis.

Stocks I think should be added. No, I don't have but maybe 2k in stocks, but alot of people DO have alot invested there. I also think the pin should be implemented for removing things from your neohome. There are people who've spent literally millions on them. And trades should be an option too. The TP has become a hotbed of scamming possibilities lately.

Overall, I think the pin is a good idea. Of course we all need to do what we can to keep our accounts and information safe (everywhere, not just neo). Part of that is having a very hard to guess/changing often password and if you're using the pin don't just use 1234 or 0987 or your birthday. Also not storing passwords and regularly clearing your internet and running scans, as well as watching where you go on the internet.

I think this is TNT's way of dealing with the rash of cg'ers short of actually putting something in the news, which we know they're not going to do. They're trying to help us help ourselves.

Thu Feb 09, 2006 7:21 pm

Well, if pins not being stored in cookies is true, then I'm overjoyed. Because I've been dealing with auctions, trades and general marketing lately I keep catching myself falling to popular neoboards such as "UB in shop!". I often panic and have been reseting my password, fearing it could've been a trick after remembering past CG issues, five times a day and clearing cookies six times more. With a pin this'll give me that secure feeling I need.

Thu Feb 09, 2006 9:18 pm

Bangel wrote:
dolphinling wrote:I'd rather they work on making it so no one can get into the account in the first place.

Which is impossible. Neopets can't discontinue every single cookie grabber site,

The way cookie grabbers work, they must be on neopets itself. Another site cannot view your neopets cookies. Neopets only needs to protect its own site, which it has the means to do.

Bangel wrote:Neopets cannot prevent people from accidently sharing secret question answers (does Neopets even have those? I don't recall.), and finally, Neopets cannot prevent the less-than-smart people who tell strangers their password.

...And people who give out their password are the exact same people who would give out their PIN. It's impossible to protect those people by technical means because it's not a technical problem, it's a social one. What I want is better solutions for people who won't be stupidly giving away their password.

Thu Feb 09, 2006 10:13 pm

When I email my suggestion of where to add the pin, I'd like to have the ones that everyone else thinks it should be added too. So if I'm missing something, please add it to the list. And don't forget, if you don't want it to have a pin, just don't check that box. Don't shoot down the idea if someone else wants it there. It can't be a bad idea, because you don't have to use it. :)

stocks
neohome
shop till
TCG deck
neodeck
user lookup
password change (although that would be on your user lookup anyway)


Maybe something on the guilds? If you're the leader of a guild, or a council member, and someone's in your account, they could cause huge problems in the guild. (kicking people out, changing the layout, etc) But I wouldn't know where the pin would go for that.

Am I missing anything that anyone could possibly want a pin on?

Thu Feb 09, 2006 10:26 pm

I love the PIN. I think it's a great idea.

I've already got it set - though I admit I haven't tried to use it yet.

Thu Feb 09, 2006 11:10 pm

Aaaah only 4 digits, question, can you change your pin?

Thu Feb 09, 2006 11:13 pm

You can, I just checked.

Fri Feb 10, 2006 1:25 am

AQ, considering that during the awful cg weekend at least one person who was a guild leader was accessed and a cg was put on the guild front page, which of course had the domino effect of anyone going to the guild getting grabbed to, then the person did change the guild layout to something pretty bad - I think having the pin for guild leaders would be a pretty good idea.

The fact that it's come to this is pretty sad. I agree that there's always going to be people who for whatever reason (usually something greedy) do give their password to someone else -- and there's nothing anyone can do about that and that the same will probably happen with the pin.

But for the most part, most of us do know better. And even with knowing better and doing our best to keep our information and our accounts safe too many people have been affected by security and coding holes or glitches which have allowed this to happen.

We should take advantage of the help TNT's giving us with the pin - even if you don't like the pin. At least use it just for your email and your pet if you don't care to use the pin elsewhere.

And let's hope that the programmers, who I believe work very hard, do look for, find and fix any problems, holes or vulnerabilities. I just wish they could find a way to completely do away with the cheaters. I know, it's not possible, but it's nice to dream of a safe site with no ABers, cgers, autospammers, autoadopters, etc.

Fri Feb 10, 2006 1:33 am

It's a little sad?. If not better for more security, it even makes it a little.. Well.
Don't laugh, more realistic. Come on, it's like having your own little Neopets
debt card with it's fancy little pin!. :P

Fri Feb 10, 2006 7:39 am

Looks like they've activated it for regular users, finally.

I'll probably only use it for bank/SDB when I'm going away.. I have a feeling it'll get too annoying for me.

Fri Feb 10, 2006 8:39 am

I think, like most things, it'll take some getting used to
Topic locked