View Single Post
Old 09-01-2007, 01:32 PM  
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
BTW gmr324, if I forget to contact you guys next week remind me.
I'm putting you in my will. Seriously. We have some new technology
that you guys could put to good use if myn own employees choose not
to continue the business.

Quote:
Originally Posted by gmr324 View Post
Once again, four plus years of experience with AMS
bears out the fact overwhemingly that the highest
percentage of pass trading can be attributed to
hackers and not members. So, any system should
address the most frequently occurring problem.
Absolutely. We just have different ways of addressing that problem.
You guys address that problem by assuming that it's always hackers
and a "member", who may have signed up with a stolen credit card
just for the purpose of getting a pass to share, is always innocent, so you
keep giving him new passwords and if he keeps sharing them oh well.
That may even be a somewhat reasonable approach if you don't
have the capability to do what we do. Our approach, in the recommended
configuration, is to simply eliminate the problem of crackers getting
passwords in the first place. Once we've essentially eliminated the
ability of a cracker to get a password, we know that any passwords
that get out were probably shared by the "member".

Quote:
I wouldn't continue paying for a membership
where I didn't have predictable constant access,
would you?
I wouldn't give out my password, so it wouldn't be an issue if the site used
Strongbox in the recommended configuration. I certainly wouldn't expect
to have predicatble constant access if I kept giving out my passwords to
10,000 of my closest friends.



Quote:
If a member were to trade their password with a friend,
Frog's Geo-IP Tracking would detect even such low
profile abuse and block it. It wouldn't take exchanging
many dead passwords like this for these friends to
discontinue the practice.
Why would they care if they accidently got one blocked?
By the time they know it's blocked they already have a fresh
new one in their inbox, courtesy of Frog.


Quote:
If members are guilty of trading passwords with their
friends, what would prevent them trading or circulating
a password that is manually issued to them by a
webmaster? Either way, (manual or AMS) they've been
handed a password that can be tracked for abuse
and confronted.
The webmaster can make intelligent decisions about who to issue new
passwords to. For example, most webmasters won't give a new guy from
Russia six new passwords in his first six days. They'll see what's going on
and tell the guy to either keep his password to himself or go elsewhere.
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote