Myst Online: Uru Live Again
mystonline.com
mystonline.com
Probably worth being careful with password choice if you're going to sign-up to this. Don't use one of your existing ones!
Other than that, I'm so glad to see Myst back!
Well you never should.
On the subject of red flags during signup, a password length restriction is always a red flag to me. If you're hashing my password, you don't care how long it is, right? If you limit length, I assume it's stored in plain text.
All of my accounts hooked to finance, or email, etc, are all unique strong passwords.
However, I have a throwaway password for throwaway sites, or sites I'm unsure of the security for.
Can anyone explain why using the same junk password for forums, crappy webgames, temporary reddit accounts, etc is a problem?
Why should I take up the brain-space to memorize a unique password for a site like this?
Steve Gibson uses it, I won't pretend to be as capable of speaking to it's benefits so I encourage you to listen to Security Now.
Edit: Last pass can be loaded once in the browser, and if you link it to a yubikey it is much more secure. http://blog.lastpass.com/2010/07/lastpass-gets-green-light-f....
I don't like keeping lastpass with a master password because typing a strong, long master password every single time I want any password is not a use case I enjoy, and I certainly don't want to lock up my passwords with something that is easily defeatable.
And without a strong master password locking every attempt to use lastpass, it becomes far, far less secure than memorizing passwords.
Also consider linking to a yubikey. https://helpdesk.lastpass.com/security-options/multifactor-a...
EDIT: DO NOT FOR ANY REASON DO THIS >for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
I cannot respond directly to Munin but anyone who suggest that is going to lead you to this http://www.telegraph.co.uk/news/uknews/crime/10276460/David-...
Someone could get a hold of your wallet and take a pic of your passwords then put them back and you'd never know you'd been compromised. And Lastpass uses the trust no one mentality so you don't have to trust them. They never see your password it's encrypted using your password and yubikey if you have one.
http://www.theregister.co.uk/2001/06/25/steve_gibson_really_...
https://www.schneier.com/blog/archives/2005/06/write_down_yo...
But, of course, don't write the password to an encrypted drive on a piece of paper that you keep with the drive.
Sure write them down if they don't matter, but don't write your bank account password down, or your google account. Especially if you have your ID in your wallet it'd be pretty easy to find you and get all your passwords if you lost your wallet. If you DO write them down, leave some portion of your password off.
I.E. your password is "password*&^&" only write down "password" and append the rest from memory.
Then they could go to my computer and photograph my LastPass which, as this thread explains, is perfectly 'secure' to leave without a master password on 'trusted' machines.
Literally identical threat, IMO, being personally targeted for password theft.
If they can get my wallet, they can get to my desktop, I imagine.
assuming that every place you use a password is both competent and honest (which is a stretch), the only way for someone to get your passwords is to compromise your computer. if they do that, and you use lastpass, then they have all of your passwords.
for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
LastPass has made certain compromises in security to give you more functionality. For example, you can log into their website and enter your master password, to retrieve any other password. This is bad since the browser can be compromised.
However, I trust the browser and LastPass more than I trust my ability to keep the passwords secure. There is no way that I am going to remember the 300 or so passwords I have stored in LastPass and I will certainly not be able to change them as fast as I sometimes have to.
I am not saying that LastPass is the end-all-be-all of security, but compared to what 99.999% of people are doing, it is a huge win. IMHO, your statements are spreading FUD.
> assuming that every place you use a password is both competent and honest (which is a stretch), the only way for someone to get your passwords is to compromise your computer. if they do that, and you use lastpass, then they have all of your passwords.
That assumption has been proven time and again to be completely false. As someone who had their BTC stolen while using what would be considered a secure password, I can say that password cracking against a stolen database dump is not a theoretical threat.
> for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
This goes directly against your initial point that you don't know when your passwords have been compromised. You have no idea when someone takes a picture of your password sheet :)
You can also get 2 factor authentication (free with google authenticator on your smartphone, or slightly less free with yubikey and others). Thus, even if someone did somehow get/break your master password (unlikely), they still wouldn't be able to use it for anything.
Lastpass really is quite great.
Allowing your lastpass to "trust" your machine means ANYONE with physical access to your machine has access to 100% of every password you store there.
How is that not the same as writing down passwords on a sticky note and sticking them under my keyboard?
Small distinction, but there it is.
Also, with LastPass you are just trading risks. You increase the risk of your accounts being compromised by access to your computer, but you decrease your risk of accounts being compromised because HN password database was cracked. I use LastPass because I think that trade results in less overall risk, especially because it replaced saving my passwords in Chrome's less-secure password manager.
Memorizing a few unique passwords for mission critical services while using generic throwaways for low-priority sites is more secure than LastPass can ever be.
I started this thread asking if there was a better solution that memorizing 5-10 passwords and using some variable of a throwaway for the majority of everything else, and I'm still not convinced that my method isn't the best outside of just hard memorizing a unique password for every site.
Fact is: my memorized passwords can only be compromised where they are stored on servers (or through a keylogger).
LastPass can be compromised every single way that my memorized passwords can, in addition to being compromisable on any computer you use it on, and the LastPass services stores all of your passwords offsite, all of them, adding in another huge vector for attack against your entire catalog--- in a way that my memory can never be attacked (without say, interrogation/force).
I don't know, I don't like the idea of a digital store of all of my most critical information put behind a password that doesn't even pop-up on your computer. Mine as well just store all your passwords in Chrome. Same amount of security. Actually Chrome probably does better since it won't automatically push your passwords to the cloud unless you sync...
I started this thread asking if there was a better solution that memorizing
5-10 passwords and using some variable of a throwaway for the majority of
everything else, and I'm still not convinced that my method isn't the best
outside of just hard memorizing a unique password for every site.
When I was younger, I had only 5-10 important accounts and I memorized unique passwords that I thought were strong. Now I have many more important accounts, including four brokerage accounts, several bank accounts, half a dozen credit card accounts, two domain registrar accounts associated with tens of thousands of dollars worth of domains, etc. I have a separate computer that I only use to access these important accounts, and my passwords for these accounts are stored in KeePass, which allows me to have unique passwords with 200+ bits of entropy.I prefer my current setup more than my old setup.
Highly likely to be compromised, you mean? Viruses are a thing, and you can bet malware will target LastPass in order to get to finances.
For this reason, if you lose your master password, LastPass can't unlock your passwords for you. You'll have to go to the NSA for that.
Putting HTTPS insecurity aside, we really shouldn't be implementing crypto in JavaScript.
http://www.matasano.com/articles/javascript-cryptography/
KeePass is both native and open-source, so it avoids many of the problems that LastPass presents, IMHO. Simply install the client program and sync via SparkleShare, git, Dropbox, UbuntuOne, Google Drive, etc.
Plus that article attacks JS doing crypto that the server will decrypt (which, yes is useless, use TLS). It doesn't address using browser add-ons to do AES encryption, have your data stored on the server in encrypted form, and only decrypted when you download it again.
Is this method flawed? Only if you do a web-app instead of a browser add-on. Once you package the client code, it can be just as hard to break as something like KeePass (assuming the add-on itself has a decent security policy, ie don't eval()code from random places).
Plus, modern browsers now have "window.crypto" which provides a PRNG. So there goes that argument.
The article is just completely wrong in many ways. The only valid point I see it make is about garbage collection and potential for reading decrypted memory directly (MANY languages have this problem, not just JS).
One of the points you brought up is extremely valid though: LastPass is closed-source, so it's nearly impossible to truly validate the crypto. Keepass (I also use it) is a much better option, and great when paired with some sort of sync utility.
The last person you should take security advice is from Steve Gibson. He's done an amazing job of making himself out to be a "security expert" but his understanding of security is ... exceedingly limited.
Read this post to see one example how he just, like, doesn't understand anything at all: https://www.grc.com/ssl/ev.htm
I was just thinking if my account is not publicly listed then I can just have a really complicated username and use a really simple password. (Complicated as in a SHA 2 or MD5 hash of your real name ). (Just thinking loud)
It looks more like a text based MUD based on the Myst universe.
Given a limited vocabulary to describe terrain and buildings and furniture and their physical relationships, along with a database of tagged 3d object models or procedural methods of generating such, this could be done but I'm not aware of anyone having attempted to create such a thing.
Edit: Actually, I guess Scribblenauts is the closest approximation to this that exists yet.
Nah, that would be crazy. It would never catch on.
I'm gonna play the MYST series again. Any programmer/hacker will love these series. they're a real classic brain cracker, and worth the play. You will get pulled into the myst worlds as if it are your own. it's so immerssive!
Here's the end: http://www.starshiptitanic.com/novel/lastpage.html
EDIT: typo
(this version contains most-to-all of the original release, and also contains extra content from the GameTap revival)
http://www.grantland.com/story/_/id/9713372/looking-back-gam...
Most are 'exploratory' (they can be solved by just one person who does a lot of backtracking / note taking, but are easier with two)
A few actually require two people. (I can't remember if they are still in MOULa today, or if their one-player counterparts are live).
A few are "cheat" puzzles -- they rely on the (very bad) physics engine or stupid-long wait times. (some are upwards of 20-30 minutes, some are over 24 hours). They were always bad ideas, but luckily these are few and far between.
While I'm a big fan of what they were trying to accomplish, the experience is significantly less polished when compared to Portal 2.
If you found Riven enjoyable, the puzzles are slightly easier and simpler. You'll probably have fun, either on your own or with a few friends.
Both are GPL3 licensed
Myst - (Cyan Worlds) and realMyst (same game, re-created in 3D)
Riven - (Cyan Worlds)
Myst III : Exile - (Presto Studios, of Journeyman Project fame)
Myst IV : Revelation (Ubisoft Montreal)
Myst V : End of Ages (Cyan Worlds)
realMyst - (Cyan Worlds) the realtime 3d remake of the original Myst game
There's also a 'partial spin-off' series "Uru", created by Cyan Worlds, which exists in the Myst universe, but happens in a different portion of that universe, and in present day (although this is somewhat of a misnomer, as the Myst V game also takes place in the present day, after events in Uru, and references them) Uru - Ages Beyond Myst
Uru - To D'Ni
Uru - Path of the Shell
Myst Online : Uru Live (MO:UL) is the latest incarnation of the original "Uru Live", and represents the state of the project after it's second (GameTap) cancellation, with some additional changes / bugfixes / ect.Myst V is sort of an odd-ball in the series, as it was originally meant to be content for Uru Live, but Uru was cancelled and Cyan could only get funding for another single player Myst-type game (something considered 'lower risk' than an online game).
So a lot of content was re-purposed from the Uru Live pipeline for Myst 5, and it attempts to closely bridge the two different parts of the universe and wrap them up together.