
Originally Posted by
Droppy
For sure! Even the login mail should be an costumised one (abcdef@fakedomain.net), because for the user find the login's email is also hard, if you think, this is a company, for god's sake! Sometimes, they don't act like one, like the greatest mute, it is a social game, not a mute game. The fault is from the staff (considering IF they choose the passwords/email), but they think its just a game.
For safety, I would give for staffs (if I was sulake):
- Custom mails (better if fake, so it would be harder to find);
- PIN code, or a second password inside the client, or simply you sms sulake everytime you want a new pin, which expires each 12 hours;
- Housekeeping is already unaccessfull, but... Extends security is always good. If they got to first base, they also can get to the second.
One thing I wish to try a bit more (I maded an private server of Pocket Habbo someday, so I know I'm talking about) if I had my some cellphone again (yes, this is one of my theories, don't suppose to work, but hell, someone could try haha)
This is for PocketHabbo + [iOS / Android]
- Download fiddler2 and config to my iphone's proxy;
- Grab the packets from login;
- There's a kind of rewrite-rule on it, via if data contains, or if url contains, w.e, if we make by the url requested which is pretty much the request to localhost...;
- Create an personal SSL certificate on IIS or Apache for habbo;
- Modify responses for Staff's username, and data, so you must be able to login on it (the smartphone would think you entered the informations correctly, so it would give you the account informations)
Let me know if somebody does something about that.