myforsans |

11 Meses atrás

In order to limit (let's not dream) the creation of "bogus" clubs to take advantage of the benefits granted to level 1 clubs, in particular through dubious transfers, I propose the introduction of a double authentication system (sending an SMS, for example) to :

  • create a new club
    but also
  • put a player on the transfer list
  • buy a player from the transfer list
  • possibly also to carry out certain operations such as launching a build or loaning a player

Even if some clever people use a 'friendly' phone number to create a bogus club, they'll no doubt find it difficult to keep the club going in the long term and even in the short term, as I think the admins could have a database that would allow them to see the phone number associated with the club and identify duplicates.

I'm curious to know if there are any technical obstacles to setting this up. In any case, my bank knows how to do it, my tax office knows how to do it, almost all the service providers I use with a login know how to do it, etc...


Esta mensagem foi traduzida. (FR) Mensagem original

Magpie |

11 Meses atrás

Unfortunately, I think this goes completely against the direction the game seems to have taken.
I get the feeling that a lot of changes have been made to appeal to an 'easier' audience.
You see, the manager who downloads the game, tries it out very quickly, is quickly helped (dynamically) with aids, doped-up mentoring and so on.
And then, they don't have to think too hard (training sessions simplified to the max, simple tactics), and they don't need to be on the game a lot (logging on once in the morning on the metro, and once in the evening during a break).
So if I've got my facts right, I think that setting up this verification system makes it much more difficult to catch consumers. And so I think it goes against the current policy (I'm afraid it's "more managers = better business for the Store", which is understandable, and can be defended, to be honest).

That said, you're absolutely right to point out a real concern about security in the game. By that I mean the fight against cheating.
But when A45 says in full audio that "we can now detect multiplayers very easily", I think we've all understood where we stand.... :/


Esta mensagem foi traduzida. (FR) Mensagem original

minadinho |

11 Meses atrás

When he sees that the admins are all going to give up their jobs, he'll back down.
Otherwise he'll have to get used to the idea that cheating is part of the game.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Double authentication when creating an account once and for all by registering a telephone number and then having to validate the code received by SMS only when making a transfer makes life infinitesimally more complex for the 'normal' player but enormously more complex for the 'cheating' player.
So as far as I'm concerned, there's no point in debating whether or not to introduce such a system.
..unless the aim is to make people believe that there are dozens of new players every day (at the risk that 90% of these new players are multi-accounts).


Esta mensagem foi traduzida. (FR) Mensagem original

Magpie |

11 Meses atrás

Hmmm no, I don't agree. Now, I'm not necessarily right.
But if a new player is tempted by the game, if they're asked for their phone number the first time they use it, I think most of them won't get past that stage. Because you wonder "why?" or "what are they going to do with it? You know, people are suspicious. Personally, I put myself in their shoes. If I was new and didn't know VF at all, I'd be reluctant to pass on data. You never know where it's kept, what it's used for, how secure it is and so on.
Admittedly, this information is probably already stored on the download platform (PlayStore, AppleStore, etc.) but that's considered secure. Now you're going to a game you know nothing about...
I really think you're just losing people. Your targets as an MDJ...

Then, are there any newcomers arriving? Of course, and I hope they do ! Otherwise the game is lost ! But I'm not fooled either. By dint of seeing cheating, I've reached the point where I look at each new account with suspicion. If I communicate with them, I always wonder which banished person I'm talking to, or which VF 'celebrity' I'm talking to... But that's abnormal, I agree. Nevertheless, I'm convinced that there are some real new players. The problem is that they don't stay. And that's A45's big problem, which he seemed to want to alleviate a while ago (setting up support, mentoring). Even the handbook I wrote was more or less oriented in this direction, and above all, was part of this policy (getting newcomers hooked).
Now, without more information, I don't have any data on the veracity of my feelings about the 'real manager / multis' gauge. I totally agree with you that measurements are needed. And I'd even add that uncontrolled cheating is the cancer of a game. It's vital to curb it as much as possible. I'm simply saying that your method, however interesting it may be, and however effective it may be in the fight against cheating, may have undesirable effects elsewhere.
Now, I'm not a prophet, I'm just stating the problem in your idea, which is very interesting by the way


Esta mensagem foi traduzida. (FR) Mensagem original
Magpie Hmmm non, je ne suis pas d'accord. Après, je n'ai pas forcément raison. Mais si un nouveau joueur se laisse tenter par le jeu, si, dès la 1ere utilisation, on …

Pierabou |

11 Meses atrás

Personally, now that I know about VF, I'm even less inclined to give my personal phone number.
If the game is pirated or something, you don't know who's going to end up with it.


Esta mensagem foi traduzida. (FR) Mensagem original

MrHoman |

11 Meses atrás

Rather than sending a code by sms for each action, a multi-account player often has to log out, so the code for each connection seems better. I do agree, however, that double authentication is needed.


Esta mensagem foi traduzida. (FR) Mensagem original

Ced90 |

11 Meses atrás

Perhaps we could have a clear and honest communication from Aymeric on this subject?
Because he really did say in his voice that it was now very easy to detect multiple accounts...

But when you dig a bit, you quickly realise that there are a lot of them (plus those with wives, cats and so on...).

I think the majority of the community is very worried about what's planned for next season!


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Personally, I wouldn't mind every time you log in, but you're going to get a lot of moaners whining that it's too much.
I think that at creation to register the phone and then only occasionally to validate 2 or 3 sensitive operations such as transfers (not auctions), choosing a sponsor, launching a build, would be enough for now and would reduce fraud considerably and simplify the work of the admins by also considerably limiting the time of an investigation for multiple accounts.


Esta mensagem foi traduzida. (FR) Mensagem original

dudziak |

11 Meses atrás

The simplest solution is to stop all aid at level 1, as is the case now, and that would solve a lot of problems.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Well, if I tell you (or VF) that my phone number is 06 11 71 45 64 what difference does it make to me?
What exactly am I risking? Canvassing?


Esta mensagem foi traduzida. (FR) Mensagem original

Magpie |

11 Meses atrás

For example, or smishing.
And even so, it's a feeling, whether you deny it or not.
If you don't, well done 👍


Esta mensagem foi traduzida. (FR) Mensagem original
Magpie Par exemple, ou du smishing. Et quand bien même, c'est un ressenti, que tu le nies ou pas. Si toi tu ne l'as pas, bravo 👍

myforsans |

11 Meses atrás

No I haven't, I must not be paranoid enough


Esta mensagem foi traduzida. (FR) Mensagem original
2 more replies
myforsans Non je ne l'ai pas, je ne dois pas être assez paranoiaque

Magpie |

11 Meses atrás

This is crazy. Can't you really open up your spectrum of vision a little?
Can't we think outside your vision?

Tell me, is that your real number? If not, use the real one to see if it's really safe. I dare you.
Secondly, it's amazing what we can do with AI these days.
If you put your CV on the internet (linkedin, keljob, etc) with your number in an image (of your CV), in 1 hour I'll publish your name, surname, address, probably a photo, your career path, etc.
Just from a number.
This is just an example. But do it if you don't care.


Esta mensagem foi traduzida. (FR) Mensagem original
Magpie C'est dingue ça. Tu ne peux vraiment pas ouvrir ton spectre de vision un peu ? On ne peut pas penser autrement que ta vision ? Dis-moi, c'est ton vrai numero ?…

kiki-sainté |

11 Meses atrás

Mine is 3 pages long, so don't bother with it if I put it in its entirety, you'll spend all afternoon on it 😁😁😁
For the subject, personally the system to receive an SMS to validate a transfer is without me
We'd still make money doing this, but this is basically a GAME for fun.
Too much constraint kills the constraint
Yes, it's a constraint to validate the same thing 2 times.
For the bank for example it's normal it's real money but for a game a bit of seriousness
Any game I've played in the past has and always will have loopholes for cheating.
I don't find any interest, especially in a football management game, in cheating. I'm repeating myself, but we're on a game here, we're trying to be the best trainer, the best in the game, etc., so why cheat I don't understand.
As for the project, I'm against it, if there's going to be a fight against cheats, it's not up to others to be penalised.
Good day (to each his own, that's mine)


Esta mensagem foi traduzida. (FR) Mensagem original

Sun's |

11 Meses atrás

Against
Not everyone has a telephone number (I don't have one myself)
Or an alternative to SMS verification


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

Emails are already stored. An OAuth linked to emails when an account is created would limit things a bit, because at least email creation is limited.


Esta mensagem foi traduzida. (FR) Mensagem original

Le croc |

11 Meses atrás

Many of us avoid talking to some of you, it's not to give you our 06!


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

Apart from this double authentication when creating an account, it will simplify life for admins and give them access to a panel of logs in terminal format that logs the IP of each connection, which will make life a little easier for the IP addresses.


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

Or mm crazier a script or bot that scrapes accounts with the same IP or devices or further added a few suspicious parameters to identify duplicates and automatically alerts the admins for manual verification.


Esta mensagem foi traduzida. (FR) Mensagem original

Azby |

11 Meses atrás

You don't need a script or bot to scrape because you have server-side logs with this information.

OAuth is just a protocol for connecting with another account, like "connecting with google", it's not this protocol in itself that will restrict accounts.

I don't think there are any solutions that are at once simple, not costly in terms of time/money or RGPD-friendly for this subject, or even that our opinion will matter.


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

Of course you have the logs, but do the admins have access to them?


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

When an account is linked to Google or other platforms, this would limit the number of users, bearing in mind that you can change your email address once you've signed up.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Even if you can have several phones (personal + business), not to mention your spouse's, your children's, your neighbour's etc... It's still less comfortable for a cheat to manage his multiple accounts than with his ten or fifteen email addresses that he can create for himself at any time in a matter of seconds.

PS: I get PMs from people telling me that those who are against double authentication are doing so because they have multiple accounts :) :) :)
Personally I don't think that's why, but there's just a bit too much paranoia on their part because they should be thinking about the countless people they've already given their number to without even thinking about the illusory consequences they're claiming.


Esta mensagem foi traduzida. (FR) Mensagem original

Pierabou |

11 Meses atrás

You're right, we probably give out too much of our phone number for free to too many strangers. And then we complain about the incessant canvassing by operators of all kinds...
So maybe I should start being a bit more paranoid.
One thing's for sure, on VF it's not paranoia, there's enough history on this game not to come and put your phone number on it. Maybe account hacking doesn't mean anything to you since you're new to the game? Do you trust all the VF members?
Not me, call me paranoid if you want, personally I call it experience. 10 years ago I'd probably have put it in without a worry, not today.


Esta mensagem foi traduzida. (FR) Mensagem original

Magpie |

11 Meses atrás

That's your point of view.
On the other hand, you might think that people who are prepared to give out their number everywhere, without knowing where they put it (as in the case of a newcomer who doesn't know the game) are being stupidly careless.
Personally, I don't think that's it, but there's simply too much recklessness on their part, because they should think about the countless people who have suffered major mishaps as a result (phishing, smishing, identity theft, etc). Having investigated a case on this (a long time ago, I admit), it often starts from nothing and can go a long way.
So you can limit the amount of information that's released to protect yourself. In any case, it has to remain a choice. But for those who don't care, frankly, knock yourself out ;)


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Oh dear, I've just left my phone number with the secretary at the garage where I've left my car for servicing so that she can call me when it's ready. .... I shouldn't have done that, I'm already freaking out!


Esta mensagem foi traduzida. (FR) Mensagem original

Pierabou |

11 Meses atrás

I don't understand your attitude.
I'll explain why I don't agree. Even if I were paranoid, it's still my right to be.

In any case, I wouldn't wish you to go through what Nicu went through, because even if it didn't ruin his life, the piracy episodes really annoyed him. God only knows how far some people will go.
Yes, and for the record, what that little joker did to Nicu back in the day, and what he's been doing lately with the "nicularo la pédale" accounts, may not affect you, but it's called harassment. It doesn't matter, we don't care.
What's the limit for these guys? Do you know what it is?


Esta mensagem foi traduzida. (FR) Mensagem original

Marcus Aurelius |

11 Meses atrás

Myforsans, evolve a little; as soon as someone disagrees with you, you either imply something or take the piss out of them. It won't help your argument, quite the opposite.

The initial idea isn't bad, although I'd limit it to creating an account. But the security on this game is literally shoddy.

Can you understand why people don't want to leave private data for a game that can't protect itself? Unless they're cheaters, idiots and/or conspiracy theorists?
Personally, I trust my mechanic's secretary more than VF to keep my phone safe.

On the other hand, good news: I've just found out that you're eligible for the renovation bonus to help you change your woodwork. You'll have to pay in advance, of course.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

The game is certainly more protected than you think.
Just because there have been two or 3 occasional intrusions (to cheat and not to retrieve contact details), which were ultimately of no consequence, doesn't mean that the game isn't protected. It is, and to a greater extent than you think, otherwise there would have been more attacks.

But above all, recent history shows that cyber-attacks affect all sites, even the most reputed for their security (Public Assistance, NATO, Amazon, etc.). So yes, VF is one of the 3 or 10 million potential targets for a hacker, but given the extremely limited interest for a hacker in knowing the telephones of VF members, I doubt that the VF database would be a priority target for him.

NB: Apart from that, when it comes to saying: Myforsans, you need to evolve a bit; as soon as someone disagrees with you you either imply something or you make fun of them.
I know that the best defence is a good offence, but coming from you and given your reputation, wouldn't that be a bit (a lot) like the pot calling the kettle black? :) :) :)


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

11 Meses atrás

As far as creating an account is concerned, I can see the point, and I quite agree.

For transfers, no. It has to be flexible enough. I can't imagine how cumbersome it would be for someone who buys and sells.


Esta mensagem foi traduzida. (FR) Mensagem original

brewen |

11 Meses atrás

The initial concern with this subject is a misunderstanding between two terms, which does not make the form any easier:

  • Double authentication, the aim of which is to SECURE the user's account from potential hackers who might try to connect to it (hence its presence in banks, health services, suppliers, which contain PRIVATE information such as bank details, addresses, etc.). The idea is simply to trap the hacker a little more if he finds the CDM for the account.

  • Digital identity, which is very present in some countries such as China, the aim of which is to control each individual's account, in order to track everything they do (particularly on social networks and individual behaviour). This is also one of the objectives of 'France Identité', where your identity card can be used at any time to connect you to various services (mainly government services, at least at the moment).

What you're proposing here is a digital identity system, to detect multiple accounts, rather than double authentication to provide the best possible security for your personal data that a hacker could find when accessing your account.

Now to the substance:

  • The idea is not particularly bad, but it will solve any concerns about multi-accounts in the legal and juridical aspects currently available?
  • Is it possible and feasible for the MDJ to create such a system?
  • The introduction of ultra-sensitive data (telephone numbers and more) inevitably means that all this has to be made secure. And when you see all the data leaks all over the place on ONLINE sites (and your example of the garage is totally out of context), and the consequences for the user (phone spam, mailbox spam, even harassment and suicide...) following the resale of your data by hackers on canvassing markets, it doesn't look particularly appealing. What's worse, when you consider the mentality and tensions in certain discussions, and the current world where harassment is rife, I don't particularly want someone to be able to access my information (normally, this information is private, so no-one should have access to it except an approved admin and the MDJ), which could allow them to identify me and cause harm IRL. And above all, for the MDJ, it's an investment to secure this system, because in the event of a data leak and subsequent complaints, he'd be risking a lot with the CNIL.

To sum up, what you're asking for is a digital identity rather than dual authentication, it exists, it's possible to put in place, but is it proportionate and appropriate to the situation to take such a measure? Everyone will have their own opinion, but I don't think there's really any firm answer possible at the moment. (This issue has been the subject of debate in France and the EU for several months now, particularly with a view to better identifying the accounts of people who harass or defraud online sites, especially social networks).


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

11 Meses atrás

I don't see where the proposal differs from double authentication: i.e. entering your password and, for example, a password received by SMS.


Esta mensagem foi traduzida. (FR) Mensagem original
Galywat Je vois pas où la proposition diffère d'une double authentification : à savoir renseigner ton mot de passe, et par exemple un mot de passe reçu par SMS. On dem…

brewen |

11 Meses atrás

The difference is that this is not the objective of this technique. The aim of double authentication is to strengthen the security of your account, to make it more difficult to log in from outside your account (by adding intermediate steps requiring verification by another means of connection such as a telephone or email address, which the hacker should not have access to in theory).
It inevitably makes creating a multi slightly more complex, because 1 account = 1 email address = 1 telephone number, but it doesn't prevent someone who really wants to cheat from doing so (it's a bit like basing a multi on an IP now, with all the talk about mobile connections and VPNs).

A system has recently been introduced to ensure that a person = a unique account, and it's called digital identity. It's a tool that's being debated, but it's a fact.


Esta mensagem foi traduzida. (FR) Mensagem original

Marcus Aurelius |

11 Meses atrás

VF is a mill. What saves it is that it is known by only 3 peeled and one shorn, that's all.

NB : No.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Yes, Brewen, very well explained.
There's no need, however, in my proposal to move towards digital identification.
Simply
With double authentication,

  1. In principle, no more hacking (so that will reassure our friends who spoke earlier)
  2. And on the other hand: not more multi-accounts but much less comfort in managing them.

As for the supposed inconvenience for those who buy and sell, I don't think they do 100 a day and validating a 6-digit code received by SMS should take around 5 to 10 seconds :)


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

11 Meses atrás

It's still a fairly 'heavy' process. It's more than enough if it's requested from time to time, it doesn't have to be for every action in the game.


Esta mensagem foi traduzida. (FR) Mensagem original

brewen |

11 Meses atrás

So, yes and no.

In theory, you can no longer have your account hacked (for example, no-one can log into your France Travail account). On the other hand, a hacker can very well hack into the France Travail database (which happens every 6 months lately), and retrieve the table containing your profile and your private information, without having hacked into your account. And this is the point that both Magpie and Marcus mention.

Double authentication is now done by digital or facial recognition (especially eye recognition) rather than a code, which I think is even more secure in practice, and quicker and more environmentally friendly than a code received by email. (So much for the ecology of sending 10k login emails or text messages a day with a code...)


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

11 Meses atrás

OK, but that doesn't change the fact that this is dual authentication, not a digital identity. Even if it's not exactly for the security of our own accounts.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

With double authentication, the creator of this club would have had more difficulty doing it.
Deleted club
(even if he could have done it with his neighbour's phone).

Apart from that, everyone is entitled to their own opinion without insulting the other, aren't they? I didn't say that your position was ridiculous, but to say that people who don't want to give their phone number are a bit paranoid, I don't think that's insulting.


Esta mensagem foi traduzida. (FR) Mensagem original

bluethunders26 |

11 Meses atrás

account already blocked


Esta mensagem foi traduzida. (FR) Mensagem original

Pierabou |

11 Meses atrás

I may be taking some things too badly too quickly but :

  • those who are against have multis, (therefore cheaters)
  • are paranoid (maybe not insulting but degrading)
  • you're making a mockery of my reply with your garage story (so you're trying to make a mockery of me)
    and yes, your response (not yours) was ridiculous because it was unconstructive, invective and in no way addressed the piracy issue raised.

To return to the subject:
Double authentication would probably make the multi more restrictive, but given the strategies organised to put them in place, I doubt it would prevent them from doing so to any extent. Technically and organisationally the solution also seems very complicated to put in place and the collateral effects seem to me to be more important than the result obtained.
Basically, I understand the approach and support it, but as far as the solution itself is concerned, I don't think it works. The risk/cost/benefit balance unfortunately seems very unbalanced.


Esta mensagem foi traduzida. (FR) Mensagem original

Nicularo |

11 Meses atrás

I'm sorry I thwarted your plans, Lomax. You can take all the pseudonyms you want and continue your 2-bit attacks; it doesn't affect me at all. On the contrary, I'm very happy to see and know that I've really given you a hard time about your plans to explore rifts 🙂 You can always come back to the game.
You can always come back to the game, it's easy to sign up, even if security is getting a bit tougher. And when you've found another scam, we'll flush it out, block all your accounts and you'll have to start again... With, I hope, another personal insult, I'll be flattered!


Esta mensagem foi traduzida. (FR) Mensagem original

Pierabou |

11 Meses atrás

For your information, I've just done a test.
I created this club: Deleted club
(admins, if you could please delete it).

I was able to create it between its 2 messages, 15 seconds. I used an email address that doesn't exist.
Maybe that's the first thing to do if you want to start making things more complex.


Esta mensagem foi traduzida. (FR) Mensagem original

Marcus Aurelius |

11 Meses atrás

If it works, you'll be able to create it with a phone number that doesn't exist.


Esta mensagem foi traduzida. (FR) Mensagem original

bluethunders26 |

11 Meses atrás

blocks


Esta mensagem foi traduzida. (FR) Mensagem original
2 more replies

maxence97300 |

11 Meses atrás

Oh yeah, you don't even need a valid email and you wonder how the guys manage to get 50 clubs ...
You'd have to start with that, valid email that needs to be checked to validate the creation of an account...


Esta mensagem foi traduzida. (FR) Mensagem original

Jallow |

11 Meses atrás

As I mentioned above, we have the free right to put in a bogus email that has never existed and have quintuple multi without worrying.


Esta mensagem foi traduzida. (FR) Mensagem original

Socrate |

11 Meses atrás

I suspected that you were at least aware of that, to go so far in your proposals ...
Before looking for solutions to a problem, you need to know where it starts. And here it starts at the very basis that a series of letters or numbers where you include @ and .com or .fr is enough to start the VF adventure ...


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

Except that creating a real 2nd, 3rd xth mailbox is still more simp'e than taking out a second, third xth telephone subscription to validate the link to validate your registration.


Esta mensagem foi traduzida. (FR) Mensagem original

Demi-cerveau |

11 Meses atrás

Hello.

Personally, ever since some clever chap wrote to me when I was administrator and said "we know who you are First Name Last Name", without any mistake of course, I've not been keen on leaving my real details on VF.

I wasn't paranoid enough. But since then it's been dedicated mail, and crazy information, because it's not very nice to receive that kind of message.


Esta mensagem foi traduzida. (FR) Mensagem original

Marcus Aurelius |

11 Meses atrás

Contrary to what our Canadian comrade claims, security and data protection on VF are in a sorry state.


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

11 Meses atrás

I've had the same experience. Well, the address was several hundred kilometres off ^^`.


Esta mensagem foi traduzida. (FR) Mensagem original

Nicularo |

11 Meses atrás

I didn't get this type of threat because I'd already created a specific gmail address for Virtuafoot, and entered a fictitious first and last name.
But yes, if someone cracks your password, they can access this type of data. And as long as the VF password is identical to that of the email address that belongs to you... I'll leave you to imagine the consequences...


Esta mensagem foi traduzida. (FR) Mensagem original

Blagoje Vidinic |

11 Meses atrás

Personally, I'm always reluctant to give my phone over the net and I immediately leave sites that ask for it when I register.
I like VF and I know it, so I might make the effort, but if I were a newcomer, I wouldn't go through with registration, that's for sure.


Esta mensagem foi traduzida. (FR) Mensagem original

Misha |

11 Meses atrás

I think it's great that after 2 days of discussions, nobody has realised that an automatic SMS system costs an arm and a leg. And there are no limits: I read that we should have two-factor authentication for EVERY connection! Oléééé 😆

I'll give you a quote (because my company sells 2FA or PCI-DSS-compliant SSO), it's 500 francs per month + €0.01 per connection + €0.08 per SMS. Imagine 1,000 players logging on 5 times a day. That's €3,000 a month. And if you want us to integrate it into your app or website, add another 30,000. I hope the Vfstore finally takes off! :D

No kidding, VF isn't Microsoft or Tinder. You really have to think small. It's commendable that you want to have your identity confirmed, but unfortunately the most you can do is send a confirmation e-mail.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

11 Meses atrás

The art and manner of making figures say what you want them to say.
You'd think you were at the National Assembly!
1°) There are much cheaper SMS APIs than the one you're selling!
2°) Why calculate the cost of authentication for each connection?
That's not what's being proposed at all.
What's being proposed is authentication when the account is created and authentication from time to time for certain live transfers (not auctions, obviously).
Of course, it would be completely inappropriate to ask for authentication if you log in to change players during a match!
So security doesn't come into play when you log on, but when you want to validate an operation deemed sensitive by the organiser (e.g. a transfer).
But it's true that it's better to let anyone spoil the game at any time.


Esta mensagem foi traduzida. (FR) Mensagem original

estac |

11 Meses atrás

Sensitive operation on a free game with virtual money.

I know that everyone has their own definition of the word sensitive, but in this case I think it's slightly exaggerated.


Esta mensagem foi traduzida. (FR) Mensagem original

Azby |

11 Meses atrás

If you're looking for a laugh, RECORD_AUDIO and READ_EXTERNAL_STORAGE have been added to the Android app's permissions manifest, as has access to your location ('at a glance' and 'fine' versions).

Deactivated by default on your mobile since Android version 6, rest assured.

There are also trackers, which are very common these days: Facebook Analytics, Facebook Login, Facebook Places, Facebook Share, Google Analytics, Google CrashLytics, Google Firebase Analytics, Google Tag Manager.

It's still peanuts compared to horrible apps like Pokemon Go, but it's there.

Of course, MDJ hasn't set this up to listen in on your toilet break and pinpoint your toilet on Google Maps. But these forgotten permissions are all possible vectors for a gifted and malicious individual/group.

(Yes, I'm team paranoid)


Esta mensagem foi traduzida. (FR) Mensagem original

Radio |

11 Meses atrás

Hello commu,

I've been closely following the debates around making VF more secure, and I think the first thing to note and praise is the determination that each and every one of us is expressing to combat cheating in the game in general. Beyond the differences on the method to adopt, the capacities and means available, and even ego squabbles, I believe we are all dismayed and determined to tackle the problem head on. Let's not forget what unites us, and let's not let this burning issue divide and weaken us.

I'm what the commu calls a 'real new manager': I discovered VF between 10 and 15 years ago (gasp) and played it for a few months from memory. I loved it, but life took me away from the game. I came back recently to get involved and, naturally, to play according to my convictions: honesty, investment, merit. So it's sad to (re)discover a VF plagued by scheming and trolling, admins who are brave but have to gnaw their cuticles, distraught managers looking for answers from Aymeric, and an overall cacophony that ultimately serves the interests of the game and strengthens the cavalry of a few discord-bearing gargoyles who thrive on this chaos.

Getting back to the point, I understand that some online betting sites (poker for example) can detect the presence of multiple accounts via the means of settlement used during transactions (cash-ins, cash-outs in particular). This enables them to intervene to ensure that a multi-account player does not end up with 7 different accounts at the same table as another player and deplores him in good standing. What do we know about the verification methods used by VF in this respect?


Esta mensagem foi traduzida. (FR) Mensagem original

junior |

11 Meses atrás

Could you identify yourself with franceconnect? Ok I'm out


Esta mensagem foi traduzida. (FR) Mensagem original

Misterheho |

10 Meses atrás

Good evening, if someone is playing with one or more false telephone numbers (there are sites that offer this service free of charge for receiving and sending e-mails), what should you do in this case?...


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

7 Meses atrás

I'm taking the liberty of raising the subject again when I see the proliferation of multi-accounts :

  • to make dubious transfers
  • to create ephemeral accounts to hurl insults at the forum or make threats
  • to create ephemeral multi-accounts to spill insults or threats on the mini-chat

It's certain that a future (real) new player logging in for the first time will be very keen to sign up to the game if they come across this when they first log in!

All those who supposedly fear for their privacy should open their eyes, they remind me of those who are against CCTV cameras in their local authority but deplore the increase in crime.

Asking for double authentication when creating an account (+ possibly when validating a transfer other than at auction) doesn't seem extravagant to me in terms of constraints and the supposed invasion of privacy, especially when it's the same grumpy people who don't hesitate to do it to make any online purchase.

These proliferating multi-accounts (no pun intended) are going to end up killing the game (and that's the aim of this or these 'creators').


Esta mensagem foi traduzida. (FR) Mensagem original

junior |

7 Meses atrás

Why not authorize the Multi account ....the game is already rotten by interior, then with the free transfers, one does not care any more....the people eat aloe that it cried with scandal


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

7 Meses atrás

In itself it is not authorised, but absolutely everything is done to facilitate and encourage it. You really have to be bad to be taken for a multi-count these days.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

7 Meses atrás

In fact, double authentication would work in the opposite direction and would be a huge deterrent to managing multiple accounts, even if some people have a personal phone and a business phone.
As I said, it's not an unstoppable trick against multiple accounts, but it will limit the risks and it will be unstoppable in preventing the chain of accounts being created, as is currently the case, by the lizards who pollute the mini chat.


Esta mensagem foi traduzida. (FR) Mensagem original

Galywat |

7 Meses atrás

In itself, I wouldn't say no to creating an account, but everything else seems too much for a game like VF.


Esta mensagem foi traduzida. (FR) Mensagem original

myforsans |

7 Meses atrás

If it's limited to account creation, it's a bit too light and too easy to circumvent.
That's why it also needs to be introduced very occasionally in the operation of accounts (particularly for sensitive 'transactions', which is why I was thinking of direct transfers outside auctions).

It would still be a real penalty, even for hardcore buyers/sellers, because this kind of double authentication should take 10 seconds, which isn't very long in the life of a VF player !!!!!

And it's worth the effort if it's going to eradicate 98% of multi-accounts.


Esta mensagem foi traduzida. (FR) Mensagem original
myforsans Si cela se limite à la création du compte c'est un peu trop light et trop facile à contourner. C'est pourquoi il faut aussi l'instaurer très ponctuellement dan…

Galywat |

7 Meses atrás

It's a convenience/utility ratio that's not necessarily good if it's required for too many aspects of the game, in my opinion anyway. Just for creating an account, and at the very least at a fixed frequency (monthly, for example), that seems to me to be more than enough.

For someone who does a lot of buying and reselling, it can quickly become burdensome. Dramatic or penalising no, but annoying yes. You already have a large initial filter with just periodic authentication and account creation.

Anyone who already passes these stages will have no qualms or difficulty in passing the transfer stage.


Esta mensagem foi traduzida. (FR) Mensagem original