Our Org Security

Day 1,786, 20:38 Published in Ireland Ireland by Sean MacDiarmata


Hello Citizens of eIreland,

With all the current discussion and worries about the security of our Government Organisations I taught I should release an article just to advise you on the measures we are taking to make sure a theft doesn't happen again.


Old Problem
Last term we all know what happened, the passwords for the Orgs or Emails were available to the thief and from there they were able to easily access the org or just reset the password with the email address.

This was quite worrying for two reasons, no person should have access to all the passwords of either the orgs or email accounts. This is common sense tbh.

When allowing someone access to this kind of information it would be ok to give certain people access, people who you know are safe and would never look to do anything remotely dishonest. Now I know people are still thinking you don't give anyone access but the kind of people who I consider safe would be the likes of my old VP Einberlinger, Sw33t, WHS, AC, Liam and a number of others. They are people who I have known since I started and I know they would never be in this for themselves and only to help Ireland in any way they could.



Solution
When I created the eireland.me domain it was to serve two purposes, the first one I wont go into here but the second one was so we could have a very secure host were we can have all the org email accounts on. Having them on my host means that due to the security features on it they can't be hacked, I can easily reset the passwords at a Presidents request and if someone else does try to reset them I can reject it.

I have always said that when using the internet for games, emails or anything you should always use a secure password. Passwords with place names, peoples names or dates of certain things are never good because programs can easily guess them.

Examples of passwords I use on the Org email accounts,
Plg+4*c$%f9C, QfGDb-^o)6ad, ETGWw;tQm)f.

The above passwords are whats known as 128bit passwords, for most things they are known as overkill passwords. Meaning that they are so secure its unnecessary, for a program to hack them above passwords would take weeks due to a number of reasons.

The first reason being that every third failed attempt the system locks out the IP for one hour.

Second reason been that I get an email and text notification that an IP of an address not known to the ones I put on the system has attempted to access the accounts, then I log on and change the PW again. Meaning it would take months to hack the email accounts.



Uncontrollable
This is not fool proof,
With the elections always bringing in new CP's I can't do anything to stop them changing the email accounts with admin meaning the security of our nations funds is in trouble, there are so many hacks out there for hotmail, gmail etc accounts its unreal. Funds can still be taken from us if the org password is leaker, I can't control that its the CP's job but what I can control is that if our Orgs are taken over once I am made aware of it I can lock them out straight away.

Security is key to everything on the internet, this game and our Orgs should be no different.

I hope this puts at ease some of your taughts and if you have any that I can help put at rest feel free to pm me ingame or on IRC.

Thanks for reading Ireland,

Marcus Suridius
Dedicated Irish Soldier
o7