NextToNothing / McX

http://www.nexttonothing.me/
1 stars 0 forks source link

[Enhancement] In-game Password Recovery #3

Open clucky opened 12 years ago

clucky commented 12 years ago

I would like to find a way to recover your password for the forum in-game. The reason why is because I am wanting to disable the email requirement for my forum to more easily comply with COPPA, doing this would also make more players feel comfortable registering, being it would only require a username and password. However, when removing the email requirement, you are also removing the ability for players to recover their account. I figure, players would keep their minecraft account the most secure being they use it for ALL servers, so there would be no harm in allowing them to recover their password in-game. This would of course be configurable, so that offline servers would not have a problem with hackers stealing forum accounts. I do not know if this is possible or not, however, either way, reply back, if it is possible, I will be very interested in taking this idea further, possibly into another plugin if you decline. Thank you very much for your consideration.

NextToNothing commented 12 years ago

I suppose it's a possible improvement. However there is possibility, some of which you've stated, that people's minecraft accounts may get hacked, or used by their friends(shared accounts), or used when the server is in offline mode which will all cause security issues for the server's users. Although this is a possibility it's not most necessary or sought after requirement. Also, when you register your Minecraft account you have to provide an email address anyway to confirm your account. People are more likely to keep their email addresses more confidential and secure than they are their Minecraft accounts. They should have an email address to use when they register on your forums because they have already entered one for their Minecraft account creation, and confirmed it.

clucky commented 12 years ago

The issue I am having is that COPPA requires all users under the age of 13 to have a parent/guardian's written consent before giving out any personal information (age, name, phone number, even email address). I am just wanting to remove the email requirement for my forum (can be done by altering the PHP on a mybb forum), and make users authenticate their account using their Minecraft account. If you want to include an acitvation to promote a user from not registered to registered, you can, however, I could easily do this myself manually. If you do not feel up to this task, I will just simply make users under 13 be required to have their parent call me, simple enough.