
Originally Posted by
warfrogs
DHaran, I'm more than a little confused. I too work for a bank, and as far as I know, online banking does exactly this. Generally, for online banking, you're required to provide a username, password, occasionally a PIN or a secret question, and nothing else. Through this, you can transfer funds to other customers, send out funds through bill pay, and even apply for credit cards and other lines and loans. Banks are able to prevent widespread fraud using that system and while there are of course people who do not properly use the system (due to couples sharing accounts, which is of course what we're trying to avoid) it seems plenty effective for them. Through behavior modeling, a much better system could be implemented that would intelligently block cheaters. Hell, with some regex magic, you could easily automatically organize, sort, and cleanse out the list of provinces that have shared IPs.
Here's a solution that would be pretty simple to implement. It's not perfect, but it's a start.
An account is logged in to from more than one IP in a short period of time (as in an unrealistic period of time, 5-15 minutes perhaps), or multiple accounts are activated from one IP in a short time (without being on the whitelist), then that account (or accounts) are flagged and monitored. This behavior continues, and blammo, they're put on a list in which the account cannot interact with other flagged provinces in any way. This would be devastating to farms and multis. Furthermore, this would allow the whitelist to exist for legitimate players.
As far as authentication, it's pretty freaking simple. While you cannot, and should not be expected to ID each and every person as being a legitimate player, you can have people make it obvious that they are two different people who are looking to play. It's all very simple really, people tend to have long and relatively common cyber footprints. For example, my handle "warfrogs." I've used it for quite a while. For example, (reddit.com/user/warfrogs) there is my reddit profile (can't post a link due to account age) and (reddit.com/r/Utopiagame/comments/n3bb4/proof_of_self/) there is my post establishing my identity.
Most, not all, people have long standing cyber presences that can be tied to ONE person and can be authenticated via a message like mine. Why wouldn't this be sufficient to get put onto a whitelist? Most cheaters would not be willing to create a profile, a bunch of fake friends, comments, etc. in order to multi, they'd probably just VPN. True, there would still be abuse, but it would cut down on your legwork quite a lot, allow the whitelist to continue as it truly is needed in the game, and would cut down on cheaters.
I'd love to get a real response on this, I've yet to see a good one which is more than a little disheartening. I feel like I might as well be using the White House petition site to ask about marijuana legalization. The only answer is no answer at all.