Gold Card Announcement

???

Only thing they ever wanted from me was a copy of my passport or driver licence.

That doesn´t hold that much personal data, you claim they want to know.

I worked with government on quite a few projects mainly the attorney general software systems and that scan bar on back of your drivers license and that scan bar on your passport hold way more info then you know. even a scan of the front of my state drivers license can revealed a lot of info not shown on the print of the license, there is scanable info all over the front of a driver license where I live.
 
That will not help if hacker successful sent you a unnoticed trojan, which captures and reports your login and password to the hacker.

Thats why I want to have 2FA security!

I'll be ok.

I always am.
 
I worked with government on quite a few projects mainly the attorney general software systems and that scan bar on back of your drivers license and that scan bar on your passport hold way more info then you know.

Here is the standard of it:
https://www.aamva.org/dl-id-card-design-standard/

Most of it appears to be things like address and physical description, according to standards. In EU, "Race/ethnicity" is considered one of the sensitive information. (I guess the US definition is more or less the color on the photograph.) If your drivers license issuer has put more info on it, I would suggest complaining to your local politician about it. Having "race" or "ethniticy" in barcode, or the text "sexual predator" [Florida] on the front *can* be sensititive in some juristictions. And while Veteran probably is a good status thing in USA, I guess in countries like Sweden it can be sensitive if it shows that you are likely to be in a military reserve (´hemvärnet´).

The 1D bar code seems to contain either some reference to social security number, or license or ID number, date of birth, expiration and a two-digit manufacturing number.

I guess if you really want you could block out the barcode(s) and see if MA still accepts it.

In Sweden on back of driving licenses there is a barcode that contains the social security number. One example when it's used is when you clam a snailmail package. It's used as a lazy way for computer systems to note "I've seen your ID".

Modern ID cards either has a visible chip (eg gold plated) or an RFID Circuit. The chip can contain a digital ID (used to, for instance, "sign" your tax form), and the RFID is on passports and "national ID cards" (instead of passports when travelling within EU); it contains biometric data. Kind of sensitive, but logically doesn't come on a photo copy.

Doesn't some services in USA make a photocopy of the drivers license, like hotels?
 
Last edited:
Modern ID cards either has a visible chip (eg gold plated) or an RFID Circuit. The chip can contain a digital ID (used to, for instance, "sign" your tax form), and the RFID is on passports and "national ID cards" (instead of passports when travelling within EU); it contains biometric data. Kind of sensitive, but logically doesn't come on a photo copy.

Well, if I scan my passport and sent the copy as a .jpg file, who on earth can read out the chips from that ?
 

No one sees Gold, but Gold sees everything.
 
Didn't see this thread when it first came out but.... I know you can use programs like WinAuth to do the 2FA that entropiapocket does....
 
Slightly different method of authentication but.... it still is open to similar attacks... but not the same method as outlined in that article.
 
I would like to ask, because I don't know. Of the below methods of logging into one's bank account which is most secure.

A) login and then code sent to cell phone (sms)
B) login and then code sent to landline phone.
C) login using screen wipe
D) login using old gold card type auth.
E) any other

Honest question and more directed at bank accounts then my EU account.
 
I would like to ask, because I don't know. Of the below methods of logging into one's bank account which is most secure.

A) login and then code sent to cell phone (sms)
B) login and then code sent to landline phone.
C) login using screen wipe
D) login using old gold card type auth.
E) any other

Honest question and more directed at bank accounts then my EU account.

D)

If you are physically near my gold card and I am, and I dont know you. Then that number will reduce.
 
I would like to ask, because I don't know. Of the below methods of logging into one's bank account which is most secure.

A) login and then code sent to cell phone (sms)
B) login and then code sent to landline phone.
C) login using screen wipe
D) login using old gold card type auth.
E) any other

Honest question and more directed at bank accounts then my EU account.


A) flaky as fk and open to exploits
B) As above
C) semi secure
D) semi secure
E) the "New" 2FA MA uses is used by a lot of companies now days and is also only semi secure

Problem with security is people are involved... and when people are involved Security is jeopardized.
 
D)

If you are physically near my gold card and I am, and I dont know you. Then that number will reduce.

you don't need to have the gold card at all...
 
Ironically, where my big money is, they need to look like >me< and know what my signature looks like.



Oldskool baby. :yup:
 
ty for the replies. Updating my stuff and might as well try to take care of everything in one swoop.

Young enough to catch the beginning of the new age but old enough to be stubborn to learn it all.

The craziness of life, I remember asking someone if it felt different when he turned 30 years old, I was younger then he. Recently I asked him if turning 60 felt different.. Oh how time flies.

Life is such a gift..
 
I would like to ask, because I don't know. Of the below methods of logging into one's bank account which is most secure.

E: Using a smartcard ("bank-ID") in a card reader with keypad (where you confirm a login or transaction by entering PIN code).

What banks are pushing for is something called "mobile bank ID", it's pretty much an app on a smartphone. Its weakness is that it allows scammers to call you, saying "we're Calling from the bank, we see someone is emptying your bank accounts, can you please verify your ID by starting bank-ID?", and some people do start bank-ID, but what happens next is that it lets the scammers in and then they can empty account for real. That is, its weakness is that Mobile Bank-ID doesn't ensure that it's same person who's visiting bank web site that is holding the phone with the Bank-ID. (It's also harder to verify since the computer could be connected using cabled broadband, while cellphone with mobile bank-ID is connected using mobile broadband (3G/GPRS etc). What they probably can do is just filtering out requests for bank-ID verfifications to certain regions like Bearland, Malta [shabby ppm-funds] and countries known for open proxies.

Bank ID with smartcard is connected to browser (on same computer) as a plugin so it's harder to spoof.
 
Last edited:
Are Mindark Announcements reliable?

especially #2 and #3!

gold_card_continued.jpg
 
especially #2 and #3!

gold_card_continued.jpg

They did continue to support it, they never said they would continue to support it for an infinite amount of time, and they're giving a massive heads up to let people know they're now, several years later, going to fully discontinue support, probably because the outdated and likely subcontracted Gold Card system has run into problems many times in the past two years and probably cost them a lot of money in the process.
 
One step back

New system for log in:
Start Entropia on PC -> typ in Password -> switch on my samsung android device and wait (in my case Tablet) -> typ in my password for my android device -> start the App for the securytysystem -> maybe more (don't tested yet) -> login to game


Gold Card:

Start Entropia on PC -> typ in Password -> use card on reader -> typ in code -> login to game


Any more to say?
 
Who ever sold the notion of a two part hardware 2fa solution that requires a separate physical reader from the card/chip and still also requires the user to type in a code anyways?

I never used a gold card because it was an over-elaborate system to protect me from the number one cause of account compromise in a game like this, my own family and friends. I suspect from all I've heard that over 90% of them are sitting obviously (the card and the reader) less than two feet from the main computer where the user also has their entropia username stored in the client.

Literally inconveniencing myself thousands of times for that one day when my wife/brother tries to steal my shit. This is not the way to stay focused on the positive but for me, I've never had enough money in this game to justify that state of endless paranoia. Also endless threads about broken cards and dead readers and contact mindark and a month or more locked out of the game.

I might at some point turn on 2fa here because now it's convenient. But only if I can use a commercial app I'm already using for it because MA is not welcome to a broad range of permissions on my device. I mean, i heard Entropia pocket is requesting a full suite of permission including contacts. How in the hell does nobody complain about that?

I gather, Trance, that you didn't try just using the microsoft authenticator on your existing device?
 
I totally agree with your post.

1 - GC is always near your pc, I doubt many 'hide' their gc when they go away from their pc.
However, it does give some small extra security, in the way that IF someone would know your login credentials, they cannot use it on another station away from the whereabouts of your GC. Then again, if you know enough to get good in EU, u probably know enough to get your pc and login credentials secure.

2 - why the fancy 2FA app, that does nothing more then the regular 2FA systems, except being fancy, being incompatible with other O/S.
Releasing a regular 2FA code, so that you can use the 2FA for EU on any system (for instance, using Authy, or some other google authenticator that is password protected) would be way more convenient and perfectly safe, and inaccessible to unauthorized people.

Not everyone wants a cancer emitting spy-phone next to their computers while gaming...
 
* a full suite of permission including contacts. How in the hell does nobody complain about that? *

Ofc, i will do and i dont like this, if that is true. My contacts are not for MA.
 
...
Releasing a regular 2FA code, so that you can use the 2FA for EU on any system (for instance, using Authy, or some other google authenticator that is password protected) would be way more convenient and perfectly safe, and inaccessible to unauthorized people.

...

I started a different thread about this will try to get an answer in the next hour or so about the current state of things.
 
Not sure if already posted but:
Google authenticator - for Android and iOS
WinAuth - for Windows
Oathtool - for Linux

That covers about all of them - same system, why not use that?
 
...
Releasing a regular 2FA code, so that you can use the 2FA for EU on any system (for instance, using Authy, or some other google authenticator that is password protected) would be way more convenient and perfectly safe, and inaccessible to unauthorized people.
...


Not sure if already posted but:
Google authenticator - for Android and iOS
WinAuth - for Windows
Oathtool - for Linux

That covers about all of them - same system, why not use that?

Microsoft Authenticator also for windows phones (won't install on my windows PC)
Authy is a big one

There are others too. I'm not 100% sure how far they all interoperate.

Anyways I tried with Google auth and started a thread about other authenticators if anyone wants to try or post results with them.

Google auth specifically IS compatible.

This took some advice from svarog but I got it set up correctly and have used it now more than once to log in to EU.

I had earlier posted that it didn't work so I will PM trance the update hopefully she will check microsoft auth for us
 
Last edited:
New system for log in:
Start Entropia on PC -> typ in Password -> switch on my samsung android device and wait (in my case Tablet) -> typ in my password for my android device -> start the App for the securytysystem -> maybe more (don't tested yet) -> login to game


Gold Card:

Start Entropia on PC -> typ in Password -> use card on reader -> typ in code -> login to game


Any more to say?

That's interesting, I had a much different experience

Gold Card :

Start EU -> Type in password -> Look for gold card -> Scramble for key gen -> Swipe several times while the key gen gives me random errors and screen issues -> Desync -> forget the card when I go on vacation -> wait two days to resync -> Generator runs out of battery -> card chip fails -> throw out the window.

Smartphone :

Start EU -> unlock my phone -> start pocket app -> type in the key that appears right at the beginning -> logged in.
 
* a full suite of permission including contacts. How in the hell does nobody complain about that? *

Ofc, i will do and i dont like this, if that is true. My contacts are not for MA.

If people are THAT suspicious, I wonder, why do they give MA their real name, real address, birth date, bank accounts details, cards AND a lot of MONEY very often? Your contacts are not for MA... but everything else is :scratch2: :laugh:
It doesn't make any sense at all... unless whining is your second nature and you find a reason to do it in every moment of any given day :)

edit: IMO if you are that suspicious about this whole platform, you should not use it at all.
 
Last edited:
If people are THAT suspicious, I wonder, why do they give MA their real name, real address, birth date, bank accounts details, cards AND a lot of MONEY very often? Your contacts are not for MA... but everything else is :scratch2: :laugh:
It doesn't make any sense at all... unless whining is your second nature and you find a reason to do it in every moment of any given day :)

edit: IMO if you are that suspicious about this whole platform, you should not use it at all.

No.

Personal information is important and control of your personal data is not "all or nothing".

Each individual draws a line. I enjoy mindark's product and I trust them with my money. They are welcome to know who I am and where I live.

They are not welcome to know where I am geographically at 24/7. They are not welcome to know whom I have in my personal contacts list, nor how frequently I call them. They are not free to browse my photos nor log data regarding what networks I may be connected to at times when I'm not even tHINKING about playing EU.

Personal "Smart" device permissions are a big issue and there is a permissive culture where people are too lazy to sort these things out. Manufacturers and developers are too lazy to bother sorting it out, and the OS developer finds it convenient to coddle that and bunches permissions in odd groupings.

This is encouraged by people who don't care because they can't be bothered to understand. I'm 24 years in the IT industry and had to listen to my idiot ex wife "tell me how the internet works" when she found out about facebook and how harmless it all was.

Guess who is hounding about how horrible they are and wants to be in a class action lawsuit for being treated like a corporate datapoint in a quarterly earnings report now?

It's becoming increasingly important and the good companies that encourage bad habits are also leading you like a lamb to the slaughter to the day when you carelessly give some stupid app the wrong permissions and get your whole life wrecked.

There is nothing wrong or paranoid about paying attention to who has access to your personal information. Just like there's nothing wrong or paranoid about having a lock on your house door. It's common sense.

Anyways it turns out they aren't asking.

To be fair I brought this up again so while I'm sitting here I went and initiated the pocket installer in the play store and here's what it prompted me with:



Photos/Media/Files not sure what they're doing here. They may have created a need for this or current android versions may require them to have this to cache own data related updates, images in news posts, or something that isn't stored in the apps own cache for some reason. In any case, this is minor but may allow them to have (or their app to be used as a key to) data that isn't theirs or relevant to them.

Absolutely needs the camera nobody wants to be dealing with 32 character codes and manual entry on a phone/tablet.

It doesn't NEED to receive data but it is also advertised as providing status updates and whatnot so there you go. Just what I love in my 2fa security fob, an open push channel for external data.

So anyways sorry to bring it up. I initiated the pocket app install from my device earlier on and would swear that it specifically listed contacts which caused me to halt the install. I'm not sure if that was a mistake on my part or if it has changed since. The last update was over a year ago but I haven't actually checked since it was first released, just kicking around things said on the forum for chatter.

I never mind stirring the pot a little. But I wouldn't push for drama on this because as android apps go, this is a totally reasonable permission list. I've no interest or idea what's happening in IOS.

As for paying attention to who has access to your personal data and why - it's 100% important. The number of people in the world who said things like "that's paranoid and idiotic" and then end up getting screwed is growing every day.

In the meantime, I find Google Authenticator to be an acceptable compromise and I'm running this 2fa on my EU account now without entropia pocket. One more app that won't be buzzing my phone at odd hours reminding me to come spend money.
 
I now do not have to turn a light on to log in, ty.
 
If people are THAT suspicious, I wonder, why do they give MA their real name, real address, birth date, bank accounts details, cards AND a lot of MONEY very often? Your contacts are not for MA... but everything else is :scratch2: :laugh:
It doesn't make any sense at all... unless whining is your second nature and you find a reason to do it in every moment of any given day :)

edit: IMO if you are that suspicious about this whole platform, you should not use it at all.

Wow! interesting, how ppl have fantasie, and every critic call whyning... sound like Trump methode.
Just acept that other ppl don't think same as you do.

I don't have paranoia about give out my contact list to an company, but i just don't like it. Where is the problem to say this. Would you like i say, that i like it, but i ever think, whats that for a BS?

A forum is here, to discuss things, not to call ppl whyning, thats supper not constructive! Let's discuss things, not start personal fights!
 
Back
Top