You are trying to log in too fast. Please try again in 1 hour

CanopySheep

Sea Legs
After misspelling my password more than a few times, I'm now faced with this error (title). At first it was a minute, then I relaunched the launcher after the servers updated and now it's up to an hour? Anyone else have this issue and is it really an extra hour of waiting after the update?
 
Yes, it is a new thing someone, somewhere felt was essential to add to the game...
 
Unfortunately rate-limiting logins is necessary to prevent brute-force attacks on accounts. I know it can be annoying in these particular instances, but it's an industry standard designed to keep accounts safe.
I understand, but does it really have to spike from 1 minute to 1 hour? Or did I manage to break it and somehow pass 3 other set times?
 
Unfortunately rate-limiting logins is necessary to prevent brute-force attacks on accounts. I know it can be annoying in these particular instances, but it's an industry standard designed to keep accounts safe.
LOL!
I'm pretty sure there's an easy way to determine a brute force attack with multiple log-ins per second versus someone trying to remember their password.
*HINT - there is, and it's an industry standard...
 
LOL!
I'm pretty sure there's an easy way to determine a brute force attack with multiple log-ins per second versus someone trying to remember their password.
*HINT - there is, and it's an industry standard...
Drop the attitude, it's getting old. You're perfectly capable of conveying your thoughts and suggestions without being condescending or rude.

In any case, the standard you refer to is limiting accounts after X logins in Y time. Which is what TLOPO does, though it sounds as though X and Y may need tweaking? Currently accounts are locked after 3 failed logins in a 1 minute period (for 1 minute), or after 10 failed logins in a 1 hour period (for 1 hour).
 
Drop the attitude, it's getting old. You're perfectly capable of conveying your thoughts and suggestions without being condescending or rude.

In any case, the standard you refer to is limiting accounts after X logins in Y time. Which is what TLOPO does, though it sounds as though X and Y may need tweaking? Currently accounts are locked after 3 failed logins in a 1 minute period (for 1 minute), or after 10 failed logins in a 1 hour period (for 1 hour).
Thanks for the information. I feel like the times should be tweaked slightly, and I can safely say for others experiencing this unfortunate luck that I'm anxious to get back to playing the game!
 
I noticed as well that when trying to login it will say logging in too fast now you must wait 1 minute or it will spike up to 1 hour then switch back and forth. The thing is why have that initiated for TLOPO it won't really work well when TLOPO reaches released candidate. Also why have this initiated especially those that have beta keys. But if this helps the servers not crash after updates won't that also defeat the purpose of fixing that issue as well. (I'm bad at explaining so hopefully what I typed makes some sense).
 
Again, it's a fairly standard line of defense against brute force attacks. Without it, there's nothing in place to prevent someone from trying password after password until they find yours. It's not about preventing the servers from crashing or anything like that. It may need some adjusting if it's problematic for regular users though.
 
Again, it's a fairly standard line of defense against brute force attacks. Without it, there's nothing in place to prevent someone from trying password after password until they find yours. It's not about preventing the servers from crashing or anything like that. It may need some adjusting if it's problematic for regular users though.
Then will a queue system be initiated for those that have beta keys or something? Just a thought.
 
Drop the attitude, it's getting old. You're perfectly capable of conveying your thoughts and suggestions without being condescending or rude.

In any case, the standard you refer to is limiting accounts after X logins in Y time. Which is what TLOPO does, though it sounds as though X and Y may need tweaking? Currently accounts are locked after 3 failed logins in a 1 minute period (for 1 minute), or after 10 failed logins in a 1 hour period (for 1 hour).
Attitude?
I have no attitude.
Perhaps you have the attitude?
I'm making light of a situation which I find amusing.
If you're getting all bent out of shape because of that, then maybe you need a break my friend.
That's not me, it's you.
Take it easy, relax and clam down.
It'll be OK.
 
Drop the attitude, it's getting old. You're perfectly capable of conveying your thoughts and suggestions without being condescending or rude.

In any case, the standard you refer to is limiting accounts after X logins in Y time. Which is what TLOPO does, though it sounds as though X and Y may need tweaking? Currently accounts are locked after 3 failed logins in a 1 minute period (for 1 minute), or after 10 failed logins in a 1 hour period (for 1 hour).
I think maybe going from 1 minute to 1 hour is a bit much. Maybe going from 1 minute to 5 minutes to 15 minutes to 30 minutes to an hour would be more reasonable? If people even have semi-decent passwords, a brute force attack would take millions of tries to have a chance of succeeding. Maybe if there's a doubt in TLOPO's mind that an account is trying to be breached, lock the account and have the player change their password by email or confirm that it's them.

Just my 2c tho :).
 
Then will a queue system be initiated for those that have beta keys or something? Just a thought.
Brute force is irrelevant to beta keys or the queue system. He's talking about a method of stealing accounts. One that's made very very nearly entirely useless by the login attempt delay.

Why would you want beta keys to be useless? Why would you want everyone to have queues and playtimes? The end goal should be nobody having queues and playtimes!
 
This happened to me I had to log into another account to get into the game, a lot of games have this very same thing so I understand why tlopo has it, also what was the update for it doesn't show in the release notes
 
Back
Top