Email Address:
Forgot Password?
Advanced Search
Active Players on Sylestia
Category Total Yesterday
Players 2,161 348
Sylestia Pet Data
Category Total Yesterday
Pets 8,328,001 1,090
Generated 664,597 295
Captured 1,204,050 48
Bred 6,459,258 747
Statistics updated daily at midnight
Forum Index > News and Announcements > IMPORTANT: Account Security
Page 4 1, 2, 3, 4, 5... 11, 12, 13 Go to Page:
Author Thread Post
Level 75
Joined: 4/17/2020
Threads: 4
Posts: 69
Posted: 12/12/2020 at 10:04 PM Post #31
Thank you for the information but I am a bit concerned about changing the log-in to my email account. I have had my email account hacked twice in the past, one was my yahoo account which I closed and the other was the hotmail account which I have had to change passwords several times due to account tampering.

Is there another option for log-in id. instead of email? Something maybe like a unique alpha-numeric combination that is assigned to each account that could be generated by Sylestia when an account is setup?

This unique id would of course be sent to the player's email account and then player usernames will still be seen on our pages but this unique individual id will only be known to the account holder and Sylestia. Just a thought.
Level 70
Joined: 2/26/2013
Threads: 3
Posts: 42
Posted: 12/12/2020 at 10:24 PM Post #32
Good to know. Thanks for the heads up.
Level 74
Grand Protector
Joined: 5/2/2019
Threads: 25
Posts: 689
Posted: 12/12/2020 at 10:41 PM Post #33
Author: Savynn
Time Posted: 12/12/2020 at 7:06 PM
What would this person have to gain by doing this?

First off , I want to thank Krin for telling us. It is so refreshing to have a site actually admit that there is a problem, rather than try to 'hand wave' it away.

As for the quote, sadly, coming from Neopets and the like, there really isn't any telling, but among my guesses would be:

1. Blackmarket. I honestly don't know how prevalent it is for Sylestia, but I know other sites tend to have huge Black markets due to retired items and things that people are willing pay real money for, usually just for bragging rights.

2. Just for fun. Some people think it is fun to try to get into sites in ways they aren't meant to. Same reason you have people who break rules.

3. Could be testing code for other sites. Seeing how detectable the code is, how efficient etc..

4. Sadly, though this isn't common, I have seen it, just to 'ruin' things. There are people out there that just like to ruin other people's fun, and if they felt that they could do that by getting into accounts, they absolutely would.
Level 74
Grand Protector
Joined: 5/2/2019
Threads: 25
Posts: 689
Posted: 12/12/2020 at 10:46 PM Post #34
Author: Katty
Time Posted: 12/12/2020 at 9:35 PM
yeah really, i dont have easy log in stuff anywhere of importance xD

What i do is i have a password protected word document of all my passwords. that way i only need to recall one pw and can cut and paste all the passwords for the sites i use

I probably shoudl do that. Right now I just use keyboard smashes as passwords, and keep them in FF (of course, I also don't online bank, or anything like that, so the only 'sensitive' password would be my email, and good luck wading through that :P Though I would hate to lose my accounts in various places, or have to go through the trouble of resetting passwords *shudders*)
Level 75
The Perfectionist
Joined: 1/9/2017
Threads: 56
Posts: 1,308
Posted: 12/12/2020 at 10:57 PM Post #35
is there any way to not do security code thing based on IP address? I have dynamic IP and there is no way I can white list the whole pull. may it be based on device please?
Level 75
Shadow of the Moon
Site Administrator
Joined: 12/17/2012
Threads: 1,125
Posts: 14,732
Posted: 12/12/2020 at 11:05 PM Post #36
Author: Gerry
Time Posted: 12/12/2020 at 10:57 PM
is there any way to not do security code thing based on IP address? I have dynamic IP and there is no way I can white list the whole pull. may it be based on device please?

It is much harder to track based on a device than an IP Address in regards to the two-way authentication I discussed. I plan on playing around with some stuff and see what I can come up with - but IP Address based is what I am most familiar and comfortable with at this time.

Either way, the two-way auth will be optional. So if it poses an issue, a player can just opt to not use it once it is implemented.
Level 75
The Perfectionist
Joined: 1/9/2017
Threads: 56
Posts: 1,308
Posted: 12/12/2020 at 11:08 PM Post #37
fine then, thank you very much for explanation!
Level 74
Joined: 9/18/2020
Threads: 14
Posts: 173
Posted: 12/12/2020 at 11:12 PM Post #38
thanks for telling us, hoping this doesn't happen again
Level 75
Warden of Umbra
Joined: 11/30/2020
Threads: 15
Posts: 319
Posted: 12/12/2020 at 11:14 PM Post #39
I know many places use an authentication code that is sent to an email if the password is incorrect a certain amount of times. Another method is to have identification questions that players set upon registration. I always use past pets' bizarrely long nicknames, which no one else can even remember.
Level 74
The Sweet Tooth
Joined: 4/5/2018
Threads: 25
Posts: 378
Posted: 12/12/2020 at 11:22 PM Post #40
Thanks krin, about two or three weeks ago i had an alert saying my password was compromised i got the alert on my iphone so i sent in a password change stating why but it was never changed so im glad about the coming change
Go to Page:
1, 2, 3, 4, 5... 11, 12, 13
This Page loaded in 0.012 seconds.
Terms of Service | Privacy Policy | Contact Us | Credits | Job Opportunities
© Copyright 2011-2024 Sylestia Games LLC.
All names and logos associated with Sylestia are Trademarks of Sylestia Games LLC.
All other trademarks are the property of their respective owners.
For questions, comments, or concerns please email at