Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Reply
 
Thread Tools Display Modes
Old Jan 21, 2010, 12:46 AM // 00:46   #41
Ascalonian Squire
 
Join Date: Jul 2009
Location: Somewhere in Ascalon
Profession: Me/E
Advertisement

Disable Ads
Default

So You've Been Hacked...

http://bifftheunderstudy.wordpress.c...e-been-hacked/
Miscreant_Moon is offline   Reply With Quote
Old Jan 21, 2010, 12:56 AM // 00:56   #42
Frost Gate Guardian
 
Join Date: Oct 2006
Default

Quote:
We have a team of security professionals with years of experience in massively multiplayer games and online security in Seoul, Seattle, Austin, and Brighton that is striving to make our servers as secure as they can be. Any vulnerability that is discovered is addressed and fixed.
I appreciate the efforts to provide such a statement by NCsoft.

I don't believe there's been adequate accountability on the part of NCsoft (or at least not publicly acknowledged). The additional security measure taken on New Year's Day seemed to address an obvious, glaring security hole. I'm not an IT or security specialist, but the ability to change GW account credentials without any authentication or control (in that event that the NCsoft master account was compromised) seems like a fairly obvious security hole. E.g., a player might've had lax account credentials for the NCMA (sharing login and password on a compromised site), but might've maintained a strong unique password for their GW account, but that wouldn't necessarily matter and could be circumvented easily because of the NCMA security design.

That issue seemed to be a noted issue since at least October from what I can glean. I just wonder how many account thefts could've been prevented if NCsoft took that measure earlier rather it require major escalation on New Year's Day to make such a change.

Given NCsoft has so many security professionals with so many years of experience, I do wonder why it took months for such an obvious security hole to be addressed (obvious to a layperson such as myself). Players need to be educated and do more, but with a large population of players, there will be varying levels of sophistication. Lapses by players which might enable their accounts to be compromised doesn't excuse NCsoft from their own conduct or failure to act that facilitates player accounts to be compromised.
greenthumb is offline   Reply With Quote
Old Jan 21, 2010, 12:57 AM // 00:57   #43
End
Forge Runner
 
End's Avatar
 
Join Date: Jan 2008
Location: Rubbing Potassium on water fountains.
Guild: LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
Profession: N/A
Default

Quote:
Originally Posted by Regina Buenaobra View Post
NCsoft has published a message from our Game Surveillance Unit today, regarding account security. For the full message, please go to the NCsoft web site.
You should just remove the link. Your just gonna piss more people off....but of course your not going to read this. Theres to many people pissed off already to notice this little message here.

Edit: I have nothing against anet in terms of security I commend them on their fast action adding in a new security feature before ncsoft even began to look at the issue.
End is offline   Reply With Quote
Old Jan 21, 2010, 01:03 AM // 01:03   #44
Krytan Explorer
 
Join Date: Aug 2007
Location: The Netherlands
Profession: W/
Default

I take this like the bimonthly skillupdate and every other thing they said they were going to do; but never did. All lies!
isildorbiafra is offline   Reply With Quote
Old Jan 21, 2010, 01:07 AM // 01:07   #45
Desert Nomad
 
Cacheelma's Avatar
 
Join Date: Jun 2005
Guild: The Ascalon Union
Profession: Me/Mo
Default

Quote:
Originally Posted by Illfated Fat View Post
This isn't meant to play kiss-ass for NCSoft
That's EXACTLY what it is.

But to be honest this whole thing is really tiring. Let's not open this can of worm again. I don't see any good coming out of it anytime soon.
Cacheelma is offline   Reply With Quote
Old Jan 21, 2010, 01:18 AM // 01:18   #46
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

Quote:
As a result of the point-by-point testing and analysis, our security team concluded no critical vulnerabilities had been demonstrated or identified, but our security team continues to research, to monitor closely, and to implement security improvements to address any potential weaknesses raised.
Don't insult my intelligence. It makes me very angry.

Quote:
We'll continue to audit our systems, and you will see some dramatic changes in the next few months. NCsoft views account security as a very important matter.
See, the issue is that if there weren't problems, you would not take action. Action is costly, so you wouldn't expend resources on the site unless you thought the downside risk from not taking action was greater than the cost of taking action. Your behavior reveals that your denial is a lie.
Martin Alvito is offline   Reply With Quote
Old Jan 21, 2010, 01:22 AM // 01:22   #47
Forge Runner
 
Gun Pierson's Avatar
 
Join Date: Feb 2006
Location: Belgium
Guild: PIMP
Profession: Mo/
Default

Quote:
Originally Posted by Cluebag View Post

You hear that Linsey, you big dummy? Stop using bots, buying in-game money, downloading keyloggers and all that other stuff that must have happened, since NCSoft security is bulletproof.
She's a cute dummy though, but that's my opinion




To NCSoft...Yes there's a war going on I agree with that, but it has been going on for years. Yes we must all fight it together, but in case you didn't know, the grunts are fighting for months now and where the hell were you? More so, people changed their passwords after the alarming message on the GW log in screen and many got their account raped after that action. But you didn't fool me, same old password since release thank you. However you did trick me into getting the free storage pane which forced me to link my GW account to an NCSoft main account. Which reminds me, I saw a thread about a list with accounts info that was stolen somehow.

People got wrong support tickets and so on. So I'm not sure what you can do for us in this war as from what I understand it will take some time before the extra security or whatever it is you talk about gets into operating mode.

You make Anet and the players look bad NCSoft and I didn't even like you before all this. If it wasn't for GW2, I would never buy a product from you again.

Last edited by Gun Pierson; Jan 21, 2010 at 01:28 AM // 01:28..
Gun Pierson is offline   Reply With Quote
Old Jan 21, 2010, 02:25 AM // 02:25   #48
Pyromaniac
 
YunSooJin's Avatar
 
Join Date: Aug 2005
Profession: Mo/W
Default

Quote:
Originally Posted by Illfated Fat View Post
My, what cynics you all are ; ).

Of course articles such as Jennings' will contain some sort of 'political' agenda, but in the grand scheme, the intent comes from a good place. They hear us - heck - they even quoted one of us. Our words are not going unread. True, we can point fingers at mistakes, but they can also do it to us (yes - I'm looking at all you people who leave your account open to vulnerabilities).

This isn't meant to play kiss-ass for NCSoft - organizations are never even close to perfect, especially with a convoluted structure of departments. If we snap our fingers, changes won't - believe it or not - happen overnight. When you deal with the many thousands of people that they do, with all sorts of details and complications, there is hardly a simple fix at the switch of a button. It is not unreasonable for their time-line to be estimated in weeks, or even months.

It is our account security but worse things could go wrong if they hasten a response. How many of you guys have actually seen the structure behind the interface we see, both for the website and multiple games they create? At best, it is organized chaos. One fix here could result in a bug there, or another vulnerability elsewhere, etc. etc. Trust me - you want these people to be as meticulous as the can.

Thanks for looking into it and hearing us. You guys aren't perfect, the gamers aren't perfect. Sometimes you guys screw shit up and so do we. Let's call it even?
Probably give you more perspective if you got hacked and then read that little gem of theirs. Hopefully you will learn to gain perspective simply by using that hypothetical as a mental exercise, although if it still doesnt bring perspective maybe being hacked is what's needed *shrug*.
YunSooJin is offline   Reply With Quote
Old Jan 21, 2010, 02:46 AM // 02:46   #49
Lion's Arch Merchant
 
thedarkmarine's Avatar
 
Join Date: Mar 2006
Default

Quote:
Originally Posted by Martin Alvito View Post
Don't insult my intelligence. It makes me very angry.



See, the issue is that if there weren't problems, you would not take action. Action is costly, so you wouldn't expend resources on the site unless you thought the downside risk from not taking action was greater than the cost of taking action. Your behavior reveals that your denial is a lie.
Every buy insurance?
thedarkmarine is offline   Reply With Quote
Old Jan 21, 2010, 02:59 AM // 02:59   #50
Desert Nomad
 
Lord Dagon's Avatar
 
Join Date: Jul 2009
Location: Inside the Oblivion Gate
Guild: The Imperial Guards of Istan[TIGE]
Profession: E/Me
Default

And you know what the sadest thing about this is? even past the account secrutiy adn their blatent lie that NCSoft has no flaws? its that Neither Martine or Regina will ever read the thread that they created ever again. And i mean NEVER. Its just "here you go guys *they go hide in the lead bomb shelter*" . it seems they just want us to sit in our own stew here.. or the fact they truely believed that this conformation would make us happy and start skipping down a nice gold bricked lane. Its the fact that they see us w/ the intelligence of cows and the value of how much crap we buy from them. good day anet *htits them w/ a white glove* its time for war -.-
Lord Dagon is offline   Reply With Quote
Old Jan 21, 2010, 03:03 AM // 03:03   #51
EXCESSIVE FLUTTERCUSSING
 
Kattar's Avatar
 
Join Date: Mar 2007
Guild: SMS (lolgw2placeholder)
Profession: Me/
Default

Quote:
Originally Posted by Tobi Madera View Post
And you know what the sadest thing about this is? even past the account secrutiy adn their blatent lie that NCSoft has no flaws? its that Neither Martine or Regina will ever read the thread that they created ever again. And i mean NEVER. Its just "here you go guys *they go hide in the lead bomb shelter*" .
Regina's reading the thread right now. Just because you can't see her doesn't mean she's not here.
__________________
All seems lost now, but still we must fight on.
Kattar is offline   Reply With Quote
Old Jan 21, 2010, 03:07 AM // 03:07   #52
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

Quote:
Originally Posted by thedarkmarine View Post
Every buy insurance?
You buy insurance when there is risk.
Martin Alvito is offline   Reply With Quote
Old Jan 21, 2010, 03:07 AM // 03:07   #53
End
Forge Runner
 
End's Avatar
 
Join Date: Jan 2008
Location: Rubbing Potassium on water fountains.
Guild: LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
Profession: N/A
Default

Quote:
Originally Posted by Katsumi View Post
Regina's reading the thread right now. Just because you can't see her doesn't mean she's not here.
And just because you can see her with a little star next to her name doesn't mean she is.
I am frankly surprised she even bothered to post in This thread...but its hard to ignore 59 pages of posts....

We'll see what happens here
End is offline   Reply With Quote
Old Jan 21, 2010, 03:10 AM // 03:10   #54
EXCESSIVE FLUTTERCUSSING
 
Kattar's Avatar
 
Join Date: Mar 2007
Guild: SMS (lolgw2placeholder)
Profession: Me/
Default

Come come, End, just educating the new user of how the forum works.

Why would they idle in threads all day though? To fool the mod staff?

Eh, I've been watching them enough to know their habits. They have been reading this thread. Sadly you just have to take my word for it.
__________________
All seems lost now, but still we must fight on.
Kattar is offline   Reply With Quote
Old Jan 21, 2010, 03:12 AM // 03:12   #55
End
Forge Runner
 
End's Avatar
 
Join Date: Jan 2008
Location: Rubbing Potassium on water fountains.
Guild: LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
Profession: N/A
Default

Quote:
Originally Posted by Katsumi View Post
Why would they idle in threads all day though? To fool the mod staff?
Actually I've found that this site dosen't update that down there often...had my ex-guild leader listed as reading a thread....two hours after they logged out and closed firefox...

Or yeah idling just for gits and shiggles

edit: not to mention anyone can look at how many people are viewing...and checking out how many names it displays...and relies some people be hiding...
End is offline   Reply With Quote
Old Jan 21, 2010, 03:19 AM // 03:19   #56
EXCESSIVE FLUTTERCUSSING
 
Kattar's Avatar
 
Join Date: Mar 2007
Guild: SMS (lolgw2placeholder)
Profession: Me/
Default

Quote:
Actually I've found that this site dosen't update that down there often...had my ex-guild leader listed as reading a thread....two hours after they logged out and closed firefox...
When you spaz around the forum half the day like I do, back and forth between profiles and threads, it does.

But regardless, this is a little off topic.
__________________
All seems lost now, but still we must fight on.
Kattar is offline   Reply With Quote
Old Jan 21, 2010, 03:22 AM // 03:22   #57
End
Forge Runner
 
End's Avatar
 
Join Date: Jan 2008
Location: Rubbing Potassium on water fountains.
Guild: LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
Profession: N/A
Default

Quote:
Originally Posted by Katsumi View Post
When you spaz around the forum half the day like I do, back and forth between profiles and threads, it does.

But regardless, this is a little off topic.
I keep important and trolly threads open in their own tab and browse in another...btw you might want to delete this after you read it...it's completely off topic...

@ChrisWorld below me...last night I think it was one of those ad people was listed as banned with a green dot

Last edited by End; Jan 21, 2010 at 03:27 AM // 03:27..
End is offline   Reply With Quote
Old Jan 21, 2010, 03:32 AM // 03:32   #58
Lion's Arch Merchant
 
Join Date: Sep 2006
Location: Travelling around Tyria, Cantha, and Elona
Profession: P/W
Default

What is this pathetic attempt to cover your incompetence, NCSoft? A giant wall of text (that I actually read) which basically tells nothing useful except to say "hey, other companies are being targeted as well so we're not the only ones. Sure Google managed to protect their customers while we still won't admit that we suck at security; but hey it's your fault if you get hacked".

And reading the Aion forums, it's clear that NCSoft really doesn't know how to do business. You never, ever use that kind of attitude like GM Ash did when dealing with your clients. I could go on but what's the point.
Giga_Gaia is offline   Reply With Quote
Old Jan 21, 2010, 03:35 AM // 03:35   #59
End
Forge Runner
 
End's Avatar
 
Join Date: Jan 2008
Location: Rubbing Potassium on water fountains.
Guild: LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
Profession: N/A
Default

Quote:
Originally Posted by Giga_Gaia View Post
You never, ever use that kind of attitude like GM Ash did when dealing with your clients. I could go on but what's the point.
Makes me miss Tabula Rasa....Seemed that the GM's for TR actually cared about the game... (15 minutes from sending in a support ticket to getting a response in game)
End is offline   Reply With Quote
Old Jan 21, 2010, 04:05 AM // 04:05   #60
Frost Gate Guardian
 
Join Date: Aug 2006
Profession: Me/
Default

Quote:
Originally Posted by Theocrat View Post
It was indeed. But clearly in her case it was not an issue of her doing something wrong; that only applies to the rest of us.

Speaking of Linsey, does anyone have any proof of her supposed hacking? I heard it was posted on her facebook or something like that. I havent seen screenshots or seen it posted anywhere else.
Diana Belevere is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:26 AM // 09:26.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("