Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Reply
 
Thread Tools Display Modes
Old Jan 06, 2010, 06:48 AM // 06:48   #21
Grotto Attendant
 
Join Date: Apr 2007
Advertisement

Disable Ads
Default

Quote:
Originally Posted by The Drunkard View Post
I thought suggestions were supposed to be posted in the suggestion sub-fourm, Sardelac Sanitarium, but I guess I'm just going crazy.
1. Sardelac is for suggestions about changes to the game qua game. Security features don't fit squarely into that rubric.

2. It's a matter of significant community concern, and those belong in Riverside. (We all know that nothing in Sardelac gets read anyway....)
Chthon is offline   Reply With Quote
Old Jan 06, 2010, 06:56 AM // 06:56   #22
Jungle Guide
 
snodaard's Avatar
 
Join Date: Jun 2006
Location: Holland
Guild: [Uni]
Profession: Mo/
Default

and what if the hacker pwns you when you are in bed? and simply doesn't change your password becouse he knows he can't trade for 72 hours if he does change passwords?
snodaard is offline   Reply With Quote
Old Jan 06, 2010, 11:07 PM // 23:07   #23
Lion's Arch Merchant
 
EmptySkull's Avatar
 
Join Date: Jul 2006
Guild: KaoS League
Profession: E/
Default

Quote:
Originally Posted by snodaard View Post
and what if the hacker pwns you when you are in bed? and simply doesn't change your password becouse he knows he can't trade for 72 hours if he does change passwords?
My account was hacked via Ncsoft master account. He changed my password through there and then logged into my account. Then stole the stuff. If the feature was implemented no way he would've gotten anything.

The only other way my account could have been logged into was by brute force busting a 10 digit real random number derived using a die, chart and coin.

Well if they had gotten in that way(which they couldn't because you can't brute force the actual account due to Anet security) then so be it.

The way I was hacked and a lot of others were was via a breach in Ncsoft security. And the suggestion I made would have prevented theft.
EmptySkull is offline   Reply With Quote
Old Jan 08, 2010, 02:35 AM // 02:35   #24
Furnace Stoker
 
pumpkin pie's Avatar
 
Join Date: Jul 2006
Location: behind you
Guild: bumble bee
Profession: E/
Default erm.

Didn't want to resurrect an old thread, but does this look familiar? notice the date of the post Sep 20, 2006, so they haven't resolve the problem? Yet have us all link our accounts to NCsoft master account? Is Plaync = NCsoft?

linkie
pumpkin pie is offline   Reply With Quote
Old Jan 08, 2010, 02:49 AM // 02:49   #25
La-Li-Lu-Le-Lo
 
Faer's Avatar
 
Join Date: Feb 2006
Default

Quote:
Originally Posted by pumpkin pie View Post
Is Plaync = NCsoft?
Yes, PlayNC = NCSoft.
__________________
Stay Breezy
Faer is offline   Reply With Quote
Old Jan 08, 2010, 02:49 AM // 02:49   #26
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

The language of the post you link doesn't acknowledge a problem with PlayNC security. Gaile maintains in that post that credential sharing and social engineering led to the hacks.

A PlayNC account is the older name for a NCSoft Master Account (NCMA). I don't remember if the PlayNC accounts used the current website design in 2006. I want to say that there was a site redesign around 2007, but I could easily be mistaken in my recollection.
Martin Alvito is offline   Reply With Quote
Old Jan 08, 2010, 07:52 PM // 19:52   #27
Krytan Explorer
 
Benderama's Avatar
 
Join Date: Jul 2008
Location: UK
Guild: [Rage]
Profession: Rt/
Default

i definetley think the e-mail your new password thing works, at least if its random numbers and letters they could send a verification notice before they confirm the password change
Benderama is offline   Reply With Quote
Old Jan 10, 2010, 08:43 PM // 20:43   #28
Frost Gate Guardian
 
nologic's Avatar
 
Join Date: Jul 2006
Location: Sweden
Profession: E/
Default

Quote:
Originally Posted by Andrew Dunne View Post
They have added recently to the login where you need email address, password and character name which makes it much more secure, (as the OP said he thought there had been something) as now you can get two of the three info from NCSoft but then need to know whose account it is, (IGN). Whilst possible stops most of the hacks, although obviously more is still better.

Edit: Only thing with 2 is whether then people will just hack and delete accounts to be malicious in response to change, (since they can get no value from it, make sure that the acc holder loses EVERYTHING).
Can't say its more secure either nothing is impossible hackers gets better over time to walk through the park. It would be real bad if they go for the database over character names etc.

I know Blizzard added a dongle u can buy for like 9 euros from their website there is one way to go to make it even more secure.
NCSoft should really consider using the same way its good that ANet stepped up and did something but i doubt the hacking wont end just because of that.
nologic is offline   Reply With Quote
Old Jan 11, 2010, 03:52 AM // 03:52   #29
Ascalonian Squire
 
Join Date: Jul 2009
Location: Somewhere in Ascalon
Profession: Me/E
Default

They don't even have to implement a dongle to make this happen though. In Korea, NCSoft has an app that you can download to your cell phone that generates a random password for you. It's all ready in their games.

But you know, pffft, the Western audience. We're just here for some side profit. NCSoft only cares about their asian players.

http://aion.plaync.co.kr/side/ncotp
Miscreant_Moon is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 09:54 AM // 09:54.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("