Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Inner Circle > The Riverside Inn

Notices

Closed Thread
 
Thread Tools Display Modes
Old Dec 10, 2009, 08:10 PM // 20:10   #121
Forge Runner
 
Join Date: Jan 2007
Advertisement

Disable Ads
Default

Quote:
Originally Posted by Chthon View Post
/Signed.

I've been keeping tabs on the "I've been hacked" stories.
http://www.guildwarsguru.com/forum/s...9&postcount=28
Bob Slydell is offline  
Old Dec 10, 2009, 08:14 PM // 20:14   #122
Grotto Attendant
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by Tullzinski View Post
The most logical explanation that is consistent with the reported facts of recent account thefts is that it is possible to steal accounts solely through interaction with NCSoft and a-net. The thief does not need to interact with the user in any way -- no keylogger, no man-in-the-middle, no phishing, no social engineering, no access to your e-mail, no gleaning your info from forums like this one. The thief goes directly to NCSoft/a-net and comes away with your GW login credentials. Do you comprehend that?

Now, can you understand why people are so upset?
Chthon is offline  
Old Dec 10, 2009, 08:20 PM // 20:20   #123
Ascalonian Squire
 
Nuime's Avatar
 
Join Date: Oct 2009
Location: Los Angeles, California
Guild: Bad Wolf Corporation [WOLF]
Profession: Mo/
Default

/signed

Although I haven't had a problem (yet, *keeps fingers crossed*) I also would like to continue to play the game, make in-game-store purchases and everything else like one normally would without even having the slightest trace of worry that any "safe" actions I take through ncsoft will result in getting my account hacked.

Aside from just ncsoft apparently needing to up their own site security...
A simple thing that would make me feel a bit better when it comes to my accounts would be to simply send out an email confirmation when any password (guild wars or ncsoft main) requests to be changed. Assuming your email wasn't compromised, that alone would help a great deal.
You could even add on a "click here to confirm that yes, you changed your password" and make the account temporarily "suspended" until that link is clicked. Heck, take it one step further and make someone answer their "secret questions" again for another level of confirmation at any point of attempting to change a password. Yes it would be a bit of a runaround and annoying to do at that point, but I for one can safely say I rather have it be annoying for me to make changes to my account if it made it harder for someone else to remotely alter anything.
Nuime is offline  
Old Dec 10, 2009, 08:20 PM // 20:20   #124
Jungle Guide
 
Carboplatin's Avatar
 
Join Date: Jul 2005
Guild: [PIG]
Profession: W/A
Default

./signed.

However, I don't expect anything to be done. I've since started stashing my new earned goodies in multiple accounts, so if they hack one, hopefully the others will be safe. Yeah its that sad.
Carboplatin is offline  
Old Dec 10, 2009, 08:22 PM // 20:22   #125
Lion's Arch Merchant
 
Grunntar's Avatar
 
Join Date: Apr 2005
Default

/signed!

Quote:
Originally Posted by Siirius Black View Post
Someone found a vulnerability in ncsoft and obviously they are exploiting it.
I completely agree with this assessment!

Quote:
Originally Posted by Chthon View Post
because NCSoft can't build a secure system is utterly unacceptable
The fact that they unwilling to even try to build in some security is what I find most disturbing. The house is on fire, and they are sitting on the couch, drinking a beer, and watching TV.
Grunntar is offline  
Old Dec 10, 2009, 08:24 PM // 20:24   #126
Academy Page
 
(Datura)'s Avatar
 
Join Date: Apr 2008
Location: South East
Guild: Kiss
Profession: E/
Default

/Signed

I don't like NC Soft but love Arenanet.

So, I'll continue to do business with Anet until I can't trust their products for any reason.

Last edited by (Datura); Dec 10, 2009 at 08:30 PM // 20:30..
(Datura) is offline  
Old Dec 10, 2009, 08:27 PM // 20:27   #127
Jungle Guide
 
Tullzinski's Avatar
 
Join Date: Mar 2006
Location: Trying to stay out of Ryuk's Death Note
Profession: N/R
Default

Quote:
Originally Posted by Chthon View Post
The most logical explanation that is consistent with the reported facts of recent account thefts is that it is possible to steal accounts solely through interaction with NCSoft and a-net. The thief does not need to interact with the user in any way -- no keylogger, no man-in-the-middle, no phishing, no social engineering, no access to your e-mail, no gleaning your info from forums like this one. The thief goes directly to NCSoft/a-net and comes away with your GW login credentials. Do you comprehend that?

Now, can you understand why people are so upset?
Absolutely!!! I guess I should have put the /sarcasm line in my last post. I find it amazing that ANET/NCSOFT has this listed as a ADDITIONAL security measure when it is NOT!!!
Tullzinski is offline  
Old Dec 10, 2009, 08:30 PM // 20:30   #128
Ascalonian Squire
 
Join Date: Aug 2009
Guild: Wtf Am I [Doin]
Profession: D/
Default

/signed

................
Hotboxin240 is offline  
Old Dec 10, 2009, 08:41 PM // 20:41   #129
Academy Page
 
Join Date: May 2006
Location: Netherlands
Guild: Lowland Lions
Default

/signed

Authenticator ftw
didis is offline  
Old Dec 10, 2009, 08:42 PM // 20:42   #130
Wilds Pathfinder
 
Join Date: Nov 2007
Guild: Still looking
Profession: Rt/
Default

/notsigned

I would agree if you provide an explanation on some of the possible reasons how people are getting hacked and some alternatives for Anet to improve the security. Otherwise this is just another thread demanding Anet to change their game's structure because "we don't like it."
The Drunkard is offline  
Old Dec 10, 2009, 08:53 PM // 20:53   #131
Grotto Attendant
 
Join Date: Apr 2007
Default

Quote:
Originally Posted by Tullzinski View Post
Absolutely!!! I guess I should have put the /sarcasm line in my last post. I find it amazing that ANET/NCSOFT has this listed as a ADDITIONAL security measure when it is NOT!!!
My apologies, missed the sarcasm.
Chthon is offline  
Old Dec 10, 2009, 09:01 PM // 21:01   #132
Ascalonian Squire
 
Aragno's Avatar
 
Join Date: Feb 2007
Location: Belgium
Profession: Mo/E
Default

Signed

ArenaNet should start focussing on main issues instead of fixing rather pointless things
Aragno is offline  
Old Dec 10, 2009, 09:03 PM // 21:03   #133
Krytan Explorer
 
Obrien Xp's Avatar
 
Join Date: Jan 2009
Location: Canada
Guild: The First Dragon Slayers [FDS]
Default

/signed

We bought it and worked on it, at least try to do something.

Skill Balance<<<Security

I love anet, its just that this is out of hand.
Obrien Xp is offline  
Old Dec 10, 2009, 09:04 PM // 21:04   #134
Pre-Searing Cadet
 
Join Date: Sep 2009
Guild: House of the Old
Profession: Me/
Post

--Signed--Signed--Signed--

Too many hours played to start over.
Jhesta Z is offline  
Old Dec 10, 2009, 09:06 PM // 21:06   #135
Lion's Arch Merchant
 
Rydia Merchan's Avatar
 
Join Date: Jun 2006
Location: Following Duran Duran around the world
Guild: Paladins of Eternal Truth [POET]
Profession: Me/
Default

/ Signed!!! Thanks for posting this Shan.
Rydia Merchan is offline  
Old Dec 10, 2009, 09:13 PM // 21:13   #136
Frost Gate Guardian
 
Join Date: Sep 2009
Guild: Electric Celerity [EC]
Profession: D/A
Default

Signed.

I got my account hacked 4 days ago by a Chinese gold farmer. I just got it back yesterday after HAVING to call NCSoft and pressure them into doing something. Pressure this company on the phone guys, even if you have to wait 20-40 minutes while on hold.

To people who want to know the potential of these hackers here are the main things.

1) These hackers can gain all your information that is entered in your NCSoft account. This means full name, DOB, Street Address, and email.

2) These hackers can change your security questions and passwords at any time they wish.


THIS IS SERIOUS NCSOFT! We are being serious about wanting to keep our accounts safe, so be respectful and return the favor.

Suggestions for NCSoft on how to improve security

1) Require changed password requests to be finalized in the email of the registered person. Changing passwords directly in NCSoft Master Account is unsafe.

2) Allow players to HAVE A CHOICE wether or not they want a password for each of their characters. This means that when you click on a character to play, another password unique to that character (and not stored on the NCSoft website) is required to access the character.

3) Characters cannot be deleted once made unless a request is sent to the user's email for confirmation.

4) Allow the email used to log into the account to be changed via email confirmation from the old email and the new email.

5) MAKE ALL REQUESTS AND TRANSACTIONS GO THROUGH THE USER'S EMAIL! This will make things much more secure.


Please fix the security issues for the sake of your company and for your player base.
shadowlurk16 is offline  
Old Dec 10, 2009, 09:18 PM // 21:18   #137
Wilds Pathfinder
 
Olim Chill's Avatar
 
Join Date: Oct 2007
Location: USA
Guild: DMI
Profession: N/
Default

Quote:
Originally Posted by Chthon View Post
The most likely explanation is that, in addition to the usual number of people who get their accounts stolen through their own stupidity, there is currently a method of stealing accounts directly through a-net/NCSoft. The password reset feature on the NCSoft master account seems the most likely culprit.
I suspect the same. One of my accounts got hacked right after I'd used the password reset feature. It was the first time I ever used the password reset feature and the first time I ever got hacked. Fortunately, there was nothing in there worth taking at the time.
Olim Chill is offline  
Old Dec 10, 2009, 09:22 PM // 21:22   #138
Ascalonian Squire
 
Join Date: Sep 2008
Location: Holland
Guild: The Mirror of Reason [SNOW]
Profession: D/
Default

/notsigned

get urself a proper password
Die You Infidel is offline  
Old Dec 10, 2009, 09:26 PM // 21:26   #139
Frost Gate Guardian
 
Eliz Genevieve's Avatar
 
Join Date: Jul 2009
Location: Portugal
Guild: The Archivists' Sanctum [Lore]
Profession: D/
Default

/signed. I've been hacked too, I know what it feels like.
Eliz Genevieve is offline  
Old Dec 10, 2009, 09:29 PM // 21:29   #140
Frost Gate Guardian
 
Join Date: Sep 2009
Guild: Electric Celerity [EC]
Profession: D/A
Default A weakness in NCSoft Security: Password Reset Feature

Through much reading of player responses, I have come to the conclusion that one of the many problems wrong with the NCSoft security system (and the reason why many people are getting their accounts hacked) is the Password Reset Feature.

4 days ago, my account got hacked after using the password reset feature. I changed my password through the NCSoft Master Account system and within 3 hours of me resetting the password, the account belonged to a gold farmer in China.

Another user made a similar post.

"I suspect the same. One of my accounts got hacked right after I'd used the password reset feature. It was the first time I ever used the password reset feature and the first time I ever got hacked. Fortunately, there was nothing in there worth taking at the time." - Olim Chill


So the moral of the story? DO NOT reset your password at this time. Leave it as it is. I figure that the hackers are getting your information via hacking the notifications that are being sent from NCSoft server that the account password was changed.

The hackers are intercepting packets from password changes.
shadowlurk16 is offline  
Closed Thread

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 11:08 AM // 11:08.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("