Quote:
|
Originally Posted by Update - Wednesday, December 2, 2009
Bug Fixes
* Fixed a crash bug. * Fixed the URL for requesting a password reset. |
|
Originally Posted by Update - Wednesday, December 2, 2009
Bug Fixes
* Fixed a crash bug. * Fixed the URL for requesting a password reset. |
|
WTB official clarification: can we breathe easier about account theft?
|
|
...and maybe this person figured out how to add something or tweak something in the url to reset (or change) the password to the account of his/her choice.
|
|
This is my suspicion: first symptom of being haxed was that password no longer worked, and only after changing it though plaync, "045, account blocked for your own protection" error displayed.
So, flow looks simple now: Goldseller abuses exploit to get username and reset its password -> Raids account -> support notices it and blocks account -> User finds out password no longer works, resets it and gets block notice upon login. |
|
These are dark times to be playing GW. I really hope that this fixed it, but, if that was the case, why was it something so "simple" to fix? I understand tracking it down would be difficult, but wouldn't things like this (If the account thefts were truly URL based) be something you'd think about in the very beginning when making a site that would involve you previously entering your account information?
|
|
We don't know if there was indeed such a vulnerability or not. But it's a possibility, and that's alarming.
Typical guru response to anyone who has their account compromised is: 1. "Your password wasn't strong enough, or you gave it away" 2. "You use bots or RMT" 3. "You visit dodgy sites" 4. "You have no computer security" And based on 1-4: "its your own fault, and you deserve to lose everything" These mantras are spouted regularly by people who presumably consider themselves invulnerable... and they are therefore either a) naive, b) ignorant or c) plain stupid. Or several of those. Because nothing is 100% secure. No anti-malware is 100% effective. Malware is ever more sophisticated. All OS's have vulnerabilities waiting to found and exploited. Everybody makes mistakes, nobody is infallible. There may be disgruntled or malicious insiders. As users, there are many things which are not under our own control. IMO, the smug people who think they are invulnerable should think again. An exploit such as what is suggested above could happen. Similarly, application or OS exploits could emerge. And if they did - they most certainly wouldn't our own faults for being careless. I hope A-net puts some serious effort into GW2's security. Both to minimise the possibility of attacks, but also to mitigate damage should an exploit emerge regardless. From the outset, there should be stuff like: -Do not require email addresses as logins. -Allow "special characters" in passwords, both in GW2 client and in NCsoft master account -Changing GW2 login password via NCsoft master account, should require you to enter the old password. -Implement the optional use of hardware security tokens for login, like Blizzard's device for WoW. -"character locks" to make characters permanently undeleteable* -optional pin numbers (or the hardware security token) to access an account's in-game storage -track the movements of items traded -etc etc etc *One or two locks should be free with each GW2 account from the beginning (the number of free locks must be less than the number of character slots that come with the account). Every purchase of an extra new character slot should come with a free lock that can be used on any character. Do not allow characters to be locked until they are a certain age or level. This way, people will not be able to lock characters right after installing the game, or creating a new one (which they may regret later); people will always be able to reroll new characters (it's impossible to lock all character slots on an account); people can purchase extra locks if they want them (by buying a new character slot). |