Update - Wednesday, December 2, 2009

4 pages Page 1
C
Chthon
Grotto Attendant
#1
Quote:
Originally Posted by Update - Wednesday, December 2, 2009
Bug Fixes

* Fixed a crash bug.
* Fixed the URL for requesting a password reset.
Second one is interesting. Either it wasn't functioning properly (which I think we would have heard about in the Bugs forum) or it had a security vulnerability. If it's the later, I guess the rash of account thefts is over now. However, it would sadden me that a vulnerability that every game programmer should remember from the days of D2 somehow made it into GW. WTB official clarification: can we breathe easier about account theft?
Hyperventilate
Hyperventilate
Krytan Explorer
#2
Quote:
Originally Posted by Chthon View Post
WTB official clarification: can we breathe easier about account theft?
This, pl0x.

These are dark times to be playing GW. I really hope that this fixed it, but, if that was the case, why was it something so "simple" to fix? I understand tracking it down would be difficult, but wouldn't things like this (If the account thefts were truly URL based) be something you'd think about in the very beginning when making a site that would involve you previously entering your account information?


I'd like to know what the fix was, really. Whether it was because of these thefts or not. This update was a tad suspicious.
sickle of carnage
sickle of carnage
Wilds Pathfinder
#3
Quote:
* Fixed the URL for requesting a password reset.
Sounds like accounts were being stolen over a URL..
l
lejimmtohy
Ascalonian Squire
#4
Hey no offense to all of these bug updates but really, when are the skill updates rolling in?
sickle of carnage
sickle of carnage
Wilds Pathfinder
#5
Quote:
Originally Posted by lejimmtohy View Post
Hey no offense to all of these bug updates but really, when are the skill updates rolling in?
Usually first monday of the month..
Hyperventilate
Hyperventilate
Krytan Explorer
#6
Quote:
Originally Posted by lejimmtohy View Post
Hey no offense to all of these bug updates but really, when are the skill updates rolling in?

Personally, I want them to get these account thefts fixed first before they devote their time to skill balances. Seems like the much more serious of the two issues.
zwei2stein
zwei2stein
Grotto Attendant
#7
Quote:
Originally Posted by Chthon View Post
If it's the later, I guess the rash of account thefts is over now.
That would explain a LOT, and make people feel secure once again, indeed.
B
Bob Slydell
Forge Runner
#8
I too was a little suspicious with the URL thing. I wonder if that really was it, you know? It is possible someone may have been into a little bit of URL tweaking (since there are lots of sites that if you tweak the URL enough you can get where you shouldn't be) and maybe this person figured out how to add something or tweak something in the url to reset (or change) the password to the account of his/her choice. And it only takes one person to figure it out, spread the word and crazy stuff starts happening.

If the "i r got haxed" threads actually stop flowing in I will be shocked.
zwei2stein
zwei2stein
Grotto Attendant
#9
Quote:
Originally Posted by Chrisworld View Post
...and maybe this person figured out how to add something or tweak something in the url to reset (or change) the password to the account of his/her choice.
This is my suspicion: first symptom of being haxed was that password no longer worked, and only after changing it though plaync, "045, account blocked for your own protection" error displayed.

So, flow looks simple now:

Goldseller abuses exploit to get username and reset its password -> Raids account -> support notices it and blocks account -> User finds out password no longer works, resets it and gets block notice upon login.
B
Bob Slydell
Forge Runner
#10
Quote:
Originally Posted by zwei2stein View Post
This is my suspicion: first symptom of being haxed was that password no longer worked, and only after changing it though plaync, "045, account blocked for your own protection" error displayed.

So, flow looks simple now:

Goldseller abuses exploit to get username and reset its password -> Raids account -> support notices it and blocks account -> User finds out password no longer works, resets it and gets block notice upon login.
As an example of how easy it might have been (of course assuming this WAS what the update fixed) would be to go up to this post now and change the last numbers to whatever you want as a way to go back to other threads, older threads..etc.. so the password reset URL may have been similar, only the "hacker" needed to simply change the number (or whatever the value was) and bam, he succeeded.
Fril Estelin
Fril Estelin
So Serious...
#11
Quote:
Originally Posted by Hyperventilate View Post
These are dark times to be playing GW. I really hope that this fixed it, but, if that was the case, why was it something so "simple" to fix? I understand tracking it down would be difficult, but wouldn't things like this (If the account thefts were truly URL based) be something you'd think about in the very beginning when making a site that would involve you previously entering your account information?
Well it depends on a number of things that we have absolutely no idea about. I can show you security bugs that got fixed and looked ridiculously "easy" from the user point of view but are hard to pinpoint during the security analysis, due to the way the software is organised (the web can be a messy place to code, in particular due to the complex frontend languages and the need to link a backend to other software).

I'm not convinced that the patched vulnerability was simple to use to hack an account, or else a hacker would have used it much more heavily (for a short period of time) and I suspect we would have had much more than the high number of hack reports we had here.
Bristlebane
Bristlebane
Desert Nomad
#12
I did click that Password retrieval URL after my account had been hijacked, and ALL it did was take you to NCSOFT. So I'm 100% sure that it couldn't have been used for stealing accounts, it just didn't take you to any specific page for retrieving your password.

Although it's fun to read all the conspiracy theories you guys come up with, thirty for blood ;-)
R
Riot Narita
Desert Nomad
#13
We don't know if there was indeed such a vulnerability or not. But it's a possibility, and that's alarming.

Typical guru response to anyone who has their account compromised is:
1. "Your password wasn't strong enough, or you gave it away"
2. "You use bots or RMT"
3. "You visit dodgy sites"
4. "You have no computer security"

And based on 1-4: "its your own fault, and you deserve to lose everything"

These mantras are spouted regularly by people who presumably consider themselves invulnerable... and they are therefore either a) naive, b) ignorant or c) plain stupid. Or several of those.

Because nothing is 100% secure. No anti-malware is 100% effective. Malware is ever more sophisticated. All OS's have vulnerabilities waiting to found and exploited. Everybody makes mistakes, nobody is infallible. There may be disgruntled or malicious insiders. As users, there are many things which are not under our own control.

IMO, the smug people who think they are invulnerable should think again. An exploit such as what is suggested above could happen. Similarly, application or OS exploits could emerge. And if they did - they most certainly wouldn't our own faults for being careless.

I hope A-net puts some serious effort into GW2's security. Both to minimise the possibility of attacks, but also to mitigate damage should an exploit emerge regardless. From the outset, there should be stuff like:

-Do not require email addresses as logins.
-Allow "special characters" in passwords, both in GW2 client and in NCsoft master account
-Changing GW2 login password via NCsoft master account, should require you to enter the old password.
-Implement the optional use of hardware security tokens for login, like Blizzard's device for WoW.
-"character locks" to make characters permanently undeleteable*
-optional pin numbers (or the hardware security token) to access an account's in-game storage
-track the movements of items traded
-etc etc etc

*One or two locks should be free with each GW2 account from the beginning (the number of free locks must be less than the number of character slots that come with the account). Every purchase of an extra new character slot should come with a free lock that can be used on any character. Do not allow characters to be locked until they are a certain age or level.

This way, people will not be able to lock characters right after installing the game, or creating a new one (which they may regret later); people will always be able to reroll new characters (it's impossible to lock all character slots on an account); people can purchase extra locks if they want them (by buying a new character slot).
Mr.H.Mishima
Mr.H.Mishima
Lion's Arch Merchant
#14
Since when didn't they allow special characters in passwords?
tasha
tasha
Auctions Mod
#15
I wouldn't expect NCSoft to ever change their security procedures. They're appalling but since there's little financial benefit to them upgrading them, I don't expect them to ever improve.
zwei2stein
zwei2stein
Grotto Attendant
#16
Quote:
Originally Posted by Hells Last Survivor View Post
Since when didn't they allow special characters in passwords?
I was not able to put ěščřžýáíéúůö in my password nor ♠ or • (wait, WHAt, his password is 056056136246040022418340 ?! ... how come it does not work)
A
Aleta
Frost Gate Guardian
#17
And I'm just as sure this is how they were hacked. How come my EQ2 account was safe my other game accounts safe? Just GW was hacked.

I hope it's over but it was on their end and they should give back the stuff stolen. I know in certain instances Sony has done that.
AngelWJedi
AngelWJedi
Furnace Stoker
#18
Quote:
Originally Posted by Hissy View Post
We don't know if there was indeed such a vulnerability or not. But it's a possibility, and that's alarming.

Typical guru response to anyone who has their account compromised is:
1. "Your password wasn't strong enough, or you gave it away"
2. "You use bots or RMT"
3. "You visit dodgy sites"
4. "You have no computer security"

And based on 1-4: "its your own fault, and you deserve to lose everything"

These mantras are spouted regularly by people who presumably consider themselves invulnerable... and they are therefore either a) naive, b) ignorant or c) plain stupid. Or several of those.

Because nothing is 100% secure. No anti-malware is 100% effective. Malware is ever more sophisticated. All OS's have vulnerabilities waiting to found and exploited. Everybody makes mistakes, nobody is infallible. There may be disgruntled or malicious insiders. As users, there are many things which are not under our own control.

IMO, the smug people who think they are invulnerable should think again. An exploit such as what is suggested above could happen. Similarly, application or OS exploits could emerge. And if they did - they most certainly wouldn't our own faults for being careless.

I hope A-net puts some serious effort into GW2's security. Both to minimise the possibility of attacks, but also to mitigate damage should an exploit emerge regardless. From the outset, there should be stuff like:

-Do not require email addresses as logins.
-Allow "special characters" in passwords, both in GW2 client and in NCsoft master account
-Changing GW2 login password via NCsoft master account, should require you to enter the old password.
-Implement the optional use of hardware security tokens for login, like Blizzard's device for WoW.
-"character locks" to make characters permanently undeleteable*
-optional pin numbers (or the hardware security token) to access an account's in-game storage
-track the movements of items traded
-etc etc etc

*One or two locks should be free with each GW2 account from the beginning (the number of free locks must be less than the number of character slots that come with the account). Every purchase of an extra new character slot should come with a free lock that can be used on any character. Do not allow characters to be locked until they are a certain age or level.

This way, people will not be able to lock characters right after installing the game, or creating a new one (which they may regret later); people will always be able to reroll new characters (it's impossible to lock all character slots on an account); people can purchase extra locks if they want them (by buying a new character slot).
i agree with everything except the password thing. did we forget about the storage pain crap? how a ton of us couldnt remember our old passwords or when we did it didnt work? umm yea lets not go down that road. and this makes me wonder if that just now notice this url thing worries about how secure GW2 will be. I would hate to spend like 50$ or more only to loose it a week later. come on regina,martin or anyone else. lets hear your take on it. that is if you have one.
Z
Zahr Dalsk
Grotto Attendant
#19
Quote:
Originally Posted by Chthon View Post
If it's the later, I guess the rash of account thefts is over now.
Given that account theft is due to stupid people not protecting their computer, or revealing their account email and/or password, I'm not sure why this would stop it.
n
nitetime
Krytan Explorer
#20
^omg, go away. how many times do we have to discuss it?^

Quote:
Originally Posted by Chthon View Post
WTB official clarification: can we breathe easier about account theft?
This and should we change our passwords now? or not ever change them again??