Fed up with account "security"
3 pages • Page 3
If what some people claim is true then there may be potential security issues with NCsoft and I wouldn't put it past them to lie about it so they dont lose customers. Maybe they cannot fix these security issues, NCsoft already can't do a lot of things because of the way they built their systems. All I have to say is if it is true I better not hear anything about it because I will never buy another arena net or NCsoft product. Not even GW2.
g
Quote:
|
It does make you want to "hack" those people doesn't it.
@Yol:The issue is that you weren't able to change the pass in the past, that's where some of the confusion is coming from. |
I recon someone calling support with I cannot access my account and think its been hacked.
Was last online yesterday my old email address is **** character name ***** live in this country bought the game 2 years ago etc.
Then they are on the way to convincing support to give them access to the account.
Seemingly innocent chat in the game could lead to someone gaining a surprising amount of information about you.
I hope I am wrong.
K
Quote:
|
95% of problems are because of the user. Absolutely no one is getting their password randomly guessed unless you used 12345/password/etc.
|
I always thought people just had bad security or terrible password too, it's not the case.
Very true. I actually work in IS and deal with password breaches on a regular basis. Most issues are PEBCAK (problem between chair and keyboard) or ID-10-T errors. Phishing emails, questionable applications with trojans and keyloggers, and very simple passwords (1234/password). while minimum requirements do help prevent some of this, nothing ANYONE does will stop them from breaking into your account if you GIVE THEM the password.
However, when there is something where the inner workings aren't transparent, its very easy for the people in charge to deny any responsibility.
X
Quote:
|
Actually, I just changed mine via gw to check, and it worked. So either you two are spreading misinformation, or the effects of licking accounts isn't consistent.
|
A consintancy could have very well been a possibility since there was someone in an alliance I was in before who had "Guild Wars" in their name. Now that has been blocked for years, but obviously at one point you could put that in your name. Though character name has nothing to do with changing your password, It's only an example.
Yes, one numeral certainly makes brute-forcing easier versus adding symbols, numerals, umlauts, etc. however, without a character name and e-mail they certainly won't do too much. Learn something about odds of chance. I don't see the point in this thread. If you're account hasn't been stolen, why are you complaining? I guarentee there are many trying to use a bot and someone that posted it said don't worry if the archive shows up as virus, it's a "false-positive" then wonder why their account was stolen. If you type your e-mail, password, and character name every time there is another good indication of jeopardizing security. If you really care about the account, never physically type the e-mail and character name, simple as that.
Quote:
|
Just a suggestion, but it would help boost your account securities if you created an exclusive email account just for your GW and NCSoft logins. That way they cannot brute force your password since they don't know your email OR ncsoft login!
|

L
Quote:
|
Seemingly innocent chat in the game could lead to someone gaining a surprising amount of information about you.
I hope I am wrong. |
Quote:
|
That's how everyone thinks UNTIL they get hacked themselves.
I always thought people just had bad security or terrible password too, it's not the case. |
Already done but thanks for the suggestions for others you haven't thought about that.
K
Its flat out impossible to have your password randomly guessed. There is a delay between password attempts that grows the more you try. It would take years (potentially decades/centuries/till the heat death of the universe, I have no idea how high the delay grows) to try just the numbers 00000-99999 without any other characters at all.
Quote:
|
Its flat out impossible to have your password guessed. There is a delay between password attempts that grows the more you try. It would take years (potentially decades/centuries, I have no idea how high the delay grows) to try just the numbers 00000-99999 without any other characters at all.
|
X
Then it's really nobody's fault if that is true, I guess Anet could have followed suit like other MMOs and made an aunthenticator, but I would hate to have to type a code in every time I log in.
Quote:
|
I think all these account hacks have very little to do with brute force password cracking, but some kind of bug in the ncsoft website.
My account got hacked, my password got changed... How in gods name is it possible to change a password without me getting a confirmation email about it? |
End
Forge Runner
LF guild that teaches MTSC (did it long ago before gw2 came out and I quit...but I barely remember)
N/A
Joined Jan 2008
If you mean the master account page its after 5 or so tries and lasts i think 10 minutes but im not sure.
g
Its probably not a serious security problem But the hom calculator could be used to judge a characters material wealth.
You can enter any character name not just your own and see how well they are doing.
Anyway I am doing the best I can to prevent being hacked, antivirus antispyware and firewall all in place.
Running on a user account so if I am hacked they do not get full control of my computer.
Internet browser is fairly secure with active x and javascript not automatically turned on for every site.
Popup and adware blocked.
Don't ever click on links from emails or on websites unless I am certain of their origin.
Password is random not a name or birthday etc and the login email hasnt been valid for years.
Hopefully potential hackers will look for easier targets, anything that could be added is in the hom anyway.
You can enter any character name not just your own and see how well they are doing.
Anyway I am doing the best I can to prevent being hacked, antivirus antispyware and firewall all in place.
Running on a user account so if I am hacked they do not get full control of my computer.
Internet browser is fairly secure with active x and javascript not automatically turned on for every site.
Popup and adware blocked.
Don't ever click on links from emails or on websites unless I am certain of their origin.
Password is random not a name or birthday etc and the login email hasnt been valid for years.
Hopefully potential hackers will look for easier targets, anything that could be added is in the hom anyway.
When I play Aion they have added a pin code to the game, and it can only be clicked by using the mouse button. It seems way better than the current system that is out there. I don't know how secure it is but still a better solution than the current implementation they added.
NCMA still needs to be more secured, and NCSoft still needs to adress their security flaws.
NCMA still needs to be more secured, and NCSoft still needs to adress their security flaws.

