Massive hack last night Why it must be a bug

Meh there are a million ways. Maybe people used passwords they used in WoW or on some gaming Forum with the same Email or an Emial that is linked somehow to the Email.
Maybe they downloaded Hacks or other Keyloggers in a different game.
Maybe they went to an infected website without noscript.

Who knows. I think its kind of funny though, that in every MMO you have all those "security experts" who got hacked.
Was the same in Diablo 3.



















Last edited by toomuchgas#2510 on Feb 20, 2013, 5:18:38 AM
"
Thyrandor wrote:
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I think there's a point there. What if someone acquired login data over a few weeks' time and just decided to run his thieving script for the last few days?
The next question is: How could this data have been acquired? We can assume it was not a server hack as the amount of accounts hacked (and the subsequent forum shitstorm) would be much higher. Also, if this was the case, some of the top players/ streamers would have been hacked as well, and we would know about it by now. Because using a script implies an automated approach which would not distinguish between casual, hardcore or streaming players.
But where does the login data come from, if not from GGG? It must somehow have been phished, keylogged or whatever? Could it be some program that utilizes a browser backdoor to access our login data in some way? Could it be something "spying" on tools like PoE Helper?
I don't assume everyone who got hacked is a computer noob, so it has to be something that was engineered very carefully, like a really good phishing site.
Any thoughts on this?


Why would you assume anything? That would leave holes unchecked. Not that we can check them but never assume anything when it comes to security.
"Unfortunately, we cannot restore any items lost to theft." Unless you are a well known streamer then we will do anything for you.
"
TheHeffNerr wrote:
"
Thyrandor wrote:
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I think there's a point there. What if someone acquired login data over a few weeks' time and just decided to run his thieving script for the last few days?
The next question is: How could this data have been acquired? We can assume it was not a server hack as the amount of accounts hacked (and the subsequent forum shitstorm) would be much higher. Also, if this was the case, some of the top players/ streamers would have been hacked as well, and we would know about it by now. Because using a script implies an automated approach which would not distinguish between casual, hardcore or streaming players.
But where does the login data come from, if not from GGG? It must somehow have been phished, keylogged or whatever? Could it be some program that utilizes a browser backdoor to access our login data in some way? Could it be something "spying" on tools like PoE Helper?
I don't assume everyone who got hacked is a computer noob, so it has to be something that was engineered very carefully, like a really good phishing site.
Any thoughts on this?


Why would you assume anything? That would leave holes unchecked. Not that we can check them but never assume anything when it comes to security.

Why not? Others assume GGG didn't spend a single dollar on security, which is highly illogical. So I try to use assumptions based on logic to maybe get a bit closer to the truth. Sure, it might have been some sever security breach that is not yet known up until now. But why weren't Kripp or Nugiyen hacked then?
A sword he brought, his foes to maim and rend,
from places dark behind forbidden doors,
But night by night he woke with frighten'd roars
from darkest dreams, too strange to comprehend.
(Anonymous)
Because its hc league and no one basically gives a shit about hc league ? ( dont get me wrong , hc > sc imo ) but still gaming shops doesnt target hc im pretty sure.
And yes, ive lost everything last night.
Last edited by Deziowy#6998 on Feb 20, 2013, 5:29:56 AM
"
Thyrandor wrote:

Why not? Others assume GGG didn't spend a single dollar on security, which is highly illogical.


Alright. List what GGG did to prevent hacking. I'll tell you what I did for myself:

I have a unique non-word/phrase password that isn't found in word databases. I keep everything up to date, I run Avast! and COMODO permanently. My firewall blocks everything that isn't manually added to the exceptions list. I did a full scan with Malwarebytes and Webroot after I discovered I was hacked, both turned perfect results. I never enabled Java since I had this laptop, for almost a year, and I use chrome. I have over a decade of online gaming experience so I know how phishing sites/mails look, and I know to avoid all 3rd party tools unless they are given the OK by the devs themselves, so I don't even bother searching for them. None of my passwords are stored on ANY device. And, naturally, I never downloaded anything remotely suspicious.
"
Thyrandor wrote:

Why would you assume anything? That would leave holes unchecked. Not that we can check them but never assume anything when it comes to security.

Why not? Others assume GGG didn't spend a single dollar on security, which is highly illogical. So I try to use assumptions based on logic to maybe get a bit closer to the truth. Sure, it might have been some sever security breach that is not yet known up until now. But why weren't Kripp or Nugiyen hacked then?[/quote]

Kripp and nugiyen have nothing to do with anything... Hell Kripp and nugiyen also prob use third party searching sites or other sites like that more then any other user on this forum. I don't watch their stream so no idea if they even would. But if they need to find the best shit that would be one of the best ways to do it.
"Unfortunately, we cannot restore any items lost to theft." Unless you are a well known streamer then we will do anything for you.
"
Deziowy wrote:
Because its hc league and no one basically gives a shit about hc league ? ( dont get me wrong , hc > sc imo ) but still gaming shops doesnt target hc im pretty sure.
And yes, ive lost everything last night.


Actualy there is no reason for them not to target them, as they can take all currency/items on a char, kill them and voila items are now in default/softcore
Last edited by Veryll#5635 on Feb 20, 2013, 5:41:24 AM
"
Veryll wrote:
"
Deziowy wrote:
Because its hc league and no one basically gives a shit about hc league ? ( dont get me wrong , hc > sc imo ) but still gaming shops doesnt target hc im pretty sure.
And yes, ive lost everything last night.


Actualy there is no reason for them not to target them, as they can take all currency/items on a char, kill them and voila items are now in default/softcore


Well, there is an easy way to explain why HC isn't targeted ( at least yet).

Look on the trading subforums. How many HC threads do you see? And if you see any, then look at the sc-hc thread ratio.
Well I was on HC, now I have no characters and no moneys ;) So... I'd say they did not differentiate sc and hc.
"
Zalmoxis wrote:
"
Thyrandor wrote:

Why not? Others assume GGG didn't spend a single dollar on security, which is highly illogical.


Alright. List what GGG did to prevent hacking.

I think I don't get what you mean by "security measures". What exactly would you want to see implemented by GGG?
A sword he brought, his foes to maim and rend,
from places dark behind forbidden doors,
But night by night he woke with frighten'd roars
from darkest dreams, too strange to comprehend.
(Anonymous)

Report Forum Post

Report Account:

Report Type

Additional Info