Massive hack last night Why it must be a bug

I would put it that way, every developer of any kind of software that uses passwords and stuff should assume that their clients are morons, have passwords like 12345 e.t.c. and provide some protection to them, like bind to ip, some sort of 2 factor authentication or support that can revert changes made by hackers. If you dont do that, you loose clients/money and well generate not that good of a buzz around you. So yes, it's partly players fault, since I'm pretty sure I had the password since closed beta and it might have been the same that was used on Origin that got hacked a while back (since password was pretty complex : upper and lower case letters and numbers, it must have been leaked somewhere, or login session intercepted somehow e.t.c.). I accept that I might be partly at fault here, but devs are too.
Last edited by Hotcooler#5777 on Feb 20, 2013, 6:35:07 AM
"
Hotcooler wrote:
I would put it that way, every developer of any kind of software that uses passwords and stuff should assume that their clients are morons, have passwords like 12345 e.t.c. and provide some protection to them, like bind to ip, some sort of 2 factor authentication or support that can revert changes made by hackers. If you dont do that, you loose clients/money and well generate not that good of a buzz around you. So yes, it's partly players fault, since I'm pretty sure I had the password since closed beta and it might have been the same that was used on Origin that got hacked a while back (since password was pretty complex : upper and lower case letters and numbers, it must have been leaked somewhere, or login session intercepted somehow e.t.c.). I accept that I might be partly at fault here, but devs are too.


That's pretty much the only leg you have to stand on. You can say it's bad planning that they don't have two factor authentication set up, or the email system they are implementing, but it is still the users fault in the end.

The game is in open beta, there are going to be problems. They are developing a way that should be out end of Feb to help people like you guys secure your accounts. After it's released, it just means anyone who gets hacked has a compromised email as well.
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I'm gonna throw this out there too, hacking is not the same as theft.

I'm also going to say Chris was right about everything. He said hundreds of passwords were stolen from users, not the servers, and it's a small drop in the bucket targeting random people instead of the top percentage of wealthy players.

You don't really know if or how you've been compromised, while it's actually Chris' job to be able to prove that he hasn't.


If they have any brain at all they will leave any famous people alone.


Why?

Because, unfortunately, we are second class players. It's good eh, we usually don't spend too much money and our chance to get other players is so minimal compared to the streamers.


If they hack Nugi/Kripp i'm unfortunately sure that GGG would instantly fix this problem and roll back. If the streamers quit they lose too many potentials new clients.

And if people stop playing why would you bother scamming items that you cannot sell?
Well almost like 10 hours ago i disconnected and when i connected now i almost had a heart atack and panic , all my fking orbbs and my good orange items GONE WTF IS GOING ON ??? HERE i lost 3 days of my life for nothing i reformated my pc and change my passwords and email`s as fast as i can but i wont play this game anymore until some one explain how the hell is possible to do that security BREACK !
"
Daiug wrote:
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I'm gonna throw this out there too, hacking is not the same as theft.

I'm also going to say Chris was right about everything. He said hundreds of passwords were stolen from users, not the servers, and it's a small drop in the bucket targeting random people instead of the top percentage of wealthy players.

You don't really know if or how you've been compromised, while it's actually Chris' job to be able to prove that he hasn't.


If they have any brain at all they will leave any famous people alone.


Why?

Because, unfortunately, we are second class players. It's good eh, we usually don't spend too much money and our chance to get other players is so minimal compared to the streamers.


If they hack Nugi/Kripp i'm unfortunately sure that GGG would instantly fix this problem and roll back. If the streamers quit they lose too many potentials new clients.

And if people stop playing why would you bother scamming items that you cannot sell?


This is silly and terrible logic. The reason they don't get hacked is because they have secure systems.
"
Lask001 wrote:
"
Daiug wrote:
"
ionface wrote:
I'm just gonna throw this out there, what if some unscrupulous orb farming company in some part of China got a list of credentials, then began to use them last night?

I'm gonna throw this out there too, hacking is not the same as theft.

I'm also going to say Chris was right about everything. He said hundreds of passwords were stolen from users, not the servers, and it's a small drop in the bucket targeting random people instead of the top percentage of wealthy players.

You don't really know if or how you've been compromised, while it's actually Chris' job to be able to prove that he hasn't.


If they have any brain at all they will leave any famous people alone.


Why?

Because, unfortunately, we are second class players. It's good eh, we usually don't spend too much money and our chance to get other players is so minimal compared to the streamers.


If they hack Nugi/Kripp i'm unfortunately sure that GGG would instantly fix this problem and roll back. If the streamers quit they lose too many potentials new clients.

And if people stop playing why would you bother scamming items that you cannot sell?


This is silly and terrible logic. The reason they don't get hacked is because they have secure systems.


Are you friend with any of them?

Do you have any details of their specs, password or anything?


Let me predict you. No.


So, how can you say that?
Easy - Chris has stated on that their have been no compromises - this leaves the user. The user is always the weak point, you don't just assume they are good because you haven't found the issue. I'm not saying it's 100% impossible that GGG was hacked, but it's extremely unlikely.
Impossible man GGG have been compromised , look around u how many players have been hacked ???
I lost all my crafting mats, maybe an item or gem or two (can't remember what I had, but most is there). They left several stacks of Scrolls of Wisdom behind in my stash.

It happened between logging off minutes before the server restart, and logging back in minutes after. When I logged in, I noticed a friend online who I'd not received an invite for, a Chinese name (I noticed because I only have one person in my friend list). I unfriended him, then noticed my mats were gone.
"
gnerex2 wrote:
Impossible man GGG have been compromised , look around u how many players have been hacked ???


Extremely small percentage of the player base. When you have a million + players it's easy to find lots of victims.

Report Forum Post

Report Account:

Report Type

Additional Info