poe prone to hack???

"
lyravega wrote:
"
TheDarkJack wrote:
Not PoE got hacked, YOU got "hacked".


You fucking dumb? Not everything is a fault of the user.

No, just most things.
"
lyravega wrote:
That many reports at the same time suggests one single thing; PoE got hacked.


No. It suggests at best that some popular community site, or popular hack, or popular RMT site got hacked or got re-purposed to do some XSS or some drive-by downloading.
I think your tinfoil hat is on too tight homeboy.
Closed beta member since: March 19, 2012
so much denial...

"
It suggests at best that some popular community site, or popular hack, or popular RMT site got hacked or got re-purposed to do some XSS or some drive-by downloading.


+1
Casual Exile.

"
We've deployed the 0.10.1d patch which adds several security features. Many users have been arriving at Path of Exile pre-compromised because their usernames/passwords are on giant lists that are leaked from other games or websites in the past. The changes in today's patch will mean that people from remote locations can not log into your account even if they have the password. We're planning to add plenty more security features so that users can opt to make it harsher (limiting it to a specific IP rather than city) or even disable it if they have confidence they can keep their password safe. Please choose unique passwords for Path of Exile that are not the same as passwords you have used for other services. Read on for more explanation about our security policies.

Because the stolen items were being sold by RMT sites, these changes help constrain their supply of items. We're continuing the aggressive bans on their IPs, mule accounts and spam accounts.

The first security feature introduced today is that saved passwords only work from the IP that they were saved on. Some users have commented that they want the saved passwords to work from any IP, so we're considering allowing that as an option if the user wants to risk their account for this convenience.

The second feature is a much more important one - accounts become locked if someone logs into them from a different city. An unlock code, which is sent to the account's registered email address, is required to unlock the account. If you get this email when you haven't logged in from a remote location then you should change your password immediately and investigate how someone learned your password (scan for malware, etc).

Users have commented that they'd like to change "city" to "country" or "exact IP". We'll see what we can do about adding these as options in the near future. We wanted to get the feature in so that users are protected as soon as possible, which is why we picked "city".

Some games have a policy of restoring the items on an account if the user lost their password and someone else took the items. We can't do this because either of the two policies would be devastating to Path of Exile:
a) If we restore the items in a way that duplicates them then users are able to arbitrarily copy their items by presenting a plausible looking case to our support department. This is actively abused in other games and their playerbases know that they can duplicate items at will through customer support.
b) If we restore the items, removing them from the people who got them, then users are able to tradehack each other by performing trades and then requesting that support restore their items. This would undermine the entire trust in the trade community because items could vanish at any time after you receive them in trade.

As you can see, both of these options are completely unacceptable. If we perform restorations then the incentive to report fake compromises is even higher. If users know that other people are having success at duplicating or tradehacking items by claiming they were hacked, then the amount of fake claims would skyrocket. We're already seeing very suspicious claims and that's with our existing no-restoration policies.

We're a small company and only have 8 customer support staff at the moment. To handle even 1% of our customer base claiming fraudulent compromises that need to be sufficiently investigated would take hundreds of support staff.

The policy of no restoration for password loss is there because:
a) All the restoration options destroy the game by letting users duplicate or tradehack items through fake claims.
b) It's completely impossible to sufficiently investigate such claims, especially if users were incentivised to make them. It's very easy to use proxies to make a fake claim look exactly like a real theft.
c) The password losses are due to users losing their passwords. The most common reason is they used the same password with another game or service. We can help with this by adding security measures like the ones added today. We cannot take responsibility for your own password security.

I'd really love to be able to help users who have lost all their items and hard work, but I just can't see a plausible solution that doesn't have the absolutely devastating consequences that restoration does. It's a really tough situation to be in, but the plan of improving user password protection and keeping the game economy intact is the only future we can allow Path of Exile to have.

I am very sorry that we didn't have account lockout features earlier. We got them in as quickly as we could and it required a lot of late nights. We plan to devote substantial effort in the future to more features that help keep users safe even if their passwords are already compromised.

Thankfully, things on the security front look great now that the location locking is in place. This will both help attack RMT and also keep your items safe from intruders. Thanks again for your patience and I look forward to seeing you in-game.
“Too often we underestimate the power of a touch, a smile, a kind word, a listening ear, an honest compliment, or the smallest act of caring, all of which have the potential to turn a life around.”
—Leo Buscaglia


Contact support@grindinggear.com to report issues relating to the game or forum. Thanks!

My beloved pets....
This is D3 all over again. I wonder how long it will take until the first IT expert with 10+ years experience gets hacked.
This happened to me on D3 - which was the ONLY game that used the password I had for it and in and in all my years on the internet, I was never hacked until then. Wasn't using hacks/bots/visiting hacking websites/etc (though I can't deny pr0n :P). Blizzard kept saying it was using the same password on another site which was complete BS.

So far no issues with PoE - again only place I use this password. Really like the idea of the new patch, I hope it solves the issues of ppl being hacked. Hopefully you guys aren't using the same password as your email account.
"
TheDarkJack wrote:
no you need to do something about it. get a stronger password, scan your system for malware, stop browsing pr0n sites.
Not PoE got hacked, YOU got "hacked". I'm now playing online games for nearly a decade and never ever was an account of mine compromised. People tend to claim that it's not their fault while in fact it was. But would you admit that you caught a virus while looking for some nasty things on the interwebz that lead to your account beeing compromised? I wouldn't.

edit: It's the same thing with bots and hacks. Even in counterstrike people cheat, get banned and claim they got hacked. Or in Diablo 3 and LootAlert. No one ever got banned for LootAlert. All of those got banned for botting.

This is why iPads are so good for viewing pr0n. Not sure what else they're good for though...
"
Redtag wrote:
This is D3 all over again. I wonder how long it will take until the first IT expert with 10+ years experience gets hacked.



lol was going to say this
I'm an IT expert with over 10 years experience and I haven't been hacked.... yet anyway :)
Nothing to see here.
"
ReZar wrote:
I'm an IT expert with over 10 years experience and I haven't been hacked.... yet anyway :)


QFT

be safe where you browse, and stop using your birthday as your password lol

Mine is currently between 8-13 characters long, alpha/numeric/special sign, and in a foreign (to me) language
Last edited by Axtrixis#0238 on Feb 22, 2013, 11:30:27 AM
"
ReZar wrote:
I'm an IT expert with over 10 years experience and I haven't been hacked.... yet anyway :)


liar thats impossible tell me your secret master is it superior intelligence common sense

TELL IT
https://poe-ssf.herokuapp.com/. Join the fun.
SSF HC Legacy Witch Lvl 53

Report Forum Post

Report Account:

Report Type

Additional Info