1. While I certainly welcome the addition of needing the old GW password to change the GW password on the NCSoft site, we're not out of the woods yet. If Mung is correct, the NCSoft site is still vulnerable to SQL injection and file mirroring -- either of which alone is sufficient to extract that bit of info from the NCSoft site.
Also,
and a-net should pay attention here either of those vectors could leave the attacker with a list of GW usernames and passwords
without needing to do a password reset. Sound familiar?
2. I want to reverse my position from several pages back. It appears that a-net is making some headway in getting NCSoft to at least take some action on this issue. So long as you believe you can get them to come around and adequately secure their site, I can understand the decision not to fix this from the GW side and face the consequences for insubordination.
3. Re: About 50% of the hacked accounts weren't linked to NCSoft.
We've been over this a dozen times. The flaw in the logic here has been pointed out repeatedly. It may be true, but it does not support the proposition that the NCMA is secure. And yet both Gaile and Regina keep repeating this. What's more, they've each posted something indicating that they understand how the logic is flawed. And they still keep repeating it. Why?
My guess is that NCSoft told them this statistic is the official cover story that they must repeat to defend the company. That's the best way I can explain two rather intelligent people, who appear to understand what's wrong with the argument, nonetheless repeating it over and over.
4. I can answer a couple of your questions, DragonRogue.
Quote:
Originally Posted by DragonRogue
But i am curious about something. What are you doing to the actual hackers?
|
Nothing. The hackers generally don't own the accounts they use. Those accounts get a temp ban, which is lifted when the true owner contacts support. I'm sure if a-net was able to find accounts owned by hackers, those would be perma banned before you could say "bye bye." I'm sure they'd also love to involve law enforcement, but the hackers tend to operate from China and other southeast Asian countries that don't much care to cooperate on matters like this.
Quote:
Also, you say the hackers have a LIST OF PWs? From where have these been obtained?
|
A-net says that a fansite was compromised. I have no reason to doubt them. Also, a couple of forum members here whom I trust have hinted they know which site it was. Anyone who was foolish enough to reuse the same username or password on that forum as on GW is in trouble.
Also, if the NCMA has the SQL injection and file mirroring vulnerabilities it's claimed to have, a list of login credentials could come from there as well.
5.
Quote:
Originally Posted by Inde
I'll pop in here. My words don't mean any more than the next poster, but you all must understand that ArenaNet is listening and taking action... I can clearly see that ArenaNet is pushing. They are fighting... ArenaNet, while they might be fighting the bureaucracy of the big corporate giant, is certainly making progress.
|
Yes, I believe they are. And I applaud them for it. I truly hope they succeed, both for our sake and theirs.
Quote:
On the same note, I do have to give thanks to not only this community but the Aionsource.com community who both seem to be fighting so hard to see that their accounts are protected. Is it because of us these security updates have happened? I think we can say with some degree of certainty that yes, yes it has.
|
I agree. And I applaud them too.
Quote:
Originally Posted by Lucci_Slevin
I think this one is a false alarm.
|
OK, your comments have reached the point where I have to ask: idiot or troll? Seriously, there were several posts on the Aion forums confirming the bug; there were posts in
this thread confirming the bug (and then even more after you posted); and you could have tested it yourself if you really felt like doubting all those people's honesty. So, what's your deal? Too dumb to read before you post or just trolling us all? Given that I can't recall reading a single post from you before this issue cropped up, I'm suspecting troll.