Account Hackings - The Source

Lishy

Lishy

Forge Runner

Join Date: Jan 2008

Damn it NCSoft =(

If only Anet had a better parent company....
Honestly, I don't blame the Guild Wars team for this =/

Angel Kiss

Angel Kiss

Ascalonian Squire

Join Date: Apr 2006

Hello dears, Bunny here (author of the icky sticky thread on Aion Source).

I just wanted to stop by and thank Erys for taking the time to make this thread. To be honest I think you summed it up quite nicely. I particularly like the bit about NCSoft having us "believe that after four years, suddenly thousands of people became infected by a real life stupidity virus and stated dealing with RMT or being keylogged simultaneously". That really sums it up from my perspective. I know for a fact that the past two weeks really has been the highest on record for complaints received about Aion players being hacked. Sure, the first few complaints come in and you think "yeah yeah...serves you right you gold buying scumbag", but after the 100th genuine sounding story you do start to doubt and raise questions.

The thing that bothers me most is the fact that the past two weeks have coincidentally (or not) followed the emergence of the NCSoft Master Account website issue and we haven't recieved a response about this from anyone. I don't think people have appreciated yet that Tamat's first response to the issue was completely out of context. There just so happen to be two issues with NCSoft websites and our Tamat rushed forth assuming we were talking about a different problem (one that actually IS cosmetic).

From reading Gaile's comments it seems to me that she has latched on to Tamat's response and arrived at the same wrong conclusion. In a meek effort to try to steer people in the right direction, I have posted the following on her talk page:
Quote:
Originally Posted by Bunny
In the interest of being helpful, allow me to clarify something for the benefit of Gaile and others.

Originally, via this thread, the player community of Aion were raising an issue regarding the NCSoft Master Account Login Page, where it was discovered that the page has the tendancy to log people into other people's NCSoft Master Accounts at random. When this happens, players are able to assume full control of another persons NCSoft Master Account, and any game accounts they happen to hold. This is not a cosmetic issue, it is a genuine issue that appears to be causing many people to loose control of their NCSoft Master account and game accounts alike.

Initially, when Tamat (Aion Community Manager) saw the complaint thread, in his haste Tamat replied assuming that the complaint referred to another known problem involving the Aion Online website and forums (a different website). The known problem Tamat is referring to is a separate issue. I cannot stress this enough. Players use their Aion Game Account information to login to the Aion Online website in order to check their broker status or their mailbox. This website has a caching issue, which sometimes causes the wrong Aion Game Account name to appear in the greeting at the top of the page. This in fact IS a cosmetic issue, so if tamat had been replying to the correct problem...his reply would have been correct.

What the player community needs is a reply to the original complaint because it will indeed affect Guild Wars and Aion players alike.
Aside from the known issue with the NCSoft Master Account page (as if that isn't enough) much worse accusations have been emerging from the Aion community over the last few days...however I couldn't say how accurate these are first hand (or how long it will be before NCSoft delete posts from the official forums of that nature).

In the meantime all I can do is say keep talking about the issue! Don't stand for this sort of nonesense and don't let it get pushed under the rug. I have it on good authority that there is rather solid evidence of a serious problem here and we all deserve to know what steps are being taken to correct it.

Fay Vert

Desert Nomad

Join Date: Apr 2006

R/

Quote:
Originally Posted by jiggles View Post
I would just like to throw the idea out there that telling every single person possible how to potentially hack GW accounts does not seem like the smartest plan ever...
Except that the predators already know! This is about telling the prey.

How about they switch off completely the whole ability to change passwords, from anywhere, if you want to change your password then go through support.

Anka Yirannes

Anka Yirannes

Ascalonian Squire

Join Date: Nov 2009

Liars Cheats and Thieves. [Liar]

Me/Rt

Thanks Bunny. Nice to see some input.

I, for one, will not rest until the cold hand of justice has laid the smackdown.

(Oh dear, I believe I got a bit ninja'd there.)

Kate Monster

Ascalonian Squire

Join Date: Jan 2009

Illinois

Guardians Of The Veil [VeiL]

E/

I took a bigger step, not screwing around with this account security bs. I crossed this over to the G4TV forums under the MMO report in an effort to find a link to submit an inquiry & request to do a story on this issue. If Anet doesn't want to listen to us..maybe they'll listen to them.

Jaythen Tyradel

Jaythen Tyradel

Jungle Guide

Join Date: Apr 2005

Happy New Years indeed. :/

Jensy

Jensy

Site Contributor

Join Date: Apr 2007

Phoenix, Arizona

Blinkie Ponie Armie [bpa]

N/Mo

This is freaking me out. It's like someone has a million key keychain, and is standing outside your door trying each key >___<

What I would like to see:

1. Ability to unlink accounts. (I'm not holding my breath)
2. Ability to delete old/solved support tickets.
3. Prompt asking for old PW before GW pw can be changed.

It's... really not a lot to ask, right?

Tom Swift

Jungle Guide

Join Date: Aug 2007

Quote:
It's quite easy. Get GW2...don't link it to anything...never let anyone outside of GW2 know your character names and practice the good habit of strong passwords mixed with never using that email or password anywhere else but GW2...unfortunately us GW 1 players only WISH we hadn't made that mistake. We get a fresh start on GW2.
not necessarily - I suspect there will have to be some kind of link if you want your HoM accomplishments to transfer over.

Thankfully I never linked to a master account, never had to file a support ticket and never planned on getting GW2 anyway.

Kerwyn Nasilan

Kerwyn Nasilan

Forge Runner

Join Date: Aug 2007

WHERE DO YOU THINK

W/

Quote:
Originally Posted by Jensy View Post
This is freaking me out. It's like someone has a million key keychain, and is standing outside your door trying each key >___<

What I would like to see:

1. Ability to unlink accounts. (I'm not holding my breath)
2. Ability to delete old/solved support tickets.
3. Prompt asking for old PW before GW pw can be changed.

It's... really not a lot to ask, right?
To much for NCSoft I bet, (I am not going to blame ANet until it is certain that they could/can do something, I will assume their hands are tied.)

Arduin

Arduin

Grotto Attendant

Join Date: May 2005

The Netherlands

Limburgse Jagers [LJ]

R/

http://wiki.guildwars.com/wiki/Feedb...ity_Issue.3 F

Quote:
Originally Posted by Gaile @ Wiki
Thank you for sharing the synopsis, Angel, and for the link, Cress Arvein. I have been working on the MHE (Missing Hat Experience) for Wintersday 2010, and so I was not able to devote my attention to the question as fully as I might have done on a normal day (and certainly on a normal work day). I am discussing this issue with Regina so that we can learn more about the concerns and, of course, address them as quickly as possible. -- Gaile 21:11, 1 January 2010 (UTC)
A confirmation of Anet being aware of the issue.

zelgadissan

zelgadissan

Forge Runner

Join Date: Feb 2008

The Warrior Priests [WP]

Me/Rt

Quote:
Originally Posted by Lishy View Post
If only Anet had a better parent company....
Honestly, I don't blame the Guild Wars team for this =/
Sums up my opinions quite well, in my eyes this is mainly NCSoft. The only blame I lay on the Guild Wars team for this is the complete shutdown that Gaile and Co. have been giving the players, but I'll be honest and say that I have no idea how much connection the ArenaNet support has with NCSoft support. For all I know, her responses might have been forced from the top.

I wonder if ArenaNet could support themselves on their own?

Michael805

Michael805

Frost Gate Guardian

Join Date: Jan 2006

Going Out Of Business Sale [GWII]

A/W

Quote:
Originally Posted by zwei2stein View Post
Anyhow:

If you manage to steal session or to recover session by accident, it means that target account was logged to plaync recently.

So, your protection would be *not* to log in to plaync.
In my case, I hadn't logged into my plaync account for (likely) a year or more, and hadn't logged into gw on any account in at least 6 months, yet my account was hacked. It's not sessions being stolen, it's likely the account ID being altered in some way under server stress (which would explain why it only works by logging in/out several times).

Zinger314

Zinger314

Debbie Downer

Join Date: May 2006

N/Me

Quote:
Originally Posted by Arduin View Post
http://wiki.guildwars.com/wiki/Feedb...ity_Issue.3 F


A confirmation of Anet being aware of the issue.
Hats > Account Security

Duh.

Emperor Bush

Frost Gate Guardian

Join Date: Mar 2007

Pandas of a Thousand Gentlemens or Something [LOD]

I hope everyone who got a festival hat gets their accounts hacked, and the hacker destroys their precious little useless hats.

Gargantuan Midget

Ascalonian Squire

Join Date: May 2007

UK

Architects Of Forgotten Truth

W/

Can someone re-name this thread 'How to hack' I know its an issue that requires discussion but seriously just telling everyone how to do it, unwise in my mind, I'm certain there are some people out there who will take advantage of the information.

gone

Guest

Join Date: Jan 2007

Quote:
Originally Posted by Gargantuan Midget View Post
Can someone re-name this thread 'How to hack' I know its an issue that requires discussion but seriously just telling everyone how to do it, unwise in my mind, I'm certain there are some people out there who will take advantage of the information.
this is far from hacking. FAR from hacking.

HellScreamS

Krytan Explorer

Join Date: Aug 2009

wouldn't you like to know?

^yea KFC just subscribed to me for 1 year^

P/

erm, the ncsoft offi page is lagging like mad atm for me, and I can barely log in to MY account. That makes me think there's a bazilion chinese bots logging in and off already... *takes a painkiller overdose*

fishy go moo

Frost Gate Guardian

Join Date: Apr 2007

Mo/E

I'm semi-pissed. I logged on and was like wtf is this shit. :/ i got a pw reset but they havent given me a freaking email yet

Gargantuan Midget

Ascalonian Squire

Join Date: May 2007

UK

Architects Of Forgotten Truth

W/

Fine it may not be hacking name it 'How to get free accounts' or judging by Gaile's response 'Hats are more important than you account'

Juhanah

Juhanah

Lion's Arch Merchant

Join Date: Apr 2005

in my house

Quote:
Originally Posted by Gargantuan Midget View Post
Can someone re-name this thread 'How to hack' I know its an issue that requires discussion but seriously just telling everyone how to do it, unwise in my mind, I'm certain there are some people out there who will take advantage of the information.
There's no "how to do it". The NCSoft website do it by it self for you or anyone.

If no one know how the bug works, most people wont care. NCSoft will continue deny it, Anet will follow NCSoft judgment, People will still get their account stolen and nothing will ever be done.

Now if the majority of people know it. Yes more account may be stolen but this also mean more people will voice their frustration toward this issue, less people will want to spend their money on NCSoft product and to get it stolen, and NCSoft will look extremely stupid for not fixing it and will loose any bits of credibility and revenue they have left.

genofreek

genofreek

Desert Nomad

Join Date: Jan 2007

USA

Jenova's Apocolyptic Remains [JAR]

D/

Quote:
Originally Posted by Michael805 View Post
In my case, I hadn't logged into my plaync account for (likely) a year or more, and hadn't logged into gw on any account in at least 6 months, yet my account was hacked. It's not sessions being stolen, it's likely the account ID being altered in some way under server stress (which would explain why it only works by logging in/out several times).
Damn, you people need to stop giving me hope and then killing it.

Jaythen Tyradel

Jaythen Tyradel

Jungle Guide

Join Date: Apr 2005

as damaging as this info is, I feel better (albeit not by much, still worried and frustrated by this news) that this has been uncovered NOW instead of after GW2 launch.

Lishy

Lishy

Forge Runner

Join Date: Jan 2008

Screw NCSoft
Anet should use the profits from GW2 to make some awesome offline rpg not limited by the online gameplay Guild Wars has :P
Using an offline game, they would earn more profit than they probably make now due to how much it costs to keep Guild Wars up each month. Once they hit the sky high success, they finally disband from NCSoft and lead there own company, furthering to develop games for the XBOX360 :P

Seraphim Angel

Frost Gate Guardian

Join Date: Nov 2008

Sacred Knights of Orr [SKoO]

P/

Is there a way to un-link your account from thier website?

Stuart444

Stuart444

Krytan Explorer

Join Date: Aug 2007

Alexandria, Scotland

The Charter Vanguard [CV]

W/

Update to the last post by Galie on her wiki:

Quote:
Addendum to my comment above: I do not wish to give the impression that I consider missing holiday hats to be a higher priority than security issues. Anyone who knows me, or thinks about my position, would clearly understand that, for me, hats < security! However, having seen an official response that seemed to dispel the concern -- a response that, in the context made sense to me -- I believed the security concern to have been adequately addressed. I have been researching this at greater depth today, and have sent emails to more than 30 people on a half-dozen teams to alert them to the concern. We'll update when we have more information.

Carinae

Carinae

Forge Runner

Join Date: Jun 2005

Inside

Fifteen Over Fifty [Rare]

The elephant in the room is the fact that we have seen them do a system-wide rollback, character data and all. So they DO have character backup data, definitively.

They simply don't WANT to do it. To be fair, there is some legitimacy in that stance. It would take a lot of manpower, open the door for exploits, and in general be a headache.

However.......They now have a way (at least for this issue) to determine legitimate hacks! Just read their own logs:


LOGIN: Player123
ACCOUNT OPENED: Player648

BINGO -> Rollback Character


You might lose some stuff, depending on the date of the rollback, but hey, better than nothing.

Gargantuan Midget

Ascalonian Squire

Join Date: May 2007

UK

Architects Of Forgotten Truth

W/

Quote:
Originally Posted by Juhanah View Post
There's no "how to do it". The NCSoft website do it by it self for you or anyone.

If no one know how the bug works, most people wont care. NCSoft will continue deny it, Anet will follow NCSoft judgment, People will still get their account stolen and nothing will ever be done.

Now if the majority of people know it. Yes more account may be stolen but this also mean more people will voice their frustration toward this issue, less people will want to spend their money on NCSoft product and to get it stolen, and NCSoft will look extremely stupid for not fixing it and will loose any bits of credibility and revenue they have left.
I do understand this will help I'm not saying its a bad thing at all, I am hugely happy someone in the GW team is taking an interest in it even if it isn't their fault.

I just don't want people to be innocent in thinking this thread will auto save us everyone has been QQing about balancing for months and nothing happened. If the information is even more readily available even if it is on a thread designed to help I just don't think the spike in hacking (or whatever I'm supposed to call it apparently thats wrong) will dissapear as fast as we all want it too.

But I do see what you're saying, a small number more is acceptable if the problem gets solved, for the greater good essentially. I hope you're right and prove me to be wrong I really really do.

zelgadissan

zelgadissan

Forge Runner

Join Date: Feb 2008

The Warrior Priests [WP]

Me/Rt

Quote:
Originally Posted by Seraphim Angel View Post
Is there a way to un-link your account from thier website?
No. Once you're connected to it, it's GG. People have been asking for that ability for quite some time now.

Rhiana Reborn

Rhiana Reborn

Frost Gate Guardian

Join Date: Feb 2009

R/

Well, this sucks. Here's hoping that if I get hacked, they have the decency to not delete my chars. I can reset my password and get my acc back, but I'd hate to have to remake my chars - some of the titles I have were a pain to get.

Also, Please don't expect the Anet team to be at the top of their game - it's the 1st day of the year, and like most of us, they too have offline lives, and I bet that more than one of the people in charge has a hangover bigger than mine.

Happy New Year! (I'd offer you some champagne, but I'm keeping the last bottles for myself. Mmmmmm)

fenix

fenix

Major-General Awesome

Join Date: Aug 2005

Aussie Trolling Crew HQ - Event Organiser and IRC Tiger

Ex Talionis [Law], Trinity of the Ascended [ToA] ????????????????&#

W/

A little delayed, but I can confirm this too.

Was logged into someone elses account on the Aion website the other day...

Fril Estelin

Fril Estelin

So Serious...

Join Date: Jan 2007

London

Nerfs Are [WHAK]

E/

Quote:
Originally Posted by Zinger314 View Post
Hats > Account Security

Duh.
Time to fix Hats problem (bugs) << Time to fix Security problem (trace/logs analysis, vulnerabilities identification and closing, prevention/redesign, risk assessment and mitigation...all this at various infrastructure levels...)

Seraphim Angel

Frost Gate Guardian

Join Date: Nov 2008

Sacred Knights of Orr [SKoO]

P/

Well this is comforting. Its like every time I log on now I'm gonna be like "Hope they didn't get me." I feel like I live in the ghetto and I have to check outside to see if my car is still there.

Edge Igneas

Frost Gate Guardian

Join Date: May 2008

Poland

Quote:
Originally Posted by Seraphim Angel View Post
Well this is comforting. Its like every time I log on now I'm gonna be like "Hope they didn't get me." I feel like I live in the ghetto and I have to check outside to see if my car is still there.
And I feel like the U.S.S.R. just launched nuclear missiles all around the world.

fenix

fenix

Major-General Awesome

Join Date: Aug 2005

Aussie Trolling Crew HQ - Event Organiser and IRC Tiger

Ex Talionis [Law], Trinity of the Ascended [ToA] ????????????????&#

W/

Stickied for importance.

Rhiana Reborn

Rhiana Reborn

Frost Gate Guardian

Join Date: Feb 2009

R/

Were there deleted posts? The thread just went from 11 pages to 10...

Gargantuan Midget

Ascalonian Squire

Join Date: May 2007

UK

Architects Of Forgotten Truth

W/

edit: Apparently my opinion of his intelligence was shared

fenix

fenix

Major-General Awesome

Join Date: Aug 2005

Aussie Trolling Crew HQ - Event Organiser and IRC Tiger

Ex Talionis [Law], Trinity of the Ascended [ToA] ????????????????&#

W/

Quote:
Originally Posted by Rhiana Reborn View Post
Were there deleted posts? The thread just went from 11 pages to 10...
Just the normal cleaning of threads. Hadn't gotten online to see this one yet :P

freedom_razor

Ascalonian Squire

Join Date: Nov 2005

Quote:
Originally Posted by Gargantuan Midget View Post
@ Freedom Razor what are you talking about? Seriously? You actually think if a member of the community finds out how peoples accounts are being stolen they should just sit there and do nothing with that information? Even if everyone at anet and everyone at ncsoft ignore it at least they tried, you're suggesting we just sit here and accept we are going to loose our accounts.
Well, my post has been deleted since [2 of them even], so I can only suppose if I post on that subject any more, I will get banned. I wasn't serious anyway, was just giving the ''advice'' I learned from other, closed by mods, thread about bots in PvP. Of course I think that kind of information should be on public community forums, just as I believe any issues concerning botting in GvG [or game in general] should be open to public discussion on game's forums.

@Fenix: can you spare at least this post? It is an answer to someone else who managed to read one of my previous posts.

Tramp

Tramp

Furnace Stoker

Join Date: Jan 2008

Mo/

I am still confused and no one answered. So the recent additional character name at login is worthless because they glitch or hack into the NCSoft account, then check out your support emails, and get your character name and information there?

I need to know if I should start to dread logging in again, because I was feeling much better when Gaile said that a minority of people who were hacked did not have the NCSoft account, therefore the NCSoft account was not a problem, but now I concerned again.

deluxe

deluxe

Desert Nomad

Join Date: Feb 2006

Monkeyball Z

S.K.A.T. [Ban]

Mo/

Quote:
Originally Posted by fenix View Post
A little delayed, but I can confirm this too.

Was logged into someone elses account on the Aion website the other day...
And that's the cosmetic thing they were talking about, 2 different things.