GSU Team's Message About Account Security

5 pages Page 1
Regina Buenaobra
Regina Buenaobra
ArenaNet
#1
NCsoft has published a message from our Game Surveillance Unit today, regarding account security. For the full message, please go to the NCsoft web site.
Introverted Dimensions
Introverted Dimensions
Wilds Pathfinder
#2
Very helpful, Thank you!
Cale Roughstar
Cale Roughstar
Desert Nomad
#3
Just a few things.

Quote:
Many of you have noticed the decrease in bots, farmers, and gold spammers as a result of our efforts
Really? I would hate to see how bad things would be if there were any less effort.


Quote:
Despite the fact that this report occurred over the holidays, when the majority of NCsoft employees were home with their families, our security team responded immediately with a point-by-point testing and analysis of the erroneous concerns that were raised. As a result of the point-by-point testing and analysis, our security team concluded no critical vulnerabilities had been demonstrated or identified, but our security team continues to research, to monitor closely, and to implement security improvements to address any potential weaknesses raised.
Are you serious? That sounds like a complete denial that anything went wrong on NCSoft's part. The rest of the article is the usual BS telling us how we shouldnt be stupid. Come on, was I just imagining the thread where people were saying that it was possible to get into someone else's NCSoft master account through accidental redirects?
Shayne Hawke
Shayne Hawke
Departed from Tyria
#4
Quote:
For example, a thread on a third-party Guild Wars forum this New Year's attracted a good deal of attention. It detailed a list of security vulnerabilities that supposedly had been discovered on our account website, ending with the alarmist note that "the only responsible thing NCsoft can do is to shut off their website, as soon as possible."
ANet and NCsoft are paying attention to us, Guruers. Make no mistake.

@Regina: I would like more of the community to have easy access and awareness to this. Is there any chance that a link to this report could become available at the log-in screen to the game?
HawkofStorms
HawkofStorms
Hall Hero
#5
Cale, that part really isn't directed at GW (which doesn't have a large gold farmer/botter population anyways every since 55 stoped being the most effective farming builds). That post is more in reference to Aion, which has had a good drop in gold spammers (partly due to their filter). Gold sellers aren't going to buy 3 games to get the builds and be able to do the runs that make them even with real players. It's not a problem in GW AT all compared to most other MMOs. We have bots, but they are run by private individuals for achievements like PvP. We do not have a large scale gold seller/botting problem. Which is a far worse situation as it causes inflation and is a major source of account theft.


And nice find Shayne Hawke. I've found quite a few posts in other NCSoft game forums (CoX, Aion) saying how "well, NCSoft blows, but at least A.net was able to fix the problem." A.net is getting some good PR for being the responsible part of the company. Although, really, it was guru that found and helped fix most of those vulnerabilities. Give yourself a pat on the back guru community.

Edit: Recanting the second paragraph. Only glanced at the statement for 10 seconds before going to work. I now realize what a slap in the face it is.
Kattar
Kattar
EXCESSIVE FLUTTERCUSSING
#6
Quote:
It detailed a list of security vulnerabilities that supposedly had been discovered on our account website, ending with the alarmist note that "the only responsible thing NCsoft can do is to shut off their website, as soon as possible.
Umm, I'm pretty sure they're brushing off anything we mentioned as nothing of value.

Relevant bits bolded.

Further on:
Quote:
our security team responded immediately with a point-by-point testing and analysis of the erroneous concerns that were raised.
See what I mean about brushing it off?
Deviant Angel
Deviant Angel
Krytan Explorer
#7
Changes coming in the next few months? Some of the things we ask for, like email confirmation before changing passwords, shouldn't take months.
KiyaKoreena
KiyaKoreena
Desert Nomad
#8
Quote:
Don't run programs designed by third parties for use with our games.
Then PLEASE give us an official multi-launcher. Give us a switch for high rez textures everywhere.
Dzjudz
Dzjudz
Furnace Stoker
#9
Quote:
Originally Posted by KiyaKoreena View Post
Then PLEASE give us an official multi-launcher. Give us a switch for high rez textures everywhere.
This and this.
Winterclaw
Winterclaw
Wark!!!
#10
...

...

...

My opinion on this statement, and it is only an opinion, is that NCsoft is making this statement on the matter in order to reduce their risk of legal liability and nothing else.
R
Riot Narita
Desert Nomad
#11
Do they really expect us to believe that they take account security seriously?

When their website has been there for all to see, for HOW LONG, with below-industry-standard "features" like NOT asking for old password before allowing you to set a new password, sending you an alert email AFTER your password was changed etc? Only a bunch of incompetent clowns would have made that system in the first place. Never mind LEAVE it there so long.

I find their message insulting.
MisterB
MisterB
Furnace Stoker
#12
Quote:
Originally Posted by Katsumi View Post
Umm, I'm pretty sure they're brushing off anything we mentioned as nothing of value.
I reached exactly the same conclusion based on the statements you quoted. There is much covering of butts in text form here.
T
The Drunkard
Wilds Pathfinder
#13
Quote:
Many of you reading this letter are experienced online game players. You've heard the "don't do this" and "don't click that" and "don't run that thing" warnings over and again, you're not dumb, you'd never get your account stolen simply because you know better.

You're wrong. I know this because I know many people who thought they knew better--people who work in the gaming industry, and have done so for years, and still tried to log in one day and found their password changed and someone else logged into their account cleaning out their inventory.
You want to know the funny thing about your statement? I never had a problem with any of my accounts until I tried reseting my password and never got a confirmation email, only to have my account hacked when dealing with support. Sure, go ahead and call me a naive dumbass, but don't try and blame the players for your shortcomings
Arduin
Arduin
Grotto Attendant
#14
So the reports about the supposed security hole in the NCSoft Master Account were all faked?
Shakti
Shakti
Wilds Pathfinder
#15
......wow.......

The use of the phrases Katsumi pointed out like "supposedly" and "alarmist" especially read in context say to me "you guys are wrong, nothing to see here"...what utter crap.

Sorry, personally I put more faith in the long term dedicated players and mods who located this security problem than the head-in-the-sand people who have continually ignored the problems covering their asses. This problem DOES exist, people are hacked daily. Most may be from the causes he listed...but not all are.

I have been a GW fan girl for years...my husband and I bought Proph around 2 weeks after release. I love the game and have been excited about GW2, but if this condescending pile of steamy crap is NCsoft's idea of "official response"....think we may pass.
Gigashadow
Gigashadow
Jungle Guide
#16
I see nothing there that indicates NCSoft is going to stop designing their games (like Aion, Lineage 2) in such a way that it encourages players to RMT.

Also check this thread out http://www.aionsource.com/forum/aion...aion-poop.html

"We have reactivated the game account.

Further violations on this account, committed by anyone for any reason, may require us to close it permanently, so please take extra care to avoid association with activities prohibited by the User Agreement."

So even if someone got hacked to due NCSoft security flaws in the first place, too bad; anything else that happens to that account, regardless of whose fault it is, means permaban.

What a terrible company.
Highlander Of Alba
Highlander Of Alba
Wilds Pathfinder
#17
Well the Guys are trying you have to look at the big picture here..

The main thing that happened was when Aion got launched they were inundated with Bots .gold sellers ect.

This is a Joint Statement concerning all games under the NCSift umbrella ..not only GW..

There message although does not assist ones who have been attacked or buying things from other sources..namley gold sellers in Aion./Bots /Powerleveling...note the 3 parts its mainly Aion

So guys they have came out and made a statement,...you know what this all died down until we see the release of a statement by NCSoft not Arenanet
Gennadios
Gennadios
Wilds Pathfinder
#18
Quote:
Originally Posted by Katsumi View Post
Umm, I'm pretty sure they're brushing off anything we mentioned as nothing of value.
It's standard industry practice to brush off anything not vetted by PR/Legal, particularly when it originates from a third party.

The fact that they even gave GURU lip service speaks volumes.

They can brush of all the want in their official notices, but they heard, and they're scared
Junato
Junato
Lion's Arch Merchant
#19
Sometimes I think people don't bother speaking in terms that everyone would understand...
Jenn
Jenn
Resigned.
#20
My, what cynics you all are ; ).

Of course articles such as Jennings' will contain some sort of 'political' agenda, but in the grand scheme, the intent comes from a good place. They hear us - heck - they even quoted one of us. Our words are not going unread. True, we can point fingers at mistakes, but they can also do it to us (yes - I'm looking at all you people who leave your account open to vulnerabilities).

This isn't meant to play kiss-ass for NCSoft - organizations are never even close to perfect, especially with a convoluted structure of departments. If we snap our fingers, changes won't - believe it or not - happen overnight. When you deal with the many thousands of people that they do, with all sorts of details and complications, there is hardly a simple fix at the switch of a button. It is not unreasonable for their time-line to be estimated in weeks, or even months.

It is our account security but worse things could go wrong if they hasten a response. How many of you guys have actually seen the structure behind the interface we see, both for the website and multiple games they create? At best, it is organized chaos. One fix here could result in a bug there, or another vulnerability elsewhere, etc. etc. Trust me - you want these people to be as meticulous as the can.

Thanks for looking into it and hearing us. You guys aren't perfect, the gamers aren't perfect. Sometimes you guys screw shit up and so do we. Let's call it even?