MTS Update Finished
#21
Liteness Wrote:id not using email- they have to actually have your pass before they can log in and find out ur email to hack it and to switch info around

email as id- woot don't need pass just hack email, resend verification to switch infos

hmmmm anything im missing here?

Not really. Nexon's "solution" is to remove one layer of security ("by obscurity" or otherwise).

They do write
Nexon Wrote:- Our Customer Support agents will work with each individual to address their concern.
which might be an outright lie (because they have an automated system set up to change every account that sends a ticket with the above parameters to have ID=Email), or not (in which case it'll probably take forever for them to deal with the flood of tickets).
If it's true, though, maybe they could be convinced to change the ID to something that isn't the e-mail.
Reply
#22
Liteness Wrote:id not using email- they have to actually have your pass before they can log in and find out ur email to hack it and to switch info around

email as id- woot don't need pass just hack email, resend verification to switch infos

hmmmm anything im missing here?
Pretty much this.

Your question actually made me check the password reset system out of curiosity.
Sure enough, requesting a password reset sends my registered email address a link that I can follow to a form that simply asks me to enter a new password...
...despite the fact that I have security questions set up!!!!

So the only point of the security questions appears to be to change the information if you already have access to the account.

Locked Wrote:Just make a mule email account people o.o Not that difficult.
That's what I'd do anyway; I don't like to keep all of my proverbial eggs in one basket.
However, it would mean having another account to upkeep.

Then again, it's far easier to burn an email address than to burn an account.

SaptaZapta Wrote:Not really. Nexon's "solution" is to remove one layer of security ("by obscurity" or otherwise).
Well, it's removing a layer of obscurity in exchange for the ability to shuffle around one 'lock' as much as you wish.

Really, the threat of someone getting into your email account should be a zero-risk nowadays.
Most popular providers prevent brute-forcing and will even alert you if someone has been trying to do so.
Gmail, folks.

Plus, Nexon has made strides in obscuring who is and isn't signed up.
Try to signup for using an email address that's already registered, and the email account gets this mail:

"Greetings,

Another user has tried to register an account with the email address xxxx@xxxx.xxx. For your account security, we recommend you update your password and secondary security.

Visit the Account Settings page at anytime to update your information.

— The Nexon Team"

They also made sure the same generic statement is given when logging in with an invalid ID/email or a valid ID/email with an incorrect password.

Of course, the only exception to this rule is the Gamelauncher itself which will open up your browser to the Maplestory homepage should you try to login with an invalid ID/email.
Reply
#23
Tickets get replied within 5 minutes, and the ticket says this for those wondering.

Quote:*Please note that this is an auto-generated message from Nexon Support based on your recent support ticket.*

We have received your ticket submission regarding the recent MTS issue. Please understand that we have changed the way the MTS stores player data in order to protect our player’s privacy. That said, we do not believe that this issue has endangered our players’ security in any way.

However, we understand that you are concerned about the potential impact this may have had, and are interested in having your account ID disabled. While we are offering this option to players, we advise against taking this step, as the account ID offers another piece of unique information through which we identify you as a player, which will no longer be available.

Keep in mind that this change will be permanent. If you go through with this change, you must always use your email to login to the Nexon website and game.

If you would still like to have your account ID disabled, there are a few things you need to do first:

-You MUST have access to the email address registered to your Nexon account.
-You MUST set up your Security Questions, in order to further protect your account.


If you have done both of these things and would like to move forward through this process, please add a comment to this ticket by clicking the “Provide Additional Information” button when viewing this ticket on the website.

Once we have received your confirmation, we will begin processing your request. Please understand that this process has multiple steps and is very time-consuming, as each step must be completed manually.

Thank you for your patience,

Nexon Support Team
Reply
#24
Why do We need to use only our email to login but The better idea is If we can get to change our ID Tongue
Reply
#25
Nexon Wrote:While we are offering this option to players, we advise against taking this step, as the account ID offers another piece of unique information through which we identify you as a player, which will no longer be available.
So they think it's a good idea to have, but they removed the option.
Allow us to combine our powers in an attempt to understand this.

Really though, as I said, all the ID does is prevent your email from being put out in the world should there be another login-leak.

If your email gets brute-forced, well, you're an idiot.

If you have a proper password on the account and a decent provider, the biggest threat anyone can present is signing you up for spam lists.
The spam should only bother you if it's your primary email account and it has a pomegranatety spam filter in which case, congratulations, you still managed to be an idiot despite properly password protecting your account.

Bomber Wrote:I'll stick with my ID and pretend this thread never happened.
Ditto.
Reply
#26
I'll stick with my ID and pretend this thread never happened.
Reply
#27
Viaje Wrote:So they think it's a good idea to have, but they removed the option.
Allow us to combine our powers in an attempt to understand this.

this....exactly what i was thinking about, wtp nexon?
Reply
#28
Locked Wrote:Tickets get replied within 5 minutes, and the ticket says this for those wondering.

AND this is why they need to rehire their stupid support staff. After that, i feel more qualified to do their job for them. It's completely stupid to think it's a good idea to allow one to reset their ID INTO the account's email. It's counter productive and makes future leaks have more potential to do more harm than this one did. I understand if it's difficult to change the IDs of 19,000 IDs (hell it takes a while to get IDs changed in my job). But with a support staff that should be bigger than mine (which consists of me and 2 other people), they shouldn't have a problem at all.

I think I'll leave my ID there. If they can get my email, I'd rather have something in the way instead of it being right out in the open.
Reply
#29
Nexon Wrote:However, we understand that you are concerned about the potential impact this may have had, and are interested in having your account ID disabled.

Uh, no. I'm interested in having my account ID changed.
It's you lazy shits who would rather disable it, which as you so carefully explain later, is detrimental to account security.
Reply
#30
Obviously there's some way to figure out your email with just the login ID, since someone has been trying to get into mine ever since the list was leaked. What the hell kind of difference would this make? Account ID change or gtfo
Reply
#31
Killed Wrote:Obviously there's some way to figure out your email with just the login ID, since someone has been trying to get into mine ever since the list was leaked. What the hell kind of difference would this make? Account ID change or gtfo

Makes getting your email address easier ;D
Reply
#32
"You MUST have access to the email address registered to your Nexon account."

Bother. Still trying to recover mines.
Reply
#33
you all do realize that u can change your email which is your login at will... so if there is a leak change email = change login id = less worry.
Reply
#34
jhkplaya888 Wrote:you all do realize that u can change your email which is your login at will... so if there is a leak change email = change login id = less worry.

You are assuming of course that the email you are currently using hasn't already been hacked open, meaning the hacker probably changed your email for you and you basically lose your account forever right?

I mean with the user ID, it's at least permanent and you can retype it and get a password reset or something.
Reply
#35
When they said "Update", I was thinking that they not only fix the hack but there will be an update that allows certain newer items and potentialed ones to be MTS:ed.

Maybe it's just my poor English.
Reply
#36
Worthyness Wrote:You are assuming of course that the email you are currently using hasn't already been hacked open, meaning the hacker probably changed your email for you and you basically lose your account forever right?

I mean with the user ID, it's at least permanent and you can retype it and get a password reset or something.

if you have a safe email, you can make a new email account, that no one will know, change the currently registered email and disable your ID.

most, if not, all email provider don't accept bruteforce (gmail ask for a captcha after 5? wrong password).
Reply
#37
Worthyness Wrote:You are assuming of course that the email you are currently using hasn't already been hacked open, meaning the hacker probably changed your email for you and you basically lose your account forever right?

I mean with the user ID, it's at least permanent and you can retype it and get a password reset or something.

hacking a major email company like yahoo and gmail through brute force is idiocy... especially if you use a long complex random password.
Reply
#38
idk...I'm still thinking about whether or not I'll do this...

I wasn't exactly thinking smart when I first made my nexon account, and I regret the ID I chose, it'd be nice to have the option to change it to something else...

Imma just keep my ID for now, but I'll be thinking about it~
Reply
#39
Locked Wrote:Tickets get replied within 5 minutes, and the ticket says this for those wondering.

Adding a comment to the ticket, as requested, generates the following auto-response (not immediately, I think it took about a day)

Nexon Wrote:*Please note that this is an auto-generated message from Nexon Support based on your recent support ticket.*

Thank you for confirming that you would like to begin the process of disabling your account ID. As this process is very time-consuming, we ask for your continued patience while we work on your request.

Thank you for your patience,

Nexon Support Team

Note that my comment actually said I didn't want my ID disabled, I wanted it changed.
Wonder at what point an actual human gets in the picture to begin the "time-consuming" process, and (more importantly, if one is indeed worried about getting hacked through the ID) how long it takes to complete.
Reply
#40
You can tell they're taking this issue very, very seriously.

I get a "we have not forgotten you" e-mail every two days, instead of the usual once a week...

Nexon Wrote:*Please note that this is an auto-generated message from Nexon Support based on your recent support ticket.*

Thank you for continuing to wait patiently. Please understand that we have not forgotten you! We are still working on your request.

Thanks again for your patience,

Nexon Support Team
Reply


Forum Jump:


Users browsing this thread: 2 Guest(s)