ResistGreen Wrote:Interesting... The person who I found one of my items in was a level 17 Evan..
The exact same case applies to me. I found 3 level 16 Evans selling stolen items in mushies on ch 2 with the title "buy of offer".
Nothing for over max, even if it was actually worth much more.
2011-09-06, 02:17 AM (This post was last modified: 2011-09-06, 02:19 AM by RahlsSoldier.)
Locked Wrote:Ah I was semi-lied to ):
It's 128 for Game Launcher, 64 for the site.
I didn't lie, I told you the Game Launcher amount.
street Wrote:This is new o_0 maybe nexon knows about the issue going on? It was just last week i couldnt login using a pw 20 digits long from game launcher.
Earlier this week I couldn't either. They changed it very recently, as my password was 15+ characters and I was able to starting this weekend.
RahlsSoldier Wrote:I didn't lie, I told you the Game Launcher amount.
Not you@@@
4 people counted for me
street Wrote:This is new o_0 maybe nexon knows about the issue going on? It was just last week i couldnt login using a pw 20 digits long from game launcher.
HellenzSin Wrote:I was told pw was 64 digits 3-4days ago, and now 128.
And just last week Game Launcher didn't even go over 12. I wonder why Nexon is doing this without announcing it. Is it a "We've been secure all along" ploy? I don't see the point in having a password that long anyways. After a certain amount of characters it just becomes unrealistic to be breached by brute force and more likely to be done in by a password bypass.
Mibs Wrote:And just last week Game Launcher didn't even go over 12. I wonder why Nexon is doing this without announcing it. Is it a "We've been secure all along" ploy? I don't see the point in having a password that long anyways. After a certain amount of characters it just becomes unrealistic to be breached by brute force and more likely to be done in by a password bypass.
I have no idea how NEXON's internal infrastructure is set up, so I'm just going to be going out on a limb here, but, do you think they could have gotten access to a password hash database? I know some setups use those...basically, that would enable them to "bruteforce" a huge list of hashes and combine matches for optimum results. If their bruteforcing is based on the old 12 character system, that wouldn't be hard at all to get hundreds of matches a day. Which, on that same token, if someone were to update to a 13^ character password, it would render their script useless on those accounts. A small chance, but anything to reduce a chance of getting hacked is better than nothing, right? And it's not like NEXON is going to publicize the exploit after they fix it, so we never will know what actually happened unless the people with the script tell us.
I recall fom the last account-hack event that a 12-character password with mixed lower-case, upper-case, and numbers was more than sufficient to make the most advanced hash-cracking techniques totally impractical. Have cracking techniques advanced so much that you need even longer passwords now? 64 or 128 characters long seems ridiculous.
street Wrote:I have a question does the nexon site show this for anyone else? Or I'm the only one?
If i'm the only one guess i'm next?
Google says if you see this it means:
The site uses SSL, but Google Chrome has detected either high-risk insecure content on the page or problems with the sites certificate. Dont enter sensitive information on this page. Invalid certificate or other serious https issues could indicate that someone is attempting to tamper with your connection to the site.
I just got an automatic update for this:
Spoiler
Microsoft Security Advisory (2607712)
Fraudulent Digital Certificates Could Allow Spoofing
Published: August 29, 2011 | Updated: September 06, 2011
Version: 3.0
General Information
Executive Summary
Microsoft is aware of active attacks using at least one fraudulent digital certificate issued by DigiNotar, a certification authority present in the Trusted Root Certification Authorities Store. A fraudulent certificate could be used to spoof content, perform phishing attacks, or perform man-in-the-middle attacks against all Web browser users including users of Internet Explorer. While this is not a vulnerability in a Microsoft product, this issue affects all supported releases of Microsoft Windows.
Microsoft is continuing to investigate this issue. Based on preliminary investigation, Microsoft is providing an update for all supported releases of Microsoft Windows that revokes the trust of the following DigiNotar root certificates by placing them into the Microsoft Untrusted Certificate Store:
DigiNotar Root CA
DigiNotar Root CA G2
DigiNotar PKIoverheid CA Overheid
DigiNotar PKIoverheid CA Organisatie - G2
DigiNotar PKIoverheid CA Overheid en Bedrijven
For supported releases of Microsoft Windows, typically no action is required of customers to install this update, because the majority of customers have automatic updating enabled and this update will be downloaded and installed automatically. For more information, including how to manually install this update, see the Suggested Actions section of this advisory.
All that means is the site is being reached over HTTPS and includes links to resources on it that are via HTTP instead HTTPS and those portions are not secured.
This is why I hate threads like this, people start to panic over things and draw lines and conclusions where none exist.
It's not having what you want - It's wanting what you've got.
Eos Wrote:All that means is the site is being reached over HTTPS and includes links to resources on it that are via HTTP instead HTTPS and those portions are not secured.
This is why I hate threads like this, people start to panic over things and draw lines and conclusions where none exist.
Hmm I didn't know about that first part and as for the second I completely agree with you Eso, I hate reading threads like this because of all the things people come up with and I posted a couple pages back that all people are doing is more scaring of people then anything else. But it's always on top and just like anyone else I too would like to know exactly what's causing all this but like I'm saying to all my friends and people I know really all you have to do is change your pass/pic at least 1-2x per month and you'll most likely be okay. I mean, with everything that's gone on in the past, people who have caught hold of the issue early on and changed their info seemed to be fine. So yeah, also hate threads such as these.
So if we want a super safe password from brute force, we should just change our passwords to a combination of Upper case, lower case, numbers, and keyboard symbols that extend pass the 12 character limit?
I found another laughable hole in Nexon's security.
To change your account email address, you need to enter the answer to both security questions.
Fair enough.
Problem is you can change one security question by knowing the answer to the other question.
So, basically, that means that having two security questions actually weakens account security.
EDIT: I also really wish Nexon would suck it up and make Item Locks free.
I'm fairly sure that the lost revenue from those items would be surpassed by people buying NX because they feel secure enough to do so.
What's more, they should change the system.
While I like some suggestions I read, it'd also be rather nice if an item being locked would allow it to be account-tradeable.
I don't mind certain items being unsellable for up to a year, but I do mind being limited to one character when things like Evo Rings can't be moved.