2011-10-25, 11:21 AM
Lots of hidden assumptions there.
Personally I'm most concerned about the current hacking wave. Trouble is, nobody knows how it's being done. Including, apparently, Nexon.
Almost all the people I know who were hacked in the past two months or so, were hacked while offline. So, even if connection hijacking ("remote hack") is currently possible, it's obviously not the biggest danger you need concern yourself with. I also don't know why you'd think website login is more susceptible to this (and in this case "I don't know" literally means that, not "I think you're wrong").
As for keyloggers... one theory that has been proposed for these recent hackings was some kind of magical keylogger that lies in wait for months (some people hacked hadn't logged onto maple in months, which means a more recent logger would have had nothing to record) and is indetectible by any of the malware scanners around (many people who got hacked had their computer scanned and found squeaky clean). Somehow I have a hard time believing in such a beast, mainly because I can't think why the keylogger's owners would wait so long to start reaping their rewards, instead of hacking accounts as soon as they have their info.
Another theory that has been advanced is that Nexon's user database has been leaked again, same as two years ago. That is possible, but the problem is that some people who were hacked claim to have changed their password recently (after the start of the hacking wave - hence the leak is continuous or at least periodic), and others claim to have had a password so complex it couldn't possibly be un-hashed by rainbow tables and the like. The second issue is especially problematic because I tend to believe Nexon that they don't store cleartext passwords anywhere. If some of their web pages are indeed unecrypted, the cleartext password could be intercepted by someone tapping their lines - but then how do inactive people get hacked? Same issue as with the keylogger, if a person isn't entering their password anywhere, nothing can record it.
The last theory is that the hackers have a "bypass", a way to fool the game servers into thinking they have been authenticated, when they haven't. This bears some similarity to "hijacks", but doesn't require that the legitimate user log in before his connection can be stolen. This is not too farfetched, considering the number of servers involved and the general quality of Nexon's coding. If this is so, however, no level of securing your password would protect you, because the hackers never need to find it out.
Personally I'm most concerned about the current hacking wave. Trouble is, nobody knows how it's being done. Including, apparently, Nexon.
Almost all the people I know who were hacked in the past two months or so, were hacked while offline. So, even if connection hijacking ("remote hack") is currently possible, it's obviously not the biggest danger you need concern yourself with. I also don't know why you'd think website login is more susceptible to this (and in this case "I don't know" literally means that, not "I think you're wrong").
As for keyloggers... one theory that has been proposed for these recent hackings was some kind of magical keylogger that lies in wait for months (some people hacked hadn't logged onto maple in months, which means a more recent logger would have had nothing to record) and is indetectible by any of the malware scanners around (many people who got hacked had their computer scanned and found squeaky clean). Somehow I have a hard time believing in such a beast, mainly because I can't think why the keylogger's owners would wait so long to start reaping their rewards, instead of hacking accounts as soon as they have their info.
Another theory that has been advanced is that Nexon's user database has been leaked again, same as two years ago. That is possible, but the problem is that some people who were hacked claim to have changed their password recently (after the start of the hacking wave - hence the leak is continuous or at least periodic), and others claim to have had a password so complex it couldn't possibly be un-hashed by rainbow tables and the like. The second issue is especially problematic because I tend to believe Nexon that they don't store cleartext passwords anywhere. If some of their web pages are indeed unecrypted, the cleartext password could be intercepted by someone tapping their lines - but then how do inactive people get hacked? Same issue as with the keylogger, if a person isn't entering their password anywhere, nothing can record it.
The last theory is that the hackers have a "bypass", a way to fool the game servers into thinking they have been authenticated, when they haven't. This bears some similarity to "hijacks", but doesn't require that the legitimate user log in before his connection can be stolen. This is not too farfetched, considering the number of servers involved and the general quality of Nexon's coding. If this is so, however, no level of securing your password would protect you, because the hackers never need to find it out.

