Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Another Nexon Mistake
Locked Wrote:Since this is indirectly talking about me, I'll go ahead and say it that no. I think people are overreacting at best, and that they should just wait until Nexon handles it. Until then you can provide yourself a very strong password and a good email that is linked to nothing. That's what everyone should do at the moment.

Nah, I think this is blown out of proportion as well. I simply found Viaje's comment rather unconstructive.
street Wrote:Hey things happen. Their is so much a company can do towards hackers attacking them. Look at sony and others companies that have felt the wrath of hackers.
It's rather ironic that you try to use Sony as an example. See, the only reason Sony "felt the wrath of hackers" is because their security was out-dated and weak:
"Being susceptible to SQL injection is embarrassing enough—techniques to prevent it are well-known, and easy to apply to any database-driven website—but what makes this hack even worse is the data that has been compromised."

Weak, you know, like Nexon's is now.

So your analogy was quite fitting, but your conclusion was flawed.
The fault still very much lies with the company itself.

street Wrote:Also dont give me the bs that the login id packet shouldn't have been in the code, because all the original code comes from kms. So give gms a break on an issue they could not control. I dont know how packet editing works, but i doubt to get rid of a packet is as easy as pressing backspace.
Two things:
1 - The GMS team certainly could control it, much like they've adapted to other holes in the original code.
2 - Most people are complaining about Nexon as a whole!

I find it strange that you're so eager to protect the GMS team from ridicule.
Kalovale Wrote:The ID can be either an extra layer of security (by obscurity) or the ONLY piece of identification to you

'Security through obscurity' is not security at all. There's a reason the term is a pejorative.

http://en.wikipedia.org/wiki/Security_through_obscurity
http://slashdot.org/features/980720/0819202.shtml
http://stackoverflow.com/questions/53396...a-bad-idea

And on and on and on.
If you've been counting on no one knowing you who are as your first line of defense, welcome to reality - Anonymity is neither protection nor realistic.
It's not having what you want - It's wanting what you've got.
They took the MTS down
Killed Wrote:They took the MTS down

LOL I guess they finally realized that it was probably a bad idea to tell people it was safe when people's login IDs were released on the internets.

Only reason I'm worried of being hacked is because It's my main account and I use it to play other Nexon games too Sad Would basically kill my will to play these games if I lost everything I earned legitimately. For now I've changed passwords to something more complicated than my last. May change emails if i feel the need to.
Viaje Wrote:I find it strange that you're so eager to protect the GMS team from ridicule.

some people are brainwashed by nexon.
Worthyness Wrote:Only reason I'm worried of being hacked is because It's my main account and I sue it to play other Nexon games too Sad Would basically kill my will to play these games if I lost everything I earned legitimately. For now I've changed passwords to something more complicated than my last. May change emails if i feel the need to.
I had the same thought, actually.
While I don't play it much and likely have nothing of value in it (pineapple if I know how the economy works), I do quite enjoy Dragon's Nest.

It would be slightly annoying if someone caused me to start over on that game.

CrazyNomad Wrote:some people are brainwashed by nexon.
By 'Nexon', you mean 'Nexon Korea', right?
They're the ones brainwashing everyone; Nexon America is just an innocent bystander.
Oh, I seem to have missed the fun involving the account purge list. Quite the slip-up on Nexon's part irrespective.
Eos Wrote:If you've been counting on no one knowing you who are as your first line of defense, welcome to reality - Anonymity is neither protection nor realistic.

As if we had any other choice for security. This is us helpless mortals struggling to keep ourselves as safe as, again, possible.
Well, it's been nice knowing everyone, but I'm on the list =(
Eos Wrote:'Security through obscurity' is not security at all. There's a reason the term is a pejorative.

http://en.wikipedia.org/wiki/Security_through_obscurity
http://slashdot.org/features/980720/0819202.shtml
http://stackoverflow.com/questions/53396...a-bad-idea

And on and on and on.
If you've been counting on no one knowing you who are as your first line of defense, welcome to reality - Anonymity is neither protection nor realistic.
That's all very well when you're designing a security system, but for the end user, obscurity is the only security you get - if someone finds out your login information, they can perfectly imitate you, whatever form that information takes. So ideally you want to keep as much of it secret as possible, frequently change whatever possible (so it's harder for someone to collect the full set at one time), etc.
PirateIzzy Wrote:Well, it's been nice knowing everyone, but I'm on the list =(

Izzyyyy nooooo it's ok half the guild besides me Big Grin (but I was already hacked during the time maple was down most of the day) names are on the list also =[ Hopefully with just the IGN nothing can really happen.
Stereo Wrote:That's all very well when you're designing a security system, but for the end user, obscurity is the only security you get - if someone finds out your login information, they can perfectly imitate you, whatever form that information takes. So ideally you want to keep as much of it secret as possible, frequently change whatever possible (so it's harder for someone to collect the full set at one time), etc.

Your logic amounts to someone who looked your address up in the phone book being able to burgle you at will.
They still need to either break in, steal your key, or get you to leave the house wide open.

This is no different from the hundreds of ways someone can find out your home address.
It's not having what you want - It's wanting what you've got.
Maximillion Thermidor Wrote:Izzyyyy nooooo it's ok half the guild besides me Big Grin (but I was already hacked during the time maple was down most of the day) names are on the list also =[ Hopefully with just the IGN nothing can really happen.

Ruben, if I do get hacked, God forbid, I won't be coming back. It's been nice knowing you, and if I do quit, tell Akshar to forget about HT card,
Viaje Wrote:Two things:
1 - The GMS team certainly could control it, much like they've adapted to other holes in the original code.
2 - Most people are complaining about Nexon as a whole!

I find it strange that you're so eager to protect the GMS team from ridicule.

1.When GMS is copying the data from jms,kms,etc they should suspect that an issue like this would have arise? Since MTS has been out and the cash shop your login id has always been present in plain view. Why would they worry about this causing a problem now? When it has not posed a threat since MTS has been around? O yea most of your morons believe gms can tell the future and is able to know exactly how hackers/exploiters are going to use certain features that are already present in other versions to their advantage.

2.No people do not complain about nexon as whole dumbass. They complain about the current version they are playing.
Two of my GF's chars is on the IGN list, as well as a couple of my friends. :/ She is changing her passes and PICs via secure methods, so it's all good. And it's also good that none of my chars were listed, so I'm safe.

Also, I wonder if Locked knows that his Windian char is also on that list...
Yes.
Yes I do.
street Wrote:1.When GMS is copying the data from jms,kms,etc they should suspect that an issue like this would have arise? Since MTS has been out and the cash shop your login id has always been present in plain view. Why would they worry about this causing a problem now? When it has not posed a threat since MTS has been around? O yea most of your morons believe gms can tell the future and is able to know exactly how hackers/exploiters are going to use certain features that are already present in other versions to their advantage.
You keep on answering your own questions.
If the login ID has always been in plain view within the MTS system, then it has always been a threat.
An unknown vulnerability is still a vulnerability.

Furthermore, if the IDs have always been so easily accessible, then they should have noticed the hole when they first implemented the MTS in GMS.

Theoretically, they should be checking for possible incompatibilities and, you know, debugging the code instead of just "copying the data".
If an exploit slips through, it's still on them for not testing the code properly.

street Wrote:2.No people do not complain about nexon as whole dumbass. They complain about the current version they are playing.
I'm fairly sure that "Nexon" by itself is a non-qualified term.

Stereo Wrote:That's all very well when you're designing a security system, but for the end user, obscurity is the only security you get - if someone finds out your login information, they can perfectly imitate you, whatever form that information takes. So ideally you want to keep as much of it secret as possible, frequently change whatever possible (so it's harder for someone to collect the full set at one time), etc.
I believe Eos' assertion is that it's impossible to remain obscure.

While your password and PIC should only be called upon/tested against on login, there are far more systems within the game (and Nexon as a whole) that reference your ID.
My email that was attached to the user ID of mine on that list is currently locked because someone's been trying to log into it too many times.
Killed Wrote:My email that was attached to the user ID of mine on that list is currently locked because someone's been trying to log into it too many times.

And thus it begins...!


Forum Jump:


Users browsing this thread: