4th time ive had to unlock my account and change my password , this website saves your password and is already there when i open the website fresh even if you dont ask it to, and it seems its happening to sooooo many people..
Ign: BlaZe_VorteX
League Service Threads: https://www.pathofexile.com/forum/view-thread/1725051
|
Posted byBlaZe88#2589on Mar 6, 2013, 8:17:12 AM
|
"
AzraelX wrote:
Right, because posting a legitimate link (which you could hover over, right click, highlight and copy, or quote to verify) to a secure page, for people who can't be bothered to take five seconds to navigate to the page themselves, somehow contradicts anything that's been said.
The best part is, you actually quoted it and verified the link was legitimate, then warned "kids" not to use it anyways.
I think your talents would be better served in a less serious thread.
My point is average Joe should not click on ANY links when you can easily just go there yourself. Especially one that will ask for their password right off the bat
- I'm not accusing you or anything, I'm saying most people don't even know about link safety and it's easier to tell them to just find the proper page themselves instead.
As for using talents, and the "seriousness" of this thread, just wondering if you realize the amount of time you spent typing your previous long post, where you are basically telling people about not losing their magic orbs in a video game. Chill a bit.
|
Posted bywonko33#2809on Mar 6, 2013, 10:43:02 AM
|
"
Selanmer wrote:
It seems to be that the main connection between hacked account is "short" password. People who hacked assure that they used a unique password and that their computer is clean. However no one mentioned that they used a long and complex password. Password needs to be unique, long and complex.
Also: It doesn't necessarily have to be hard to remember! As correctly pointed out by this xkcd comic four randomly selected English words will produce a very strong password (potentially with a good mnemonic) without any symbol characters or digits required.
Last edited by MesostelZe#4113 on Mar 6, 2013, 10:50:30 AM
|
Posted byMesostelZe#4113on Mar 6, 2013, 10:50:02 AM
|
"
Thomas wrote:
Morgawr, AzraelX, as you both presented fairly compelling cases I decided to investigate your accounts to make sure there wasn't anything unusual going on (as I have done with other random accounts when I get the chance). I wanted to share my findings with you in the hopes that it helps explain the situation.
In both cases your accounts were compromised during a sweep of login attempts, and in both cases yours were the only logins that succeeded from the respective IPs performing the login attempts (out of the half-dozen or so accounts they tried in each attempt). In each case only 1 login attempt is made per account, suggesting they are using a list of email/password combinations and are not brute forcing the passwords. None of the other accounts they tried even have PoE accounts associated with them, suggesting this list did not come from us.
A quick google search of your registered email addresses shows that both are used elsewhere on the internet. I cannot guess as to how they got your passwords, especially if they were randomly generated specifically for PoE - however if they had somehow been obtained from us it wouldn't make any sense for them to try all the non-existent email addresses at the same time (tinfoil hat theorists please stay in off topic).
These findings are consistent with everything we've seen and reported so far, I make a point of investigating cases which sound suspicious and so far none have raised alarms.
Also, before people start saying "Why don't you just block them from trying all these accounts?", we *do* have limits in place for login attempts which is why they only tried half a dozen or so per IP. The problem is we need to allow enough slack in the system for legitimate users to get their email/password wrong a few times without being instantly blocked - and the hackers (or crackers if you prefer) have over 270,000 IPs to do these tests from. We are however coming up with other ways to combat them, and will continue to do so until they are no longer a problem.
OOOOOOOOOOOOOOOH LOOK, the cry babies were once again utterly f***ing wrong, DAMN that was not expected, that was EXTREMELY surprising. It is all good tho, that GGG spends time and money on these bullshiters instead of using the small amount of money and work force they have to improve the game, not saying that is the wrong choice. Ofcourse you have to put these bs on their place, im just kinda annyoed by them.
Last edited by neroscapegod#7009 on Mar 6, 2013, 11:03:54 AM
|
Posted byneroscapegod#7009on Mar 6, 2013, 10:57:41 AM
|
I just logged on and in the last 8 hours apparently someone not only guessed my account, my password, but according to the email that told me I was locked out, they logged on from my home city.
Kind of disconcerning.
Yes, I do use the same junk email I use for all online games.
No, I don't use the same password.
No, I don't sign up for random stuff with this email, it's just for games and the purchasing of games.
It's pretty lame to spend the last month or so saving up to get a nice item or be ready to gear myself out @ 70 only to log on, see all my uniques/q-gems/currency stripped.
I honestly can't see how two things would happen here without some sort of breech on your end GGG;
1. How would they even know my email is associated with this game? How would they even know I'm playing, especially from this email? It's not like it's publicly flaunted.
2. How would they guess a password that I don't use for any other services, or better yet, how would they know where I live personally to set up a proxy so they could access my account through your services?
I welcome you to try to log on my email with the password that's associated with this account. It won't work, because this is the only account with that password. If you look up my youtube channel that shares the name of this character, it doesn't even use the same email, so it's not like they looked up my char names and found the email for this account. I don't download random things, as a matter of fact I run your game off a partition solely dedicated to games; there's only your game opened and used at any given point of time, no maphacks or any of that silly stuff.
I can't see myself continuing to play this game at this point. That's a huge setback to face when you're not doing anything wrong. If I want to spend a month to get no where I'll play something that I'll at least enjoy 100% of the time, not something that gives me desync deaths, crashes while zoning (beyond annoying, especially in places with LARGE maps like act3, tp to town and waste 45 minutes getting back to where I was), the lack of an ability to group because of particles spiking my fps. It's just not worth it right now.
And yes, you're right, they're not robbing devs/high profile players. But how would that make any sense to do? You're not going to get away with it, so why try? Good luck in your game, but I doubt you're being honest about this string of hacking going on. In my 15 years of online gaming I've never had any accounts stripped, I'm not careless, and I'm not going to read a thread that blames carelessness instead of manning up to an honest mistake.
|
Posted bysteven_mcburn#0891on Mar 6, 2013, 11:15:40 AMBanned
|
They've bent over backwards to show over these past few weeks they have not been compromised. You have to accept that it's not simply a coicidence, the hackers are systematically using botnets to spam GGG with thousands upon thousands of random log-in requests. They've gotten your information from where else on the net and are randomly guessing you and 10,000+ others over the span of days. Once you've written a program toautomate all this stuff, it's pretty trivial to cover thousands of possible combinations every minute.
My Keystone Ideas: http://www.pathofexile.com/forum/view-thread/744282 Last edited by anubite#0701 on Mar 6, 2013, 11:23:46 AM
|
Posted byanubite#0701on Mar 6, 2013, 11:22:27 AMAlpha Member
|
they dont log in from your home city, thats only because your provider changes your ip every day, happens to me each day that i have to unlock my acc
|
Posted byDeletedon Mar 6, 2013, 11:27:42 AM
|
"
steven_mcburn wrote:
I just logged on and in the last 8 hours apparently someone not only guessed my account, my password, but according to the email that told me I was locked out, they logged on from my home city.
Kind of disconcerning.
Yes, I do use the same junk email I use for all online games.
No, I don't use the same password.
No, I don't sign up for random stuff with this email, it's just for games and the purchasing of games.
It's pretty lame to spend the last month or so saving up to get a nice item or be ready to gear myself out @ 70 only to log on, see all my uniques/q-gems/currency stripped.
I honestly can't see how two things would happen here without some sort of breech on your end GGG;
1. How would they even know my email is associated with this game? How would they even know I'm playing, especially from this email? It's not like it's publicly flaunted.
2. How would they guess a password that I don't use for any other services, or better yet, how would they know where I live personally to set up a proxy so they could access my account through your services?
I welcome you to try to log on my email with the password that's associated with this account. It won't work, because this is the only account with that password. If you look up my youtube channel that shares the name of this character, it doesn't even use the same email, so it's not like they looked up my char names and found the email for this account. I don't download random things, as a matter of fact I run your game off a partition solely dedicated to games; there's only your game opened and used at any given point of time, no maphacks or any of that silly stuff.
I can't see myself continuing to play this game at this point. That's a huge setback to face when you're not doing anything wrong. If I want to spend a month to get no where I'll play something that I'll at least enjoy 100% of the time, not something that gives me desync deaths, crashes while zoning (beyond annoying, especially in places with LARGE maps like act3, tp to town and waste 45 minutes getting back to where I was), the lack of an ability to group because of particles spiking my fps. It's just not worth it right now.
And yes, you're right, they're not robbing devs/high profile players. But how would that make any sense to do? You're not going to get away with it, so why try? Good luck in your game, but I doubt you're being honest about this string of hacking going on. In my 15 years of online gaming I've never had any accounts stripped, I'm not careless, and I'm not going to read a thread that blames carelessness instead of manning up to an honest mistake.
Had password and email? In the same city? Look to your "friends" and siblings is my guess.
|
Posted bywonko33#2809on Mar 6, 2013, 11:30:53 AM
|
"
anubite wrote:
They've bent over backwards to show over these past few weeks they have not been compromised. You have to accept that it's not simply a coicidence, the hackers are systematically using botnets to spam GGG with thousands upon thousands of random log-in requests. They've gotten your information from where else on the net and are randomly guessing you and 10,000+ others over the span of days. Once you've written a program toautomate all this stuff, it's pretty trivial to cover thousands of possible combinations every minute.
That would be all fine and dandy except:
"
steven_mcburn wrote:
1. How would they even know my email is associated with this game? How would they even know I'm playing, especially from this email? It's not like it's publicly flaunted.
2. How would they guess a password that I don't use for any other services, or better yet, how would they know where I live personally to set up a proxy so they could access my account through your services?
I welcome you to try to log on my email with the password that's associated with this account. It won't work, because this is the only account with that password. If you look up my youtube channel that shares the name of this character, it doesn't even use the same email, so it's not like they looked up my char names and found the email for this account. I don't download random things, as a matter of fact I run your game off a partition solely dedicated to games; there's only your game opened and used at any given point of time, no maphacks or any of that silly stuff.
There's no way for those two things to happen without some sort of leak of information from GGG. First off, if you search my email, there's only 1 hit related to my email and it's completely unrelated(bogus sign up for some f2p stuff, no real information was used). Second off, there's no where in that search that it says where I'm from. How are they not locking the account out spamming password guesses but they know where I am in the world?
You can't call that a coincidence. A bot isn't going to not only guess my password, but where I'm from as well. That's absurd to say. Let's imagine there is only 1000 passwords ever and only 1000 places I could be from, that's 10,000,000 combinations, and in order to log on you have to get that right the first time. A whopping .000001% chance of that happening. And it's NO WHERE near that realistically, because there are far more than 1000 password combinations and places to be from.
edit:
"
wonko33 wrote:
Had password and email? In the same city? Look to your "friends" and siblings is my guess.
I live alone, I'm 25 and not in any real serious relationship. I've moved from my original hometown and work/play games/occasionally go out. No one else from here would even know I play games, let alone know what games specifically, or guess my password.
"
lorlak wrote:
they dont log in from your home city, thats only because your provider changes your ip every day, happens to me each day that i have to unlock my acc
I've had emails saying somewhere from china was trying to access my account in the past, but when my account was stripped (today) it said it was from my home city, probably not a coincidence either.
Last edited by steven_mcburn#0891 on Mar 6, 2013, 12:19:48 PM
|
Posted bysteven_mcburn#0891on Mar 6, 2013, 11:31:31 AMBanned
|
Just tossing in a weird idea - do you happen to use a wireless connection?
|
Posted bymirelitbab#7060on Mar 6, 2013, 12:51:53 PM
|