Question for NC/Mistryl

Player Questions Started Last reply 9 posts
I thought I'd ask this question for the sake of everyone here.

NC announced that our L2 account passwords were reset, and we know also that our PlayNC accounts were reset if they had the same password.

Am I coming to the right conclusion if I guess that this means someone out there might have or had access to everyone's L2 account passwords?

Also, IF that is true, shouldn't everyone who plays L2 be warned to change that same password if they use it elsewhere?

I don't want to see someone lose anything non-L2 related because it has the same password as their L2 account. :(
Who care about l2 non related stuff ^^
i don't want to see ppl that loose high overenchanted A or S grade weapons !
I don't think someone could use this information. (Except maybe to try the same account data to login to your email account or a non-offical server.)

More critical are the accounts that have credit card numbers stored. It doesn't look like someone could have accessed them, because there was no information (or Ncsoft is just covering up).

More critical are the accounts that have credit card numbers stored. It doesn't look like someone could have accessed them, because there was no information (or Ncsoft is just covering up).



I could very well be wrong, but I dont think much danger of that. Even if person was able to get your master account name and password (cause used same as set as the game)... the credit card info there would only show em last 2 digits and exp date. Thier actually billing database would have to of been breached; and they never eluded to such a occurence....
I guess to most it may sound trivial, but I picture a hacker out there with a big list of user/pass from L2 accounts trying those same user/pass on other websites. Not just email but also financial institutions etc. How long before they come across some poor sap who uses the same user/pass for everything?
I am surprised that NCsoft did neither reply nor kill this thread... They seem to have no answer, or they just don't care.
Or they're otherwise occupied trying to resolve the issues at hand.

Which would you rather have? Someone locking / deleting threads, or one more pair of hands working on resolving the issue?

I know which one I'd want.
Well, maybe I was to hard with them. :eek:

The GMs that are responsible for the password reset may be punished enough by now.
I would highly doubt that the Community Liason and the Forum Moderators have anything to do with the server security team.

As a matter of fact, it would worry me greatly (though perhaps explain a lot of things) if this were, indeed, the case.

I'm wondering, what, exactly happened?

Did they just *stumble* over a hole that no one else had found and fill it? Unlikely, we wouldn't need to change our passwords and such. Which leads us to the only natural conclusion that, indeed, account information had been compromised.

However, here come my next questions... how far did the vulnerability go? Did whoever exploited it get past the game account info? Was our private billing data compromised? Seriously, with such information that PlayNC wants, it's nearly ready-made identity theft... the only thing you're lacking is my Social Security Number and my passport photo!

Furthermore, if such activity *did* occur, and personal information *was* compromised, when was NC-Soft planning to inform us to take necessary precautions? If such data was taken by hackers from these servers at this time, and used in an illegal manner, you can be quite sure that I, and my lawyers, would be calling NC-Soft NA.

Overall, I think that a lot of people, myself included, have a lot of questions about what happened, what was compromised, and what else we need to do or keep an eye on from this point forward, and NC-Soft's usual silence and lack of information towards their customer base is certainly not helping matters.