Board goodbye

General Discussion Started Last reply 41 posts
After 4 years of actively using this forum I am very sad to lave this board. Until the issue with putting your actual game credentials to log in or create account here will be resolved to some more secure way.

Yeah, one less troll to take care of. Whatever. Sorry.
I fully agree with Crawlerin. However I won't withdraw.

The current situation could lead to some tragic events.

Hope the comunity leaders will take action to fix this.

Thanks.
Why is this such a big security risk compared to the other forum?

If ur log in was JamesBond, while in the forum it can say Crawlerin.
How can anyone know your log in, if no one can see your log in nick?
Yes they MUST fix this, it's easy to get hacked.
Why is this such a big security risk compared to the other forum?

If ur log in was JamesBond, while in the forum it can say Crawlerin.
How can anyone know your log in, if no one can see your log in nick?

It's better to have the pass separate too. Can never have too much security.
I'll be watching boards just not posting after this session expires. I submited support ticket to have that actual password changed - hope they understood it, I wrote it very clearly which password I wish to change and I hope they have it separated enough to do just initial check on active account and avoid using in-game password permanently.

I mean ... what's the purpose of having GameGuard and Key Security feature if it's necessary to breach own security this way?
Why is this such a big security risk compared to the other forum?

If ur log in was JamesBond, while in the forum it can say Crawlerin.
How can anyone know your log in, if no one can see your log in nick?

Honey ... but you TYPE IN that "JamesBond" and password to those little fields in your browser. What's displayed on board is not important. Say hello to any keylogger in netcafe, your friend's computer infected with virus, your employer spying on you or somebody tapping unsecure http connection on router on the way.
http://en.wikipedia.org/wiki/Keylogger for more info, it's just an example.
Why is this such a big security risk compared to the other forum?

If ur log in was JamesBond, while in the forum it can say Crawlerin.
How can anyone know your log in, if no one can see your log in nick?

On the other forum, you had a separate password from your actual game login. On this forum, you use the same username/pw as you do to log into the game. Which means that someone just needs to place a keylogger on a computer to get the login info for this website/forum, and he immediately can then empty out that person's game account. Or, even easier, he could just check the saved passwords in e.g. Firefox, if he has access to the computer - for example, if you visit this forum from a computer at work/at a friend's place etc. The game uses gameguard to check for keyloggers before you get to the login page, this forum of course doesn't. So we now have less security than before.
I agree that it's big security risk, but all in all I'm not using theese boards outside my laptop so for me it's safe to use.
I agree that it's big security risk, but all in all I'm not using theese boards outside my laptop so for me it's safe to use.
If someone wants to steal your password, controls some router between you and NCsoft (to be able modify HTML coming from http://boards.lineage2.com/ to your computer) and have enough hacking experience, they can obtain your password even if they don't control your computer directly. Basically, until they fix this security risk, no one should post from the places where the router can be controlled by a L2 gamer, such as net cafes (including posting from your own laptop on a net cafe wireless spot).
The game uses gameguard to check for keyloggers before you get to the login page, this forum of course doesn't. So we now have less security than before.

I demand using GameGuard for forum them :-P
I agree that it's big security risk, but all in all I'm not using theese boards outside my laptop so for me it's safe to use.

I guess it's safe for me then also..... I only use my own computer and my laptop.

However my cousin does have access to my laptop :eek:
Even if you're playing from your own PC absolutely nothing can be guaranteed...
Same can be said for when you're buying stuff online or paying or loggin into your main NC account. If you log in there.. what's the difference to logging in here? Really, I don't see the problem.

If you have a keylogger on your own PC.. that's your problem.
If someone wants to steal your password, controls some router between you and NCsoft (to be able modify HTML coming from http://boards.lineage2.com/ to your computer) and have enough hacking experience, they can obtain your password even if they don't control your computer directly. Basically, until they fix this security risk, no one should post from the places where the router can be controlled by a L2 gamer, such as net cafes (including posting from your own laptop on a net cafe wireless spot).

I'm using autoconnect, I dont have to enter my data everytime I use.

P.S. I dont know if autoconnect os more secure way, but at least it's secure from keylogers.
Login is done via https, so http via ssl, even if the "hacker" intercepts your traffic the connection is safe and information can't be stolen (it's encrypted) easily at all. (for the most part can't be stolen at all).
Hmm :|.
I will stop using this board if they do not fix it, however, it is not only keyloggers I'm worried about. (or man in the middle)
Are there not people out there that know really well how to **** this type of Forum, gaining access to the Forum database... and thereby gaining access to all password hashes. A professional with an entire PC dedicated to *censored because I dont want to give people idea's* wont have much trouble getting a few accounts.

I don't trust forums, they are far to insecure... and we cant do anything to protect us from some dangers... no matter how paranoid you are...
It's not about keyloggers only. What bothers me more is pharming.

You receive new mail on your e-mail address (some have visible them from forum) that you have one new private message on forum, click here to read it. Click the link, don't check URL properly (or you have unpatched browser and using Outlook so it cannot recognize scam e-mail and fake web address). You get redirected to nice form about logging in first.

10 minutes later you have your game account cleared.
And that's why pishing filters are there.
Also I stopped trusting addresses implicitly when i was tricked back in highschool (oh... 10 years ago ?) to enter my yahoo nick/pass in a fake site that looked exactly like yahoo's email site :S.
In any case, no matter the precautions no matter how paranoid one is, it's too dangerous to have things like this.
I plead with the comunity managers to take action on this matter, we can't leave it like this, it's way to dangerous. (even if it was only due to human carelessness).
Login is done via https, so http via ssl, even if the "hacker" intercepts your traffic the connection is safe and information can't be stolen (it's encrypted) easily at all. (for the most part can't be stolen at all).
Hmm :|.
There's a problem: login form on the board (unlike on https://secure.plaync.com/cgi-bin/accountManagement.pl) is sent to you using plain HTTP. Which means a "man in the middle" hacker could insert any code he wants there.
Well, I want to be able to change my forum password. That's all.

And until I do, I am probably going to stay away from the boards as well.

Call me extra-safe, but I had an attempt of having my game password changed before. I do not want to risk it again.

So I'll see you whenever this issue is solved. What a pity.
EDIT: Let's try this since the forum is borked...

http://i211.photobucket.com/albums/bb280/UbahNecro/L2BoardMessage.png

EDIT #2: Lol, Owned!

To Board Admins: The following is popping up ALOT when you attempt to post on this forum. It takes over an hour to even get something to post... I've been trying to post that since like 6am and I kept getting this message:

http://i211.photobucket.com/albums/bb280/UbahNecro/BadInput.png

Looks like Quality Assurance and Testing went out the window with this one, eh?
Rather than posting things which show you can break the forum (I have many ways.. but I don't want to risk my account by testing) maybe you can PM them to Siren so she can fix them.

Stop trying to look 'l33t' in front of your peers.
.. maybe you can PM them to Siren so she can fix them.

True. ^^
Rather than posting things which show you can break the forum (I have many ways.. but I don't want to risk my account by testing) maybe you can PM them to Siren so she can fix them.

Stop trying to look 'l33t' in front of your peers.

Not trying to look L337 sir, so, carry on smartly.

This is no different than posting the text, except the forum won't let me.

How am I breaking the forum by using simple image tags?

If they had tested the forums and made sure they were working, I wouldn't have to screenshot posts in notepad and post the images.

I am not obligated to report anything. They are lucky I put it in my post.
Sometimes ignoring Purp's standards and requirements is the only way to go. He's much too picky for my taste, so that's what I do :D
Sometimes ignoring Purp's standards and requirements is the only way to go. He's much too picky for my taste, so that's what I do :D

Gotcha.

If the admins don't like it they can simply type it in for me and delete the image tags, or delete it and PM me about it.

I pay to post here, just like everyone else.
Sorry for being professional. Really.

Maybe I should go ahead and 'test' the stuff I've found. Oh.. maybe then I'd be banned or maybe you wouldn't have a forum for which you've paid to post on.
LOL, purp. We aren't professionals; we are gamers. And it's more the 2 cents you have to say about anyone who doesn't do things exactly how u want them done. But I <3 u anyway. I just try to balance out your sourpuss with some sugar :D
Sorry for being professional. Really.

Maybe I should go ahead and 'test' the stuff I've found. Oh.. maybe then I'd be banned or maybe you wouldn't have a forum for which you've paid to post on.

QQ moar about me posting an image of the post I wanted to write on the forums, but the forum wont' let me. It will only let me type very short messages, and seems to choke everytime you write more than 2 full paragraphs.

Don't care what you think, or how professional you want to be.

I will test to see if the ignore feature works, with you screen name.
The forums are about as easy to **** as the player database containing all player information including credit card information/login/passwords/etc
I mis-read your post Trensharo, for which I apologise. Not to worry though because you've ignored me.

QQ moar about me posting an image of the post I wanted to write on the forums, but the forum wont' let me. It will only let me type very short messages, and seems to choke everytime you write more than 2 full paragraphs.

Don't care what you think, or how professional you want to be.

I will test to see if the ignore feature works, with you screen name.
look at the bright side. If some1 somehow will get our accounts, im sure ncsoft will reward us with smth nice :) :) :)
im actually waiting for that
These forums are as secure as the forums they had before. Dunno why people are complaining en masse about this one when they didn't have a problem suplying these credentials on the other board. At least, I haven't read any threads about it in the past 2 years or so.
Well, on the other boards you had a specific pw for the boards. It was not your game pw.
Well, on the other boards you had a specific pw for the boards. It was not your game pw.

It was you game account name, though, and that's more than enough info.
It was you game account name, though, and that's more than enough info.

my forum name is NOT my game login name and same for a lot of other people :p yours is? :eek:
There is alot of scare mongering going on here by people who know very little about the subject of computer/internet security.
I completely agree. For those who don't know a lot... when you submit your forum username and password it's done via SSL. The same thing which is used to hide your credit card details when paying for your subscription or buying your latest game from an online store.

Both use similar levels of security... which do you treasure more? Your credit card or your L2 account?

There is alot of scare mongering going on here by people who know very little about the subject of computer/internet security.
There is alot of scare mongering going on here by people who know very little about the subject of computer/internet security.
To be honest Linka... from someone who has run forums under the SAME forum software as this.... it most certainly IS possible to have the forum hacked and the databases comprimised.... I had it happen twice to me a while back. I believe everyone has the right to be concerned and to want SEPERATE passwords, it's like having different passwords for all your accounts like a domain registrar, a online bank, your email and other things. The more secure you can be and not have the same password for EVERYTHING the safer you are online.
I completely agree. For those who don't know a lot... when you submit your forum username and password it's done via SSL.
Only if using the original login form. The page with the login form is provided to your browser without use of SSL, so even if it comes from the original L2 site, it can be modified with man-in-the-middle attack.

Both use similar levels of security... which do you treasure more? Your credit card or your L2 account?
Of course my L2 account. What do I lose on credit card number theft, half an hour of my time on filling a fraud report form?