After my recent hacking and after several clannies going through it I believe it is seriously time to change update the PlayNc account saftey.
First, you should not be allowed to change your email without an email going to you previous email address notifying you that your email is being change and if this is not you to immediately reply to email to lock your accounts down.
Second, you should not be able to change your secret questions without knowing the previous answers to the questions. My secret question answers were changed and I haven't input them in over 6 years. There was no way a hacker could see them from a keylogger or trojan so they shouldn't be able to be changed to a different answer.
Also, if all the info is suddenly changed IE email, all account passwords, master password etc Account should be flagged and locked down. No one will do all these changes all within a matter of seconds/minutes.
Also there needs to be a way either in game or out of game for a customer to immediately report and lock down their accounts. It will save hours of GM's time not having to go through trade logs if accounts can be locked down within minutes instead of hours/days.
Many hackers wait until after 5pm pst when account services closes to **** the accounts even if they have had the passwords for days or weekends so response time is slowed and they can fully clean out the accounts without being slowed down.
I believe alot of these changes will help NCSoft staff and the players increase their account security. No matter how safe someone is there is always a chance of getting hacked some hackers do it by brute force some do it with viruses. I was in game when I was hacked so if I had a way to lock my accounts down most of my belongings would still be there and it may only took a day or so to replace the things they did get off quickly like adena etc.
Any one else have any suggestions for producer etc. to change the account security?
Smittie I think you know me well enough I do not share any of my info with anyone. So its not claiming to be hacked there was a real virus there.
I like to add in that they deleted all my credit card info and cancelled all my accounts. I guess hoping I wouldn't find the trojan and they would then have all my credit card info too.
This just keeps getting better.
How do they cancel your accounts and billing and you do not get a email for that either?
I lost this account last week and never shared the info. Not once in 6 years. I lost 130+ mil adena and tons of ab abd c stuff. Thinkfully it isn't my main or i'd be over.
Smittie I think you know me well enough I do not share any of my info with anyone. So its not claiming to be hacked there was a real virus there.
I like to add in that they deleted all my credit card info and cancelled all my accounts. I guess hoping I wouldn't find the trojan and they would then have all my credit card info too.
This just keeps getting better.
How do they cancel your accounts and billing and you do not get a email for that either?
And what kind of security do you use on your computer, that lets a virus get through?
EDIT: By the way, the Korean L2 already has this in place since more than a year.
Yup, and I can't understand why we do not get something like it, too. Especially if they would just offer it as an "upgrade option", i.e. pay ten dollars to get a security token. Most players I know would buy it in a heartbeat. As I understand it, in Korea they send the password to your mobile phone, that would of course not work for our servers. But one of those small security tokens, like WoW/Paypal/RSA etc.offer them, that would work and would 100% prevent account hacking (that is, if they ask for the password from the device even if you click the "I forgot my standard account password" link).
Yup, and I can't understand why we do not get something like it, too. Especially if they would just offer it as an "upgrade option", i.e. pay ten dollars to get a security token. Most players I know would buy it in a heartbeat. As I understand it, in Korea they send the password to your mobile phone, that would of course not work for our servers. But one of those small security tokens, like WoW/Paypal/RSA etc.offer them, that would work and would 100% prevent account hacking (that is, if they ask for the password from the device even if you click the "I forgot my standard account password" link).
The SMS service would kind of work in Europe. First, only the sender has to pay for them; second, bulk rates for sending are in single cents per hundredth of SMS (that's for Germany, but most of the others should have similar priciing). Third, nearly everyone in the target demographics already has a mobile phone.
An additional idea would be emergency/restricted passwords to an account, by the way. The "emergency" password would lock the account, kick the chars out of the game and open a support ticket. The restricted would only allow you to add GTCs, purchase account services like renames, gender changes and so on, but not change any contact data or passwords - basically, the web site's equivalent of running under a normal user account instead of an administrative one.
The SMS service would kind of work in Europe. First, only the sender has to pay for them; second, bulk rates for sending are in single cents per hundredth of SMS (that's for Germany, but most of the others should have similar priciing). Third, nearly everyone in the target demographics already has a mobile phone.
I am just not sure it would work for a service like L2 with players from all over the world (NA, Russia, Australia, Europe, ...). The little security tokens which show you a number and you then enter that number at the login screen would probably be cheaper overall, especially if you sell them to players at $10 to $15 each (i.e. at a profit) - something probably most players would be willing to pay. After that, there's no real running cost except for replacing the token once every 2-3 years.
And what kind of security do you use on your computer, that lets a virus get through?
Thats not a very intelligent question! It doesn't matter what security you have if you are targeted your screwed. There isn't a security program out there that can prevent new attacks/hacks they all work after the fact. You have a better chance of not being victimized if you keep everything up to date, but nothing can prevent everything from getting through.
The question should be, Why don't companies who accept payment on line continually upgrade and change their procedures so it's harder for hackers to beat.
It will come to a point in the near future, that nothing will be safe on line and everything important will be done through snail mail again or in person. The good guys are loosing to the bad guys on line at such a huge rate it's ugly.
I am just not sure it would work for a service like L2 with players from all over the world (NA, Russia, Australia, Europe, ...). The little security tokens which show you a number and you then enter that number at the login screen would probably be cheaper overall, especially if you sell them to players at $10 to $15 each (i.e. at a profit) - something probably most players would be willing to pay. After that, there's no real running cost except for replacing the token once every 2-3 years. I really like L2; but im sorry, at this point im not willing to give them any more money than I already do.
Thats not a very intelligent question! It doesn't matter what security you have if you are targeted your screwed. There isn't a security program out there that can prevent new attacks/hacks they all work after the fact. You have a better chance of not being victimized if you keep everything up to date, but nothing can prevent everything from getting through.
The question should be, Why don't companies who accept payment on line continually upgrade and change their procedures so it's harder for hackers to beat.
It will come to a point in the near future, that nothing will be safe on line and everything important will be done through snail mail again or in person. The good guys are loosing to the bad guys on line at such a huge rate it's ugly.
Is that a challenge because I know several people who love the challenge of destroying an ignorant person like yourself computer in matter of minutes.
It is like saying someone is stupid because their car got stolen or their house got broken into. You can be ultra-paranoid and be ultra-safe and it can still happen.
You comments make no sense. 7 years of having a clean computer and I get a virus and hacked does not make me stupid makes me unlucky. If i got hacked every 2 weeks then yes you could put me in the stupid category. So before you open your mouth you really need to think your words through because I will bet money if someone wants to access your account they will no matter how smart you think you are.
Like someone else posted on another thread, a line from the matrix movie.... "Hacking a computer, all takes is time" for me it took them 7 years :-/
Regardless you add nothing to this thread and are just being a troll. PlayNC security needs to updated, stay on topic or Ill ask your comments be deleted from a constructive thread. This is about changes that need to be made because of outdated security features on their account site.
The SMS service would kind of work in Europe. First, only the sender has to pay for them; second, bulk rates for sending are in single cents per hundredth of SMS (that's for Germany, but most of the others should have similar priciing). Third, nearly everyone in the target demographics already has a mobile phone.
An additional idea would be emergency/restricted passwords to an account, by the way. The "emergency" password would lock the account, kick the chars out of the game and open a support ticket. The restricted would only allow you to add GTCs, purchase account services like renames, gender changes and so on, but not change any contact data or passwords - basically, the web site's equivalent of running under a normal user account instead of an administrative one.
I like the idea of the emergency password. Sort of like a panic button only works 1 time. A trojan would never pick up on it because if you use it becomes useless and you need to select a new one when your accounts are no longer locked down. It would eliminate most of the hacking problems especially if your being hacked while playing you know its happening but have very little time to slow the bandits down. I would see this stop 95% of your items from being taken you may only lose adena and some gear by the time it gets locked, making the time GM's need on recovery a lot shorter and make it less profitable for hackers in the first place because they benefit very little from it.
Is that a challenge because I know several people who love the challenge of destroying an ignorant person like yourself computer in matter of minutes.
It is like saying someone is stupid because their car got stolen or their house got broken into. You can be ultra-paranoid and be ultra-safe and it can still happen.
You comments make no sense. 7 years of having a clean computer and I get a virus and hacked does not make me stupid makes me unlucky. If i got hacked every 2 weeks then yes you could put me in the stupid category. So before you open your mouth you really need to think your words through because I will bet money if someone wants to access your account they will no matter how smart you think you are.
Like someone else posted on another thread, a line from the matrix movie.... "Hacking a computer, all takes is time" for me it took them 7 years :-/
Regardless you add nothing to this thread and are just being a troll. PlayNC security needs to updated, stay on topic or Ill ask your comments be deleted from a constructive thread. This is about changes that need to be made because of outdated security features on their account site.
Maybe you can stop listening to your own voice long enough to see who I quoted when I replied?
And then check who you quoted when you replied?
I'll tell you this though, you arent looking all that bright at the moment.
Oh that hurts lol, not. Nice try. You will some day everyone does eventually. Just consider yourself lucky, if you get targeted you wont be able stop it.
Until then though go ahead and enjoy your throne on the better than everyone else hill. Eventually someone will take your place.
You keep saying that you got no e-mail from NC, I would check your profile then, because if your e-mail info was up to date you would have received a e-mail from NC the minute your password was changed, even if they changed your e-mail information while they were changing your password. And no matter what you say, you did not get a trojan simply by visiting blah, or logging into your acct on blah, you had to have clicked on something that no one in their right mind's would have even if you did inadvertently, or DLed something.
And people asking what you use for AV/security isn't stupid, by your way of saying it hadn't updated at that present time norm means you need to think about getting something better, any decent AV out there nowaday's updates every few hour's, not every few day's, because virus definition's change that fast.
Any decent AV would have given you a warning if it was running in that background at the time, and probably stopped it in its track's.
There's no reason NOT to have your AV running in the background at all times if you are running around on the web, if you say you had it turned off at the time because you were also in game, and wanted your PC to respond faster, either you need a better PC, or you shouldn't be surfing while playing.
You keep saying that you got no e-mail from NC, I would check your profile then, because if your e-mail info was up to date you would have received a e-mail from NC the minute your password was changed, even if they changed your e-mail information while they were changing your password. And no matter what you say, you did not get a trojan simply by visiting blah, or logging into your acct on blah, you had to have clicked on something that no one in their right mind's would have even if you did inadvertently, or DLed something.
And people asking what you use for AV/security isn't stupid, by your way of saying it hadn't updated at that present time norm means you need to think about getting something better, any decent AV out there nowaday's updates every few hour's, not every few day's, because virus definition's change that fast.
Any decent AV would have given you a warning if it was running in that background at the time, and probably stopped it in its track's.
There's no reason NOT to have your AV running in the background at all times if you are running around on the web, if you say you had it turned off at the time because you were also in game, and wanted your PC to respond faster, either you need a better PC, or you shouldn't be surfing while playing.
I did not get any email from NCSoft at all, when I changed my passwords back I immediately got email confirmations so yes there is a problem with PlayNC if when hacked the account is not sending out warning emails.
Also my virus software updated on 11/1/10. The virus came on my pc somewhere between 11/2/10 and 11/10/10. The virus definition for that particular virus history stated the orginal virus was created in 2005, last update to it was Oct 18th, 2010, and a recent update was 11/11/10 when it got caught on my PC. So no matter what it wouldn't been caught for those 10 days which is still very good for any virus program to find a new virus anyway.
Yes no email for ncsoft I was in game when I was kicked off and nothing received about changing my email or my passwords so thats a fault of PlayNC security that needs to be changed.
Why do people like to use the word hacked when they've been a victim of a trojan?
Trojan virus is a tool of hacker. If you do not know how to **** a trojan is pointless, you need to be able to program a virus and enable you to open a backdoor into the person's computer to allow you to retrieve the information from the trojan otherwise its just a useless program.
Hacking (English verb to ****, singular noun a ****) refers to the re-configuring or re-programming of a system to function in ways not facilitated by the owner, administrator, or designer
IE using a program to allow you to obtain information not facilitated by the owner is one way to ****.
Sly brings up a good point. Some changes should happen to the account security. In Sly's case he got a trojan, you can be as safe as you possibly can, sometimes it just happens.
Before I stated playing Lineage2 again, I had my PlayNC account hacked. The first thing they did was change my email address which was linked to my Blackberry. I never received one notification that my email had been changed. They then changed my password, security questions and passwords, even went so far as to put in a fake address. I wasn't the only one that got hit around that time. I know it wasn't a trojan, because I hadn't logged into my PlayNC account since I had changed the password (months ago), plus my system was clean. I still wonder how it happen, but I'm glad it all got worked out in the end. I read many rumors from a NCSoft DB getting hacked, to a popular Aion site getting hacked. I probably just got phished by someone and that was the price I paid for not paying attention. However....
Had NCSoft had some more measures up, instead of me trying to go back to Aion and finding out that the account had been banned and having to deal with the phone support, which was very pleasent, I would have maybe been able to pervent something from happening if I was notified about my email address changing. Even to go so far as make any and all changes required your security answers is a step further then what we have currently.
So, please, lets keep the thread on the topic at hand and not doom it right out of the gate. You, nor I, have any proof that Sly clicked on a link or DLed anything. Yes, those are two popular methods of getting a trojan onto someones system, but it is by far not the only way. S(%* happens, just remember when it happens to you what do you want people to remember when you bring it up?
Before I stated playing Lineage2 again, I had my PlayNC account hacked. The first thing they did was change my email address which was linked to my Blackberry. I never received one notification that my email had been changed. They then changed my password, security questions and passwords
Major note to NCSoft: NOTHING on the master account should be able to be changed AT ALL without 1st knowing the correct answers to the current security questions.
You keep saying that you got no e-mail from NC, I would check your profile then, because if your e-mail info was up to date you would have received a e-mail from NC the minute your password was changed, even if they changed your e-mail information while they were changing your password. And no matter what you say, you did not get a Trojan simply by visiting blah, or logging into your acct on blah, you had to have clicked on something that no one in their right mind's would have even if you did inadvertently, or DLed something.
Come on are you serious! First it's obvious that whoever is doing this is circumventing the system. They are getting into the accounts and changing passwords and security questions and answers in a way that doesn't trigger the automatic email notification system. Before my account was hacked every time I changed the password or changed anything in my master NC account or game password I received a email verification. After I got my account back I had to change the password but didn't change the email account. Guess what, I got an email notification. I have gotten one every time since. Also if you think you cannot get a virus from just going to a web site you no little about the Internet, or work in the business and blinded by pride.
And people asking what you use for AV/security isn't stupid, by your way of saying it hadn't updated at that present time norm means you need to think about getting something better, any decent AV out there nowadays updates every few hour's, not every few day's, because virus definition's change that fast.
Any decent AV would have given you a warning if it was running in that background at the time, and probably stopped it in its track's.
This is totally false no security system will stop a Trojan or anything else it does not have a definition for. Security programs are only as good as the people who run them and keep their libraries up to date. Anything new will get through until it's caught, diagnosed and a prevention is built to combat it.
There's no reason NOT to have your AV running in the background at all times if you are running around on the web, if you say you had it turned off at the time because you were also in game, and wanted your PC to respond faster, either you need a better PC, or you shouldn't be surfing while playing.
Now this is a true statement, you should never be on line without your security program turned on and monitoring the system.
And what kind of security do you use on your computer, that lets a virus get through?
Actually Smittie, that's not a valid question..
I work for a company who are REALLY hot on security, always up to date on virus protection and lockdown pretty much everything on the systems.
A couple of weeks ago we were hit with a Trojan "dropper" - the payload for this could have been anything, pretty much all of our internal systems were hit. the FOLLOWING DAY semantic, Sophos, AVG and others came out with a hot-fix to remove the trojan.
It was new, it was fast and it was expensive.
so I'll repeat how I started this reply. your question is not valid.
but I'm sure that wont stop your ******** comments, but meh.
I did not get any email from NCSoft at all, when I changed my passwords back I immediately got email confirmations so yes there is a problem with PlayNC if when hacked the account is not sending out warning emails.
Also my virus software updated on 11/1/10. The virus came on my pc somewhere between 11/2/10 and 11/10/10. The virus definition for that particular virus history stated the orginal virus was created in 2005, last update to it was Oct 18th, 2010, and a recent update was 11/11/10 when it got caught on my PC. So no matter what it wouldn't been caught for those 10 days which is still very good for any virus program to find a new virus anyway.
Yes no email for ncsoft I was in game when I was kicked off and nothing received about changing my email or my passwords so thats a fault of PlayNC security that needs to be changed.
I just read this post .. this is about the date our "dropper" trojan hit us....
Actually Smittie, that's not a valid question..
I work for a company who are REALLY hot on security, always up to date on virus protection and lockdown pretty much everything on the systems.
A couple of weeks ago we were hit with a Trojan "dropper" - the payload for this could have been anything, pretty much all of our internal systems were hit. the FOLLOWING DAY semantic, Sophos, AVG and others came out with a hot-fix to remove the trojan.
It was new, it was fast and it was expensive.
so I'll repeat how I started this reply. your question is not valid.
but I'm sure that wont stop your ******** comments, but meh.
I'm sorry, but I'm having a really hard time taking you seriously with all those numbers at the end of your name. Is it a serial number?
2 of my clannies got recently hacked and are currently under support tickets. In addition, one of them found a trojan inside google chrome plugins. So the vulnerability might be through google chrome. (more research needs to be done in this one)
In addition, in the 1 year I have been a clan leader I have seen (without counting this last 2) about 3 or 4 more accounts get hacked / wiped where noone had their info. After placing a ticket NCsoft gave the stuff back which means it was clearly some kind of vulnerability on their part.
One time, one of our buddies was playing and he received the messege "somene has logged in to your account" and nobody had his account. While he kept trying to relogin to his account (in order to keep kicking whoever was trying to login), he gave me his plaync.com account info and I was able to change his password. After that he formated his computer, and was safe and nothing happened. The point is that this things happen. They have not happened to me I trully beleive it happened to other people through no fault of their own.
My account was cleaned out back in july. they didnt send me any notification email when they changed my account info. The most interesting part about this is that the game was not even installed for nearly a year on my brand new pc and they happened to wipe me out. There is no virus.. it was hacked on ncsoft side in this case.
Granted ncsoft has returned majority of my gear, but i at a loss of more than 500 million adena of "consumables" crystals, pots, mats, etc and a few weapons that convienantly never got returned. 5 years of collecting those items GONE. As a victim i was penalized. OP suggestion is correct. Also thos victimized, GM should be able to roll back the account just when the mass changes to the ncsoft account so they would not have to go thru all the logs trying to return the account to original state with just the minimal of returning main gear back and adena. Everything should have been returned:mad::mad:.