Aye ye ye. Didn't I just get done saying IE is no less safe than FF?Originally Posted by aurik
I claim page five in the name of internet safety! Remember to wear your condoms on your CAT5 wires boys and girls!
Aye ye ye. Didn't I just get done saying IE is no less safe than FF?Originally Posted by aurik
I claim page five in the name of internet safety! Remember to wear your condoms on your CAT5 wires boys and girls!
What most of you aren't mentioning is that when someone gets hacked, SE doesn't just loose that one person's revenue. They also stand a very good chance of loosing the revenue for that person's friends, too. Two accounts hacked in my friend's salvage shell has that entire shell ready to pick up and hit WoW. She wants me to take over her account for the duration (just in case she wants to return).
The entire customer motive behind an established MMORPG is not "oh, I'll pay so I can play a month and who cares if it gets hacked." It's not like putting a quarter in a video game; play it for a bit, have some fun, walk away. It's "I'm paying because I don't want to loose my investment" and "I want to to build on past efforts." TRUST is the single most important factor in such a relationship between a company and a customer when continued subscription REQUIRES people to build on the results from previous sessions. It's the entire reason the MOORPG customer keeps paying: because he believes the game will still be there for him to play for a very long time to come.
If a large number of people start believing that FFXI will just suddenly go away one day soon, they'll stop playing and go elsewhere. There is literally no point at all in playing any MMORPG when you think the plug could be pulled on it at any moment.
SE's responses to these hack&sacks shows that they do not understand this at all. If they leave this issue unresolved, it could have truly severe repercussions for all of us who play the game. It would be VERY easy for SE to protect people from keyloggers and file theft. (Trivial programming effort -- couple days work & testing maximum). It would take more effort to put employee processes in place to recover hacked accounts, but IMHO, it really should be just about the absolute TOP priority on SE's plate right now.
SE inept handling of these hack&sack cases is destroying the trust that is the basis for their entire FFXI revenue stream.
Shouldn't it also be the company's reason as well, or are we not paying them enough each month for that?Accepting the fact that no product is safe upon release should be your reason to patch and update and if you don't then it's your fuckup, sorry.
Yes, but you're stupid and not to be believed.Originally Posted by Zero Serenity
Do not use Internet Explorer if you value your data security.
Originally Posted by Lucavi
Are we not assuming that the company is the one putting out the patches and updates in the first place? I thought it was pretty clear that I meant your reason to, y'know, download said patches and updates.
Unless its being hacked through a software or network server security vulnerability it is NOT SE's job in anyway to defend your PC against a hacker attack whether it be a keylogger or some other virus/trojan planted on your computer through an email or website attack. If its not being hacked through the software then SE can't be blamed in any way or form..Originally Posted by Ashira
Finally. More people that understand that it isnt all about scolding the playerbase for being a victim and more trying to keep the facade that the game is safe by eliminating this threat IMMEDIATELY and setting a great standard that SE isnt gonna let your investment isnt gonna go up in smoke. If this issue is left to grow, the implications that it could one day create if it becomes commonplace could END the game for many.
Finally... people who understand this isnt an issue for the present only. This could sow the seeds of alotta grievences in the future.
First mentioned at lolalla, but it's imporant for everyone to know.
Right now on the front page of ffxi.somepage.com there is a hidden iframe that loads a page with a javascript exploit.
If you right click and view sauce and search for iframe, it should be the first to pop up. If you don't and to risk going, I made an image found here
http://img409.imageshack.us/img409/9725/iframegm0.jpg
(Would have uploaded it to my own server, but being at school and all lol.)
The iframe loads up the url, at first glance some might say "oh it's just microsoft", but look at the url closely.. they're exploiting the fact that you read words as a whole and not letter by letter. On that page is the javascript exploit, pretty sure it uses a realplayer exploit, but I'm not positive.Code:ttp://www.miorsocft.com/help/help.htm
The fact that it's embedded in the last news post is what gets me, curious as to if the admin of the site realizes it's there or not. I suggest not going to somepage, at least for now, and to use FF with No Script enabled, I've seen a couple ads on ffxiah that try to get you to download fake antivirus software. RMT are desperate to make ends meet, I have a feeling our favorite sites are going to be targeted for some time...
edit: put the nasty url in code to help prevent clicking.
What exactly is so insecure about IE?
Updates are made much more commonly than they are for Firefox as well (I use Firefox by preference) just asking why.
1) Since IE is integrated with the OS (hooray, throughput?) that means exploits happen in kernel space instead of user space. Firefox is at least theoretically a userland application, therefore if you have permissions on your computer set right, malicious code will need to find a local exploit to get into kernel space to load a backdoor.Originally Posted by Seditedi
2) Since IE's userbase is larger and less technically sophisticated on average, they are a more appealing target for exploits. See also why 99% of virus makers target windows instead of Mac OS
3) Since IE's code is closed source, it is impossible to audit and, even worse, only Microsoft has the ability to respond effectively to exploits. With Firefox, exploits can be patched by virtually anyone, and thus their turnaround time on exploits is generally much better.
Let me make myself a bit more clear: name a patch that SE has ever released to help combat account theft, and/or to help account-holders recover their info after being hacked/attacked/ect.Are we not assuming that the company is the one putting out the patches and updates in the first place? I thought it was pretty clear that I meant your reason to, y'know, download said patches and updates.
1) Since IE is integrated with the OS (hooray, throughput?) that means exploits happen in kernel space instead of user space. Firefox is at least theoretically a userland application, therefore if you have permissions on your computer set right, malicious code will need to find a local exploit to get into kernel space to load a backdoor.
2) Since IE's userbase is larger and less technically sophisticated on average, they are a more appealing target for exploits. See also why 99% of virus makers target windows instead of Mac OS
3) Since IE's code is closed source, it is impossible to audit and, even worse, only Microsoft has the ability to respond effectively to exploits. With Firefox, exploits can be patched by virtually anyone, and thus their turnaround time on exploits is generally much better.
You forgot 4.
4) Plugins. Plugins. Plugins. The core difference between the 2 is you can increase security on your PC using plugins to block malicious ads and scripts for no added cost. Plugins are what make Firefox what it is. Lack of plugins coupled with complete OS integration make IE the most dangerous of all browsers.
The patch that enforced minimal password security.Originally Posted by Lucavi
The info is not being hacked through the POL software..
But yes, I do agree that SE should rethink their measures of re obtaining stolen account info.
Customer: My account info was compromised, password was changed
SE support: Ok, I'm going to need your name, address, phone number etc.
Customer: gives info
SE support: Also going to need your POL Registration keys and the last 4 digits of the credit card number on the account.
Customer: Gives info again, but credit card is not correct because hacked changed it already
SE support: I'm sorry I can't do anything for you.
Well done, and kudos to SE for that. Now, as for the second request?The patch that enforced minimal password security.
Yeah, Oku, I was going to make mention of this but it didn't really follow with other points in my arguments too well, but I was definitely thinking this point... nearly mentioned it after the thing about how RMT stolen accounts will eventually get banned, etc.Originally Posted by Okuza
Sedi: Again, nowhere did I say it's SE's fault that shit gets put out there that people are susceptible to. But they can do more to keep their customer base happy in trying to resolve these issues, first by recognizing them and then trying to remedy those situations made as a result. Hearing about people being told "there's nothing we can do" over and over and over again isn't very good for customer satisfaction.
Ironically since then more accounts have been compromised than before that patch. =/Originally Posted by aurik
What second request? You asked "and/or"Originally Posted by Lucavi
he chose "or", fulfilling your request!
Is it mainly PC player accounts being stolen, or are PS2 and Xbox360 accounts at risk, too?
Not true, over 300 accounts were vulnerable due to the FriendList Plus attack (ask Taj for the actual number), and I'm sure even more were at risk since you could derive the password on many accounts once you had the account number.Originally Posted by ronin sparthos