Pages: 1 2 :: [one page] |
|
Author |
Thread Statistics | Show CCP posts - 2 post(s) |
Mithridates VI
IMPSwarm Negative-Feedback
2028
|
Posted - 2013.07.03 10:02:00 -
[1] - Quote
Someone should probably mention to you guys that the mail servlet used to send out mass emails like "hey, players, there's a human endurance event" or "please fill out a survey" contains a link at the top labelled "View this message in a browser" which will open links.mail.dust514.com/servlet/MailView followed by a series of variables which tell the system who you are and which message you want to look at.
Unfortunately, if you make the appropriate changes to the part of the URL which tells the servlet who you are, you can view a message that was sent to someone else. You can also view the email address associated with their PSN. Presumably you could farm a list of character names and associated email addresses.
CCP were advised of this mid-May. It's on a third-party provider to actually fix the thing, but if CCP aren't going to disable the system, it seems appropriate that everyone be warned of the possibility that their email address has been disclosed. As far as I know, there is no evidence that this has occurred but it's polite to let customers know that the possibility existed.
I kind of expected that CCP would do this but, personally, have received no such notification, so here it is. Hopefully CCP comment in here to say that the reason no announcement was made is that they have fully explored the possibility of this being exploited and determined that nobody is at risk but the fact that the system remains vulnerable concerns me enough to advise players myself. |
Delta 749
Kestrel Reconnaissance
711
|
Posted - 2013.07.03 10:05:00 -
[2] - Quote
Well ****
Ugh, and Im betting now that some jackass who didnt notice this on his own is trying to farm email accounts now |
Kekklian Noobatronic
Goonfeet Special Planetary Emergency Response Group
109
|
Posted - 2013.07.03 10:09:00 -
[3] - Quote
Seems legit. Thanks for the heads up.
+1 for OP -1 for CCP not taking this seriously enough to fix sooner. |
GLiMPSE X
Internal Error. Negative-Feedback
205
|
Posted - 2013.07.03 10:10:00 -
[4] - Quote
Mithridates VI wrote:Someone should probably mention to you guys that the mail servlet used to send out mass emails like "hey, players, there's a human endurance event" or "please fill out a survey" contains a link at the top labelled "View this message in a browser" which will open links.mail.dust514.com/servlet/MailView followed by a series of variables which tell the system who you are and which message you want to look at.
Unfortunately, if you make the appropriate changes to the part of the URL which tells the servlet who you are, you can view a message that was sent to someone else. You can also view the email address associated with their PSN. Presumably you could farm a list of character names and associated email addresses.
CCP were advised of this mid-May. It's on a third-party provider to actually fix the thing, but if CCP aren't going to disable the system, it seems appropriate that everyone be warned of the possibility that their email address has been disclosed. As far as I know, there is no evidence that this has occurred but it's polite to let customers know that the possibility existed.
I kind of expected that CCP would do this but, personally, have received no such notification, so here it is. Hopefully CCP comment in here to say that the reason no announcement was made is that they have fully explored the possibility of this being exploited and determined that nobody is at risk but the fact that the system remains vulnerable concerns me enough to advise players myself.
This is why we keep you on staff there big dog... |
Banning Hammer
Tal-Romon Legion Amarr Empire
129
|
Posted - 2013.07.03 10:11:00 -
[5] - Quote
I never use important E-mail addresses for gaming, most of them are just Ghost hotmail E-mails, or inactive addresses. Hell.. i don't even check most of that E-mails, because i forgot the password of most of them. |
|
ChribbaX
Otherworld Enterprises Dust Control Otherworld Empire Productions
478
|
Posted - 2013.07.03 10:15:00 -
[6] - Quote
Not saying it's not good or anything, but wouldn't you think that actually bringing this public would make it happen faster than to keep pushing CCP to change their things... just a thought.
But then, I'm far more concerned over other things that needs sorted.
Good work!
edit/and for obvious reasons I'm now going to go do exactly what you warn about just because I wasn't aware of it
/c |
|
GLiMPSE X
Internal Error. Negative-Feedback
205
|
Posted - 2013.07.03 10:19:00 -
[7] - Quote
ChribbaX wrote:Not saying it's not good or anything, but wouldn't you think that actually bringing this public would make it happen faster than to keep pushing CCP to change their things... just a thought. But then, I'm far more concerned over other things that needs sorted. Good work! edit/and for obvious reasons I'm now going to go do exactly what you warn about just because I wasn't aware of it /c
Unfortunately, most of the time it takes public scrutiny to get these things pushed through. Mith followed the norm in the industry by giving them plenty of notice prior to publishing his findings. |
Mithridates VI
IMPSwarm Negative-Feedback
2032
|
Posted - 2013.07.03 10:24:00 -
[8] - Quote
GLiMPSE X wrote:Unfortunately, most of the time it takes public scrutiny to get these things pushed through. Mith followed the norm in the industry by giving them plenty of notice prior to publishing his findings.
Basically this is my position. I put a great deal of consideration into creating the thread, fully aware that disclosure would give a small window of opportunity to exploiters. Lack of disclosure gives a greater window.
I honestly expected a temporary solution to immediately close the hole. More than a month later, no such patch/service suspension is in place and without public attention the possibility exists that further time could be used by anyone else aware of the issue to exploit it.
IMO, ideally this thread will result in the servlet being taken offline in part or in whole until it is secure. |
|
ChribbaX
Otherworld Enterprises Dust Control Otherworld Empire Productions
478
|
Posted - 2013.07.03 10:25:00 -
[9] - Quote
GLiMPSE X wrote:ChribbaX wrote:Not saying it's not good or anything, but wouldn't you think that actually bringing this public would make it happen faster than to keep pushing CCP to change their things... just a thought. But then, I'm far more concerned over other things that needs sorted. Good work! edit/and for obvious reasons I'm now going to go do exactly what you warn about just because I wasn't aware of it /c Unfortunately, most of the time it takes public scrutiny to get these things pushed through. Mith followed the norm in the industry by giving them plenty of notice prior to publishing his findings. Yep it does. You'll get plenty of non PSN account trying to guess hashes there as well I'm sure, I know I'm signed up for their newsletters and stuff on addresses that are not PSN, but can agree it's a bit of bad habit to include the actual address in the html. |
|
|
ChribbaX
Otherworld Enterprises Dust Control Otherworld Empire Productions
478
|
Posted - 2013.07.03 10:27:00 -
[10] - Quote
Mithridates VI wrote:GLiMPSE X wrote:Unfortunately, most of the time it takes public scrutiny to get these things pushed through. Mith followed the norm in the industry by giving them plenty of notice prior to publishing his findings. Basically this is my position. I put a great deal of consideration into creating the thread, fully aware that disclosure would give a small window of opportunity to exploiters. Lack of disclosure gives a greater window. I honestly expected a temporary solution to immediately close the hole. More than a month later, no such patch/service suspension is in place and without public attention the possibility exists that further time could be used by anyone else aware of the issue to exploit it. IMO, ideally this thread will result in the servlet being taken offline in part or in whole until it is secure. Taking it offline would mean they now have their entire PR and game sendouts offline. Since it's used for anything that they send out and has been for years. But yeah leaving the unsubscribe and removing the email from html should be easy enough.
/c |
|
|
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
76
|
Posted - 2013.07.03 10:28:00 -
[11] - Quote
Oh, no! Not my email address!
That information is supposed to be top-secret level 5 classified! Now my secret identity is blown! My loved ones are in danger! |
Mithridates VI
IMPSwarm Negative-Feedback
2034
|
Posted - 2013.07.03 10:34:00 -
[12] - Quote
Jaqen Morghalis wrote:Oh, no! Not my email address!
That information is supposed to be top-secret level 5 classified! Now my secret identity is blown! My loved ones are in danger!
Seroiusly, though, what's the worst-case scenario here, some extra spam emails? Derp. I'm glad you don't suffer at all from having your email address known. Some would prefer their FirstName.LastName@gmail not be attached to their character. I don't mind giving them that right.
I'm out of this thread now. Those who are pleased to know, you're welcome. Those who inevitably react with"OMG MITHILEAKS", I'm not going to engage with because it would look too much like returning to the forums. |
Banning Hammer
Tal-Romon Legion Amarr Empire
129
|
Posted - 2013.07.03 10:40:00 -
[13] - Quote
Jaqen Morghalis wrote:Oh, no! Not my email address!
That information is supposed to be top-secret level 5 classified! Now my secret identity is blown! My loved ones are in danger!
Seroiusly, though, what's the worst-case scenario here, some extra spam emails?
Actually, worst-case scenario is typing about it in this thread..most of my E-mail accounts are ghost towns, that i use exclusively for spawn E-mails. Is where junk and spawn rubbish go to die....a graveyard for internet BS. |
|
CCP Eterne
C C P C C P Alliance
2258
|
Posted - 2013.07.03 10:42:00 -
[14] - Quote
I've snipped the explanation of how to do this, but I've also forwarded this on to our security team. Obviously giving people a way to farm the e-mail addresses of PSN accounts is not a good thing. EVE Online/DUST 514 Community Representative GÇ+ EVE Illuminati GÇ+ Fiction Adept
@CCP_Eterne GÇ+ @EVE_LiveEvents
Muhahaha, I have a signature and CCP Frame doesn't! |
|
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
77
|
Posted - 2013.07.03 10:45:00 -
[15] - Quote
Mithridates VI wrote:Jaqen Morghalis wrote:Oh, no! Not my email address!
That information is supposed to be top-secret level 5 classified! Now my secret identity is blown! My loved ones are in danger!
Seroiusly, though, what's the worst-case scenario here, some extra spam emails? Derp. I'm glad you don't suffer at all from having your email address known. Some would prefer their FirstName.LastName@gmail not be attached to their character. I don't mind giving them that right. I'm out of this thread now. Those who are pleased to know, you're welcome. Those who inevitably react with"OMG MITHILEAKS", I'm not going to engage with because it would look too much like returning to the forums.
Sorry, but I just don't see how this as the seroius issue that people are making it out to be. It's not my home address or credit card number, it's my email address, something that gets given out ALL the time!
Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security. |
Mithridates VI
IMPSwarm Negative-Feedback
2034
|
Posted - 2013.07.03 10:45:00 -
[16] - Quote
Fair enough if you want to edit out that bit, Eterne. Please also remove it from GLiMPSE X's post where it is quoted.
My feeling was that identifying the mail servlet gave as much useful info to a would-be attacker as that brief comment about the method, but I don't want to spell it out further than necessary if you think the post did that. |
GLiMPSE X
Internal Error. Negative-Feedback
205
|
Posted - 2013.07.03 10:48:00 -
[17] - Quote
Banning Hammer wrote:Jaqen Morghalis wrote:Oh, no! Not my email address!
That information is supposed to be top-secret level 5 classified! Now my secret identity is blown! My loved ones are in danger!
Seroiusly, though, what's the worst-case scenario here, some extra spam emails? Actually, worst-case scenario is typing about it in this thread..most of my E-mail accounts are ghost towns, that i use exclusively for spawn E-mails. Is where junk and spawn rubbish go to die....a graveyard for internet BS.
The 'worst case' isn't increased spam, it's losing your unspent sps, wallet, and that of your corp. |
Mithridates VI
IMPSwarm Negative-Feedback
2036
|
Posted - 2013.07.03 10:48:00 -
[18] - Quote
Jaqen Morghalis wrote:Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security.
I'm not going to enumerate the possible attacks based on having the personal details and PSN login of another player because I don't want to give anyone any ideas. Sorry if that doesn't convince you, but I'm mainly looking to advise people who feel it significant. |
Heinz Doofenshertz
BetaMax. CRONOS.
417
|
Posted - 2013.07.03 10:49:00 -
[19] - Quote
woo, my email address is known, it's not like I don't advertise it on my website, or someone couldn't guess it from my psn name or anything. |
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
77
|
Posted - 2013.07.03 10:54:00 -
[20] - Quote
Mithridates VI wrote:Jaqen Morghalis wrote:Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security. I'm not going to enumerate the possible attacks based on having the personal details and PSN login of another player because I don't want to give anyone any ideas. Sorry if that doesn't convince you, but I'm mainly looking to advise people who feel it significant.
I still don't understand (honestly, sorry if I'm being dense). I thought you said a person could get my email address, so where are they getting "personal details" and my login password from?
Without those, what's the worst they could do, send me emails?
How is my email address alone enough information to be in any way useful? |
|
Banning Hammer
Tal-Romon Legion Amarr Empire
130
|
Posted - 2013.07.03 10:57:00 -
[21] - Quote
Right... so is that EvE metagaming thing you guys are worrying about. I guess i can understand that, but... still...Who will hack an account just for that ? it seems a sad thing to do, and that people should get a life. |
GLiMPSE X
Internal Error. Negative-Feedback
205
|
Posted - 2013.07.03 10:57:00 -
[22] - Quote
Jaqen Morghalis wrote:Mithridates VI wrote:Jaqen Morghalis wrote:Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security. I'm not going to enumerate the possible attacks based on having the personal details and PSN login of another player because I don't want to give anyone any ideas. Sorry if that doesn't convince you, but I'm mainly looking to advise people who feel it significant. I still don't understand (honestly, sorry if I'm being dense). I thought you said a person could get my email address, so where are they getting "personal details" and my login password from? Without those, what's the worst they could do, send me emails? How is my email address alone enough information to be in any way useful?
google. |
Khal V'Rani
Nephilim Initiative
152
|
Posted - 2013.07.03 11:02:00 -
[23] - Quote
Mithridates,
Just thought I'd pop in and say I'm slowly becoming a fan of your postings. Keep up the good work.
+1 |
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
77
|
Posted - 2013.07.03 11:03:00 -
[24] - Quote
It's an email address.
That thing is on my business cards! I give them out to strangers! Gasp! Oh noooooeeeeeesssssss!!!!!
Just seems like an awful lot of trouble for someone to go through just to spam me with emails. There are far easier, and more effective, ways to cause me harm, if someone really wanted to. |
Shion Typhon
Intara Direct Action Caldari State
92
|
Posted - 2013.07.03 11:10:00 -
[25] - Quote
Jaqen Morghalis wrote:Mithridates VI wrote:Jaqen Morghalis wrote:Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security. I'm not going to enumerate the possible attacks based on having the personal details and PSN login of another player because I don't want to give anyone any ideas. Sorry if that doesn't convince you, but I'm mainly looking to advise people who feel it significant. I still don't understand (honestly, sorry if I'm being dense). I thought you said a person could get my email address, so where are they getting "personal details" and my login password from? Without those, what's the worst they could do, send me emails? How is my email address alone enough information to be in any way useful?
Because one of those 100 internet sites / services you've signed up for with your email as your username has $hit security and allows you to reset your password w/o a second level of authentication. Then in that 1 site you've also input your date of birth or home address which is the authentication factor for 3 more sites which then .... etc etc etc. 15 steps later they're in a site/game that has your credit card saved on file and is susceptible to buying in-game currency which can be RMT'd or whatever.
Security breaches occur across a multitude of interconnections, often run by people other than the original source. You might split your emails but having your primary gaming email in the wild is rarely awesome. |
Takahiro Kashuken
Red Star. EoN.
587
|
Posted - 2013.07.03 11:14:00 -
[26] - Quote
Dont use an important email for gaming?
Generally i check it now n again and if its not emails about forums posts or getting banned its spam anyways advertising **** games to me on the PSN |
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
77
|
Posted - 2013.07.03 11:16:00 -
[27] - Quote
Shion Typhon wrote:Jaqen Morghalis wrote:Mithridates VI wrote:Jaqen Morghalis wrote:Maybe if you could explain how this grievous oversight and negligence on CCP's part might potentially cause me more than a slight inconvenience, I might share your concern over this "threat" to my personal security. I'm not going to enumerate the possible attacks based on having the personal details and PSN login of another player because I don't want to give anyone any ideas. Sorry if that doesn't convince you, but I'm mainly looking to advise people who feel it significant. I still don't understand (honestly, sorry if I'm being dense). I thought you said a person could get my email address, so where are they getting "personal details" and my login password from? Without those, what's the worst they could do, send me emails? How is my email address alone enough information to be in any way useful? Because one of those 100 internet sites / services you've signed up for with your email as your username has $hit security and allows you to reset your password w/o a second level of authentication. Then in that 1 site you've also input your date of birth or home address which is the authentication factor for 3 more sites which then .... etc etc etc. 15 steps later they're in a site/game that has your credit card saved on file and is susceptible to buying in-game currency which can be RMT'd or whatever. Security breaches occur across a multitude of interconnections, often run by people other than the original source. You might split your emails but having your primary gaming email in the wild is rarely awesome.
Fair enough, thank you for the explanation.
Still not too worried, though. |
|
CCP Stillman
C C P C C P Alliance
1
|
Posted - 2013.07.03 11:21:00 -
[28] - Quote
Hi there,
We were indeed made aware of a vulnerability in the email system that we use, which is a third-party hosted system. When we were made aware, we rewarded the reporter as per our PLEX for Snitches program, and we contacted our partners who handle this for us to address the issue.
As a part of that, we no longer include the email which it's sent to as a part of the mail. Also, technical changes were made on the backend to prevent abuse of this at a large scale. We're still actively working with them to fix this issue fully, but this is not something that gets done over night.
We're always extremely grateful when people report these sorts of things to us, and rest assured we took action and had a conference call with our partners the very same day we became aware, and we continue to work with them to ensure that this problem is sorted out fully.
-Stillman |
|
Crash Monster
Snipers Anonymous
912
|
Posted - 2013.07.03 12:16:00 -
[29] - Quote
To those saying "so what" I'd suggest that as you develop a larger internet presence it gets easier to track you down. If your email contains your name, and you provide identifying comments in a forum, then a Google search on your name might lead to memberships, schools, publications, facebook, etc.
Even a small item like this can be the missing element that ties all your internet activity together and zeros in on you, your home, your job and/or your family. If you don't have your own family yet then maybe you don't understand the concern level that this can cause for some people.
It's great that you personally don't mind... but some people actual desire (or need) privacy for various reasons. |
Jin Robot
Foxhound Corporation General Tso's Alliance
1187
|
Posted - 2013.07.03 12:22:00 -
[30] - Quote
I am so secretive, even I dont know my real name. |
|
steadyhand amarr
Royal Uhlans Amarr Empire
750
|
Posted - 2013.07.03 12:30:00 -
[31] - Quote
To day I learned how little people know about internet security and how damage can be done with just your email :-( |
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
78
|
Posted - 2013.07.03 13:03:00 -
[32] - Quote
steadyhand amarr wrote:To day I learned how little people know about internet security and how damage can be done with just your email :-(
Meh, a little common sense and due caution goes a long way.
I generally don't volunteer any personal info when registering on forums and such, I rarely use my credit card online (and when I do, it's with sites that I am reasonably confident are as secure as possible), I monitor my credit card balance frequently and regularly, I use PSN Cards for PSN purchases, and I've got multiple "junk" emails, all with different passwords.
To do me any real harm, a person would need much more than just this one email address (even factoring in any other information about me that they could possibly extrapolate from it). I'm not saying it isn't possible but, to target me specifically, a person would have to be pretty determined, and spend quite a bit of time and effort to expand that one email address into something that would actually hurt me.
If they're THAT determined, then they've got a serious vendetta against me for some reason, and will probably find some other, easier, more effective and direct way to hurt me, even if they didn't have my email address.
The only other way this could affect me is if I'm just unfortunate enough to be either randomly selected, or one of many victims in some sort of mass-fraud, and the common sense and due caution that I mentioned above should protect me.
Besides, I could also get hit by a bus on my way to work, that doesn't mean I'll never go outside again.
Face it, stuff happens and, personally, I prefer not to spend my life worrying about every little thing that might possibly happen under just the right set of circumstances. You can't protect yourself from everything.
Obviously I do whatever I reasonably can to protect myself, but I'm not going to lose any sleep because someone might have access to one of my email addresses.
Living in fear is not living.
/rant |
Draxus Prime
BurgezzE.T.F
840
|
Posted - 2013.07.03 13:43:00 -
[33] - Quote
CCP Eterne wrote:I've snipped the explanation of how to do this, but I've also forwarded this on to our security team. Obviously giving people a way to farm the e-mail addresses of PSN accounts is not a good thing. i want a signuture |
semperfi1999
Internal Error. Negative-Feedback
557
|
Posted - 2013.07.03 14:04:00 -
[34] - Quote
Jaqen Morghalis wrote:steadyhand amarr wrote:To day I learned how little people know about internet security and how damage can be done with just your email :-( Meh, a little common sense and due caution goes a long way. I generally don't volunteer any personal info when registering on forums and such, I rarely use my credit card online (and when I do, it's with sites that I am reasonably confident are as secure as possible), I monitor my credit card balance frequently and regularly, I use PSN Cards for PSN purchases, and I've got multiple "junk" emails, all with different passwords. To do me any real harm, a person would need much more than just this one email address (even factoring in any other information about me that they could possibly extrapolate from it). I'm not saying it isn't possible but, to target me specifically, a person would have to be pretty determined, and spend quite a bit of time and effort to expand that one email address into something that would actually hurt me. If they're THAT determined, then they've got a serious vendetta against me for some reason, and will probably find some other, easier, more effective and direct way to hurt me, even if they didn't have my email address. The only other way this could affect me is if I'm just unfortunate enough to be either randomly selected, or one of many victims in some sort of mass-fraud, and the common sense and due caution that I mentioned above should protect me. Besides, I could also get hit by a bus on my way to work, that doesn't mean I'll never go outside again. Face it, stuff happens and, personally, I prefer not to spend my life worrying about every little thing that might possibly happen under just the right set of circumstances. You can't protect yourself from everything. Obviously I do whatever I reasonably can to protect myself, but I'm not going to lose any sleep because someone might have access to one of my email addresses. Living in fear is not living. /rant
Actually all this "time" you claim someone is spending...........is not true. By and large someone who had the technical skills to obtain your email from this system would not then personally try to put your information in other sites looking for a hit...they have a bot program that does all of that for them. They literally would only have to check the bot on occasion and perhaps do a couple things when its required of them by it would mostly be an automated system that your information would be put into.
So saying someone would have to spend a lot of "time" to get this information on your is just ludicrous...they dont spend alot of time on any single person. They get massive amounts of data and put them into bot programs to sift the data and collect everything they can so that they can use it or sell it to someone who wants to use it.
BTW I completely agree with steadyhand......apparently I have long overestimated the technical knowledge of gamers. It would appear that many gamers have no clue of anything regarding the computers/internet beyond....I click this button and it works and if it doesnt work then I call tech support. |
Jaqen Morghalis
Abandoned Privilege General Tso's Alliance
78
|
Posted - 2013.07.03 14:28:00 -
[35] - Quote
lol, you make it sound like they can just type my email address into the magic internet box and the magic computer bots do their computer magic and PRESTO, they have full access to my entire life!
Is it possible that someone could conceivably use information from the internet to steal my identity and/or access my money?
I suppose so, which is why I do take certain reasonable precautions when conducting business online.
On the other hand, It's also possible that I could be randomly shot by a total stranger while walking down the street.
But, is it likely?
Probably not. |
HowDidThatTaste
Internal Error. Negative-Feedback
2910
|
Posted - 2013.07.03 15:42:00 -
[36] - Quote
Sometimes you just got to wear the tinfoil hat. |
HowDidThatTaste
Internal Error. Negative-Feedback
2910
|
Posted - 2013.07.03 15:44:00 -
[37] - Quote
Sometimes you just got to wear the tinfoil hat. |
Shion Typhon
Intara Direct Action Caldari State
93
|
Posted - 2013.07.04 02:20:00 -
[38] - Quote
Jaqen Morghalis wrote:lol, you make it sound like they can just type my email address into the magic internet box and the magic computer bots do their computer magic and PRESTO, they have full access to my entire life!
Is it possible that someone could conceivably use information from the internet to steal my identity and/or access my money?
I suppose so, which is why I do take certain reasonable precautions when conducting business online.
On the other hand, It's also possible that I could be randomly shot by a total stranger while walking down the street.
But, is it likely?
Probably not.
You should read the article by the head of security from SOE on the Planetside 2 team. Its quite interesting.
One of the factors they discussed is that most intrusion attempts on accounts on their network are not random. They don't get mass brute force attempts at cracking passwords by trying millions of alphanumeric combinations. Most of the intrusion attempts that occur show evidence of information gathering/social engineering by the bot.
So, they'll get an access attempt against a single email address then 10 different password attempts where the passwords are clearly word combinations lifted from somewhere (implying the bot is attempting to combine information about the user collected elsewhere, DOB+home city, etc etc etc or a combo phrase clearly used a password on some other site).
How many users do you think use the same password for their IGN website login, their iTunes account, their SOE/Dust login and "that cool forum about games they visit".
Answer: Lots.
Physical and electronic security are the same, they are about layers. You have a spectrum of layered measures that can be applied ranging from "nothing" to "completely ridiculous". Every time you add a layer you exclude a potential threat level and also make it harder to perform the activity in question. You stop adding security when you hit the boundary curve between likely threats and useability.
Unfortunately most people who aren't security experts and especially in the digital world usually stop a few layers short of what is required to protect themselves adequately (not perfectly). |
LuckyLuke Wargan
HavoK Core RISE of LEGION
188
|
Posted - 2013.07.04 02:31:00 -
[39] - Quote
Another check mark in my long list of CCP **** ups... |
Mithridates VI
IMPSwarm Negative-Feedback
2047
|
Posted - 2013.07.04 06:49:00 -
[40] - Quote
CCP Stillman wrote:When we were made aware, we rewarded the reporter as per our PLEX for Snitches program. This is true.
CCP Stillman wrote:As a part of that, we no longer include the email which it's sent to as a part of the mail. Also, technical changes were made on the backend to prevent abuse of this at a large scale. We're still actively working with them to fix this issue fully, but this is not something that gets done over night.
I'm glad to hear that something has been done to prevent large scale abuse but it's surprising to see that something like programatically removing the email addresses from historical messages is not possible. If control over the content of an email is not made possible by hosting it in full I'm afraid I don't see the point in the system used to host the messages at all.
|
|
|
|
|
Pages: 1 2 :: [one page] |