-
Oct 17 2011 11:25 PM #81
Re: Official Thread: Community Site Issues Discussion
I am in the IT Security industry. So I know that #### happens.
What counts is too keep your customers happy.
To keep worried customers in the dark is the WORST possible way to handle it!
Your only chance is to keep your customers informed. Show them that you are able to react professional.
I am really worried now that I had to realize you aren't able to deal with such a situation in a professional way.
What of my data did get disclosed? And I am not asking politely. I DEMAND an answer!
(Where does this stupid 'AUTO-SAVED' come from? I certainly didn't activate it.)L85: Rune-Keeper, Warden, Minstrel, Guardian, Hunter, Captain, Burglar, Lore-Master, Champion
-
Oct 17 2011 11:34 PM #82
Re: Official Thread: Community Site Issues Discussion
A completely random password of 16 characters chosen from the set Turbine allows represents just over 100 bits of entropy.
However, 100 bits of entropy won't protect you much if your random password generator picks the following 16 completely random characters: f-e-e-b-l-e-m-i-n-d-e-d-n-e-s-s
The odds of any specific 16 character combination (including that one) appearing randomly are very slim. My point is that when protecting against an offline attack, it's still important to review random passwords for human preferences and weaknesses.Founder of the Better Biscuit Bureau, 4 Brookbank Street, Bannockbury, Brandywine.
-
Oct 17 2011 11:36 PM #83
Re: Official Thread: Community Site Issues Discussion
I'd really like to see a simple statement from Turbine-is everyone getting these emails or no? Do we need to deal with credit/debit card number changes, etc.? Sorry, but "If they don't say, you're fine" won't cut it. And claiming that using the same username/password for the forums and game was safe is of course now patently ridiculous.

-
Oct 17 2011 11:40 PM #84
-
Oct 17 2011 11:42 PM #85
Re: Official Thread: Community Site Issues Discussion
-
Oct 17 2011 11:58 PM #86
-
Oct 18 2011 12:04 AM #87
Re: Official Thread: Community Site Issues Discussion
Well, that depends on how they're stored (and of course, whether that data was exposed at all). vB forum passwords are stored with a one-way hashing algorithm, hopefully with a custom "salt" applied so it's quite a bit harder to crack. Turbine has it's own "unified login", so they might store it differently, but that general approach is sound.
CC info has at least the potential to be easier to crack than any decent passwords because the range of possible values for a given length are much smaller. It all depends on what sort of encryption they use, what additional algorithms are layered in, etc. This is why they need to let people know if that sort of data was lost. Heaven help them if players start taking it in the shorts with their CC companies and they didn't warn anyone. That could easily turn a mess into a full-blown disaster, and they obviously don't want that sort of event to happen at any time. (But especially not just before the largest MMO in the past 7 years is getting ready to ship...)
Now that things are supposed to be closed up tight, the best policy is full disclosure IMO.
KhafarLast edited by Khafar; Oct 18 2011 at 03:49 AM.
-
Oct 18 2011 12:08 AM #88
Re: Official Thread: Community Site Issues Discussion
Last edited by Victiswolf; Oct 18 2011 at 12:18 AM.
Victuswolf - Rank 7 Warg
VaeVictis - Rank 7 Weaver
Server Snowbourn - Member of the Blackpact
-
Oct 18 2011 12:10 AM #89
-
Oct 18 2011 12:31 AM #90
Re: Official Thread: Community Site Issues Discussion
I have had no such email sent to my account.
Do you remember the taste of strawberries?
-
Oct 18 2011 12:39 AM #91
Re: Official Thread: Community Site Issues Discussion
If the email message originated from a host at parature.com, bluehornet.com, or playspan.com, it's probably authentic.
- Turbine uses a web-based solution from Parature for its all of its support operations.
- Turbine uses BlueHornet (from Digital River) for managing its email marketing cammpaigns and customer contact preferences.
- Turbine contacts with PlaySpan (now owned by VISA) to operate the LOTRO Store.
Last edited by Fredelas; Oct 18 2011 at 12:49 AM.
Founder of the Better Biscuit Bureau, 4 Brookbank Street, Bannockbury, Brandywine.
-
Oct 18 2011 12:55 AM #92
Re: Official Thread: Community Site Issues Discussion
Not sure if they are busy or not but I followed the instructions about changing the password and have waited quite awhile for the confirmation email and still have not received it. I can still log in to the game and forums using my old password.

“Courage is found in unlikely places". J.R.R. Tolkien
-
Oct 18 2011 12:55 AM #93
Re: Official Thread: Community Site Issues Discussion
I received the Reset Your Password email but I don't think its from Turbine.
Well I have not forgotten my password and it still works and I would never Click A Link to recover a password from an email...... click on "Forgot your password?" You may also click this in the game launcher.
Follow the instructions on how to recover your password. A new password will be sent to this e-mail address.
I think someone is still poaching stuff... sort of like the constant emails I get about my Battle.net account being compromised - I have never had a Battle.net account and never played WOW....
I will change my PW but only if I initiate the connection to the account page.
I'm shocked, shocked to find that gambling is going on in here!
<Your winnings, sir.>
[sotto voce] Oh, thank you very much.
-
Oct 18 2011 01:16 AM #94
Re: Official Thread: Community Site Issues Discussion
Greetings!
I would suggest to everyone here... If you used the same password, with which you logged into LOTRO on other games and/or forums, that you also chang those passwords. Most people who play MMOs or post in forums get "known" around the Internet. If there is a digital-trail of your past postings / game playing, then the stolen password from Turbine WILL be tried on those other sites for access. This is just a word of caution!
I always check any email that purports to come from official sites/games. If they are genuine, then I follow their instructions.
So far, I've recieved about 100 phishing emails from Blizzard, Citibank, Jagex, NCSoft, etc. Out of the 100, only one could have been genuine...I do have an NCSoft account...but none of the others.
To check the email from "Turbine":
• Checked the full header of the email.
• From the full header, I found: Received-SPF: pass (domain of returnpath.bluehornet.com designates 216.54.194.103 as permitted sender)
• I directed my browser to http://www.networksolutions.com/whois to look up the domain of bluehornet.com
• I found the following ownership:
===> Registrant:
Digital River, Inc.
10380 Bren Road West
Minnetonka, MN 55344
US
Domain Name: BLUEHORNET.COM
Administrative Contact , Technical Contact :
Digital River, Inc.
hostmaster@digitalriver.com
10380 Bren Road West
Minnetonka, MN 55344
US
Phone: 952-253-1234
Fax: 952-253-8497
Record expires on 27-Feb-2014
Record created on 02-Mar-2005
Database last updated on 15-Oct-2006
• Digital River, Inc. are used by Turbine to download & verify the Isengard Expansion...so they are a trusted site.
• Redirected the browser to https://myaccount.turbine.com
• Followed the email instructions and clicked the "I forgot my password" to initiate the resetting of the password.
• Noticed that it only asked for my Account Name...not any email address. This is vital since phishing sites would ask for the email but Turbine is relying on the one that the account was registered with...which is stored seperate from Account Name & Password data.
• Clicked on the link to reset the password in the email received.
• Came here to the Forums to see if the password was changed. It takes a few minutes to update Turbine's servers...so the first entry didn't work. But the second try worked fine.
Hope this helps and isn't just another "Wall of Blah"!
TQQdles™,
Dolnor Numbwit
Eternal Newbie
Satine's Web BrowserΦ 3.4 GHz i7-2600 • 8 Gigs DDR3-1333 Memory • ATI HD6770 • 768K DSL Broadband • 2x500gig RAID0 Storage • RealTek Integrated 5.1 Digital Audio • Windows 7 Home Premium • Dell 2410 24" LCD Monitor Φ
-
Oct 18 2011 01:40 AM #95
Re: Official Thread: Community Site Issues Discussion
This really sums up all questions I have about this incident, thank you Victiswolf for this.
Now the only thing we need is to get ANSWERS from the Turbine staff - is there anybody from Turbine present who is monitoring this thread and can give answers to the questions asked above?
-
Oct 18 2011 01:54 AM #96
Re: Official Thread: Community Site Issues Discussion
I hardly think this subject needed more confusion. but we now have at least two different emails being sent to some, but not all, players. FWIW, my email came from newsletter.turbine.com.

-
Oct 18 2011 02:27 AM #97
Re: Official Thread: Community Site Issues Discussion
If this post can make it through my TARDIS and onto the thread I hope this helps. I know I haven't been playing LotRO for very long, bout a year now, but I still think I have a relationship with Turbine. They lured me in to one of the most addictive games I have ever played then stole my life away. I have given them far more money than I care to admit, and for that I feel like I deserve something. I understand there are security concerns, but I can't fully buy that. The perpetrators of this attack clearly know what they did, and when they saw the forums down they must have realized it was in response to the attack. One of the most annoying aspects for me was that right when the forums went down Turbine fed us some bogus story about maintenance. Telling us that there had been an attack couldn't have hurt, clearly they weren't going to scare the attackers away. The internet is a unique place where it is much easier to get closer to true anonymity, and for that reason I believe that those we put our trust in, in this case Turbine, need to put forth extra effort into transparency. I am not expecting Turbine to tell us everything, especially not what they plan to do for extra security or to find the attackers, but they can tell us what has already happened, what has been possibly exposed so as to let us, the consumer, make educated decisions about what to do about our own private information.
Thank you for listening to all that,
Hang
-
Oct 18 2011 02:27 AM #98
Re: Official Thread: Community Site Issues Discussion
The launcher needs to be more clear that the issue doesn't only affect 'forum users' (ie people who actively use the forum) but that everyone who has a turbine account should be changing their password.

-
Oct 18 2011 03:03 AM #99
Re: Official Thread: Community Site Issues Discussion
A couple of things.
1. I haven't seen one post by a blue name in this thread. I'm wondering if they are just letting us blow steam and forget about it.
2. This forum is still in beta.
3. It's still the same damn forum in spite of all that happened.
4. Information from Turbine has been nil.
5. Issue number one deserves to be read again. It just seems to me that they are just letting us rant about the forum and not responding just like they have done for the last 13 months. It really disgusts me. Very poor customer service. Right now with what happened I cannot recommend this game to anyone. I never thought I would hear myself say that.Life is not a journey to the grave with the intention of arriving safely in a well preserved body, but rather to skid in broadside, totally worn out & proclaiming "WOW, what a ride!"
Civ II rules after all these years......

-
Oct 18 2011 03:19 AM #100
Re: Official Thread: Community Site Issues Discussion
♥Wargs Rule!♥ *But only because we have no playable feline races.*
˙˙˙sƃuıɥʇ ǝʇıɹnoʌɐɟ ʎɯ ɟo ʍǝɟ ɐ ǝɹɐ ǝsǝɥʇ*sƃuıs* ¡ʎɯ ɥo ♥sǝıƃɹɐʍ puɐ 'sǝssǝɹʇsıɯ-ǝɹol 'sǝsɟlǝ♥
Founder & Altoholic: playing wargies and loremistresses since 2006 SoA beta. *Jingle Jangle!*

-
Oct 18 2011 03:25 AM #101
-
Oct 18 2011 03:40 AM #102
Re: Official Thread: Community Site Issues Discussion
Saying that turbine didn't contact individuals via mail is simply not true.
I haven't been aware of this whole incident until I received an email by turbine that they locked my account since it might have been abused due this issue.
The help desk has been friendly. Yet it had been already to late. My Chars had been stolen and the house was sold (and retaken :-( ).
I cant say that turbine isn't helping me. No it seams they are friendly and trying to solve the issue. even so i dont think i will get the same house again since someone else moved in...
But lets not forget .. this is only a game..
I would just like to advice people not only to change there passwords at turbine but at other sites as well.
As for turbine i would love to see something they use over at blizzard (wow). There your account is secured with a 3rd party token.Its like a one-time password that changes every 2 min.
-
Oct 18 2011 04:22 AM #103
Re: Official Thread: Community Site Issues Discussion
Just a couple of minutes ago I finally got an email advising me to change my password, this being the one from newsletter.turbine.com. Since I had changed my password after the 11th, I'm not worried about it anymore, but this does show Turbine is rolling out emails now, probably to everyone with a LOTRO account. It is simply taking time to get all of them sent.
-
Oct 18 2011 04:23 AM #104
Re: Official Thread: Community Site Issues Discussion

"Run! My pretty little chunks of Renown, Run!!!!"
-
Oct 18 2011 04:29 AM #105
Re: Official Thread: Community Site Issues Discussion
Life is not a journey to the grave with the intention of arriving safely in a well preserved body, but rather to skid in broadside, totally worn out & proclaiming "WOW, what a ride!"
Civ II rules after all these years......

-
Oct 18 2011 04:54 AM #106
Re: Official Thread: Community Site Issues Discussion
Turbine is not allowed to display your full credit card number anywhere (semi-)public for security reasons. Nor is any other website really. Simply displaying the full info would make it accessible to any individual who just might happen to glance at your screen while you've gone to get coffee or something. You can be sure that if someone indeed got into their database with credit card data, they have the full info.
lotrocommunity.com
-
Oct 18 2011 04:59 AM #107
Re: Official Thread: Community Site Issues Discussion
The only reason I know what's going on is that I'm a member of "that other site". I've warned my kinnies who don't use this forum that they should change their passwords but a lot are sceptical about my info as they've heard nothing off Turbine and don't use these forums often. I don't think that simply emailing those who Turbine *think* have been affected is enough: an email should be going out to *all* users.
As for keeping us updated during the days the forums were down, all I saw on Twitter were ads for competitions :S Not ideal when you're wondering if your password and account is safe...Blaize, Ellorien, Melica, Rhedyn, Finriel, Aerynna, Merywen, Faelarth, and Tathriel, wandering the shores of Middle Earth.
-
Oct 18 2011 05:00 AM #108
Re: Official Thread: Community Site Issues Discussion
I find it very bad customer service for Turbine not to have immediatly advised all players to change their passwords as soon as they were made aware of unauthorized access to the accounts database.
I would hope that in light of this issue as you are liking to call it, then you will revert back to having different passwords for the forums and game logins. This has been requested numerous times. The events of the past week have proved that your forums are not safe as you have stated in reply to these requests.
Lets also hope that you have done full checks on the forums to ensure that you did not leave any other doors open.
If you are planning on sending me one of those emails regarding this be sure to include in it a list of all my details that have been compromised. Will save you some work in the long run

-
Oct 18 2011 05:08 AM #109
Re: Official Thread: Community Site Issues Discussion
I must say this is the most amateurish and inept forum handling and coding I have seen in quite some time. Beta after HOW many years? GTC VIP upgrades just working recently.. From the underhanded censorship through turning posts "invisible" but for the original poster, to the abysmal handling of vital information and outright dangers of identity theft to the users. I´m glad this catastrophe led me to the "other" Lotro forum. This will be the last time I have logged in here.
-
Oct 18 2011 05:21 AM #110
Re: Official Thread: Community Site Issues Discussion
Well, I got an email this morning from Turbine Support advising me to change my password. How many of you are getting the same?
-
Oct 18 2011 05:25 AM #111
Re: Official Thread: Community Site Issues Discussion
I'm assuming they have added something to the launcher advising people to change there passwords for those that don't visit the forums (I haven't logged in this morning so it may already be there!)
I haven't yet, although I had already changed my password after being advised of the issues on "other site" (is that the official name for it now?)Last edited by Runesi_EU; Oct 18 2011 at 05:34 AM.

-
Oct 18 2011 05:34 AM #112
Re: Official Thread: Community Site Issues Discussion
The only text on the launcher is an advice to click a link regarding forum updates. I know lots of people in my kin don't read these forums and don't care about reading up on forum updates either. They all missed the important information contained in that message simply because they did not think it was anything that concerned them.
The advice to change passwords would reach many more players if it was directly stated in the launcher in stead of referred to via a link regarding forum issues. Most* players don't even know their forum accounts are linked to their game passwords.
*where "most" is a number of 9:1 players in my kinship.
-
Oct 18 2011 05:39 AM #113
Re: Official Thread: Community Site Issues Discussion
From your statement about this:
So, how seriously do you consider it?We take all potential issues seriously
As I understand it, Turbine were told, privately, under the "responsible reporting" principle about a huge security flaw ..and you did NOTHING until the person who discovered it despaired of your taking any action and posted publicly about it, at which time you took the forums down.
Is that taking is 'seriously'?
Not to me it isn't, it's taking notice only when it becomes a PR embarrassment.
-
Oct 18 2011 05:48 AM #114
Re: Official Thread: Community Site Issues Discussion
Received an email from newsletter@turbine.com.
Some of the grammar is a bit dodgy and anyway all my passwords have been changed so no reason to click any links.
Just wanted to know, if this is a legitimate email or a Phishing email.
-
Oct 18 2011 05:54 AM #115
Re: Official Thread: Community Site Issues Discussion
*waves to the forum maintenance/security hobbits in charge*
I changed my passwords 3 days ago when the forums went down.
I have a new password and I have been using it for the game for the past 3 days.
The forums were back up during my night.
This morning I was able to log in on the Forums with my old password( the one I changed a few days ago)
Is this working as intended?
Thanks in advance for the support
-
Oct 18 2011 06:09 AM #116
Re: Official Thread: Community Site Issues Discussion
Still running the old and new password. lol
http://www.youtube.com/watch?v=COSeM...eature=relatedLast edited by Edhereth; Oct 18 2011 at 06:14 AM.
-
Oct 18 2011 06:11 AM #117
Re: Curioser and curioser....
-
Oct 18 2011 06:27 AM #118
Re: Official Thread: Community Site Issues Discussion
Got the email recommending I change my password (which I had already done a couple of days ago).
The entire situation is a disgrace. It's not exactly a secret that kids all over the world have been showing off their hacking abilities in a very public manner lately, attacking banks, corporations, etc. to prove how inept some of the people handling security seem to be these days. Not only has Turbine revealed itself to be vulnerable to hacks, but they have handled the matter poorly, revealing no solid information to their customers. They deserve to get bad publicity for this, and I sincerely hope they do.
Ardeth --75 minstrel; Mirianor--75 RK; Philippa--75 captain;Brynna--68 burg; Ellaril--72 hunter; Irulan--67 loremaster
-
Oct 18 2011 06:44 AM #119
Re: Official Thread: Community Site Issues Discussion
For those interested, got the email as well, and the old password no longer works (changed it yesterday...before I got the email). So I guess that's something. But honestly, it's getting a little ridiculous. You can't keep people in the dark like this. I realize Turbine's trying to dampen a potential PR disaster, but in doing so they're fueling another potential PR disaster.
Your customers deserve an answer to very legitimate concerns. They trusted you with their private information, and deserve to know if that information was compromised.
And really, I don't think anybody's asking too much.
-
Oct 18 2011 06:45 AM #120
Re: Official Thread: Community Site Issues Discussion
*Little Update # 2*
I was timed out (?) of the Forums after I posted my previous comment in this thread.
I had to log in the forums again.
I did try the OLD password which does not work anymore.
I used the NEW password and here I am, so thank you for fixing my issue , that was really fast
*hands a cookie to the technical maintenance hobbit in charge of passwords*
-
- Community Guidelines
- New Posts
- Dev Tracker
- Forum List
- Discussion Forums
- Classes
-
Worlds
- Arkenstone
- Brandywine
- Crickhollow
- Dwarrowdelf
- Eldar
- Elendilmir
- Evernight
- Firefoot
- Gilrain
- Gladden
- Imladris
- Landroval [EN-RE]
- Laurelin [EN-RP]
- Meneldor
- Nimrodel
- Riddermark
- Silverlode
- Snowbourn
- Vilya
- Windfola
- Withywindle
- Anduin [DE]
- Belegaer [DE-RP]
- Gwaihir [DE]
- Maiar [DE]
- Morthond [DE]
- Vanyar [DE]
- Estel [FR-RP]
- Sirannon [FR]
- Bullroarer (Public Test Server)
- Community
- Gameplay
- PvMP














