-
Oct 18 2011 04:03 PM #241
Re: Official Thread: Community Site Issues Discussion
-
Oct 18 2011 04:03 PM #242
Re: Official Thread: Community Site Issues Discussion
I just hope officials start responding to this thread with more info. This is a very serious issue and silence shouldn't be an option for Turbine.
Last edited by MoonwalkIntoMordor; Oct 18 2011 at 04:21 PM.
Yalras
Eldar
-
Oct 18 2011 04:07 PM #243
Re: Official Thread: Community Site Issues Discussion
This^^^
The hacker contacted Turbine about their security hole by Email and the forums. They ignored him just as they ignored everyone else saying that linking forum to game accounts is unsafe.
If it wasen't for him we would still be stuck with a unsecure system where anyone could get their information stolen at any time. It was only when the "white hat" hacker posted screenshots of Turbines databases that Turbine took the forums offline. He posted images that showed he had access to over a million accounts across 2 databases. He stated it was to do with a door left open since migration. Would you be happy if that door was still open?
I don't think its any coincidence that some news sites/blogs and forums have made posts regarding a large increase in the amount of lotro accounts that have been compromised by hackers. I do not believe in coincidences or that games companys tell end users when their information has been left unsecure. Every time you read about it in the news the games companys admit nothing till a hacker uploads their database. That doesen't inspire confidence at all.Last edited by Victiswolf; Oct 18 2011 at 04:12 PM.
Victuswolf - Rank 7 Warg
VaeVictis - Rank 7 Weaver
Server Snowbourn - Member of the Blackpact
-
Oct 18 2011 04:14 PM #244
Re: Official Thread: Community Site Issues Discussion
He did not expose the vulnerability beyond some very general descriptions and did not give any information to the public on how to exploit it. He apparently did share those details with Turbine. As far as I'm concerned he did kept it private enough to ensure no additional damage was done, but public enough to make sure Turbine would do something. He did it right as far as I'm concerned and all of our information is safer now because of his actions.

-
Oct 18 2011 04:15 PM #245
-
Oct 18 2011 04:51 PM #246
Re: Official Thread: Community Site Issues Discussion
And yet, all they took down was the forums.
They didn't take down the game, or the myaccount pages.
Remember when Sony was hacked? PSN was *gone* totally.
Posting screenshots of an exploit does *nothing* productive except a) let every hacker that sees the post know that there's a potential for mayhem, and b) force the company - whatever company - to take action before they have a chance to actually analyse the threat.
It's not *noble* to post it in public. It's akin to throwing a temper tantrum, because they didn't instantly cave to your will. Period.
If the guy *truly* had noble intention, he would have presented his evidence, explained the exploit, suggested a fix...and then kept it to himself.
There *are* white hat hackers out there. Someone that posts it all publicly does not fit that definition.
-
Oct 18 2011 05:08 PM #247
Re: Official Thread: Community Site Issues Discussion
The forums are obviously the weak link in the chain that leads to the account database. They should of took the forums offline as soon as the hacker had emailed them. There is no good reason to leave security hole open. Leaving the forums up to make it look like theres no security hole in the forums and putting the entire Lotro community at risk is wrong period.
In every single case where a games companys security has been flawed they have done nothing till a hacker provided proof of a security breach. Both Sony and Trion "Rift" didn't fix their security issues till weeks or months after people people had already been hacked. The same goes for Turbine.
The community has been telling Turbine to increase security for over a year. The Lotro community has been telling Turbine to seperate forum and game accounts for over a year. This led to many threads locked and posts deleted. Nothing done at all. The hacker contacted Turbine directly and heard nothing back from them about the issue. We always hear nothing and get told everythings fine. That our information is safe. Well our information wasen't safe and we have every reason to believe that its not been safe since the end of may.
It was ONLY when proof was provided on the interwebs that any games company has taken action or admited that personal information had been compromised. First Sony then Trion and Now Turbine despite all the best efforts of this community to highlight the need for added security measures.
Why should we trust any games company at this point to take action in private when they only ever take action when a hacker uploads proof that customer information is not secure?Last edited by Victiswolf; Oct 18 2011 at 05:17 PM.
Victuswolf - Rank 7 Warg
VaeVictis - Rank 7 Weaver
Server Snowbourn - Member of the Blackpact
-
Oct 18 2011 05:16 PM #248
Re: Official Thread: Community Site Issues Discussion
It makes a difference, because as soon as the forums went down, they could not get in using the back door anymore. If the forums are hacked, that doesn't mean all other apps, like game-login and lottery software are hacked too. So it completely normal to shut down forums while keeping other services online. It is just like real life: if you own something, it means that someone can steal it. If you live in a house, you can be burgled. It's not only the landlord's responsibility to secure your home, but also the tenant's.
After everybody changed passwords, the hackers cannot get in anymore. I changed my password again, less then a week after changing it like I always do on a regular basis. I have never been hacked in my life, just because I have an unique password/username combo for every service (1password is your friend) and my game profiles for my characters are anonymous, so you can't see which account those characters belong to. I never give my credit card information to companies, I either use paypal or I use a prepaid debit/credit card.
Yes, it sucks to be hacked, but like I said, it can happen to anybody, no matter how secure your site is. If people want to hack your site, they will eventually succeed in doing so. It's not fair to 100% blame one party. I would have liked more info, too, because some personal information is at stake. But I also see why they cannot give all the information I like to hear, because that would compromise security and encourage hackers to try find more holes.
I am interested to see what the aftermath will be. Of course I lost my trust in Turbine and won't be buying Turbine Points or get a subscription using a credit card any time soon and I'm assuming I am not the only one. This is going to hurt them financially, they know that. Therefore I'm sure they will do whatever they can to make things better, not only in the player's interest but also in their own business interest.
-
Oct 18 2011 05:18 PM #249
-
Oct 18 2011 05:20 PM #250
-
Oct 18 2011 05:24 PM #251
-
Oct 18 2011 05:24 PM #252
Re: Official Thread: Community Site Issues Discussion
Sorry, you don't know that. You have no idea how many security threats they've been notified about, and responded to, and corrected. And I don't just mean Turbine, I mean any company with an online presence. You have no idea what they do in the background. Neither do I - I only know from personal experience with the servers we maintain. One of them has been under near constant attack for the last 4 years - with one breach that was something we had to notify customers about. I personally have reconfigured, rewritten, or updated security measures on that machine on a near weekly basis, in response to changing attack vectors - as well as monitoring several automated system defenses.
We know about this one, because someone chose to splash stuff around. Is he a white hat? Or someone who's been working to get in just to prove his position that the servers aren't secure enough? I can bet that one of the things Turbine's lawyers are looking at right now is whether or not the "white hat" should be brought up on charges - most countries have laws against the misuse of computer systems.
-
Oct 18 2011 05:27 PM #253
Re: Official Thread: Community Site Issues Discussion
Yes, this was what I had in my mind when I asked that. My kin's forums (which are part of a larger gaming site) recently started using Xenfero, and I love it.
I understand these things are not simply changed out like one's purse, but in light of this I'm hoping Turbine is at least considering it.
-
Oct 18 2011 05:28 PM #254
Re: Official Thread: Community Site Issues Discussion
I don't think people are necessarily blaming Turbine for being hacked (although if the claims about them leaving the door open are true, then they are to blame). What most people are angry about is the lack of communication from Turbine (as usual). It took several days of the forums being down before they told people to change their passwords, and even then it was only on the forum and with a link to the forum on twitter/facebook. From the email we got today, this was several days after they'd closed the hole. Its now a week after they closed it, and they're only just sending out emails to people to change their passwords. Look at the message in the launcher, it could mean anything, most people won't give it a second glance.
After all this, we still haven't had any confirmation on whether or not they took credit card etc. details or not. Sapience has opened this thread 24 hours ago, and there's been no response since. Its not good enough. They have the legal responsibility to protect the information they give us, and if something happens to that information, to tell us. So far they've failed on both counts. As people say so often, a little more communication would go a long way.
-
Oct 18 2011 05:37 PM #255
Re: Official Thread: Community Site Issues Discussion
Actually there was a reason, customer requests. Before if one wished to submit an ingame ticket, one had to log on the the forum when the pop-up window appeared and people complained about it. People complained about needing a seperate log-in to access the Lorebook ingame. If Turbine went back to separate logins, I suspect there would be complaints about the "inconvenience."
-
Oct 18 2011 05:38 PM #256
Re: Official Thread: Community Site Issues Discussion
Hir i Meigol Bruinen/High Council Member of the EoI/Of the Exiles of the Hidden City/Meigol Bruinen, Uncle Seregnin's Misguided Children, Curse the name of Maeglin, the Treacherous Villain, forever, may he rot in the Halls of Mandos for all time....
-
Oct 18 2011 05:45 PM #257
-
Oct 18 2011 05:47 PM #258
Re: Official Thread: Community Site Issues Discussion
They need to be educated on why this is important. If you're going to convenience them and say, a database gets hacked with potential access to their credit card data and other important stuff, they'll also get an education, but is a "practical approach" really the best option?
edit-
dang it turbine, sync those servers with a NTP server or something. This time difference is driving me bloody crazy. This has nothing to do with "wonky servers", they're just not time synced.Last edited by Rhyaehar; Oct 18 2011 at 05:54 PM.
lotrocommunity.com
-
Oct 18 2011 05:48 PM #259
Re: Official Thread: Community Site Issues Discussion
Still no blue names in this thread? I know at least one has read it...
Even if it's just to say that you're investigating, the sensible response would be to post *something*. Anything. All you have right now are ectremely annoyed customers. You can't tell me that's good business sense!Blaize, Ellorien, Melica, Rhedyn, Finriel, Aerynna, Merywen, Faelarth, and Tathriel, wandering the shores of Middle Earth.
-
Oct 18 2011 05:50 PM #260
Re: Official Thread: Community Site Issues Discussion
People can be weird about convenience. I remember working at a medical facility with two trash containers side by side, one marked "Trash" and the other "Biohazard waste only". I watched a RN that I knew had a Bachelor's toss some printouts, basic office trash, into the biohazard bin. When I asked her why, she replied, "Its closer."
Point is, I am not too sure that many customers would accept inconvenience for security - those posting here of course, but what about the majority of customers that don't frequent the forums?
-
Oct 18 2011 05:53 PM #261
Re: Official Thread: Community Site Issues Discussion
-
Oct 18 2011 05:55 PM #262
-
Oct 18 2011 05:57 PM #263
Re: Official Thread: Community Site Issues Discussion
I changed my password after the forums were taken down. I use KeePass to generate complex high bit-depth passwords. Little good that did since I'm logging into the forums with my old password.
I don't know what to say without coming off as rude, but I'm not a happy camper at all. I find this inexcusable.
I was hoping the old forum software would have been scrapped. I don't need fancy forum software and the myLotRO site is still sluggish compared to other gaming sites. Please just scrap the social network you were trying to create and make a lean clean website that is responsive and delivers information. I don't care if we have a unified login or not. Most of my other gaming sites use unified login, but they also have better security features.
Please provide a way for us to remove our payment information without calling you.The Bees have chosen.
Order Through Chaos
-
Oct 18 2011 06:03 PM #264
Re: Official Thread: Community Site Issues Discussion
-
Oct 18 2011 06:07 PM #265
-
Oct 18 2011 06:08 PM #266
Re: Official Thread: Community Site Issues Discussion
In this case we do know a few important details. We know that players have been asking for better account security or a year. We know players have been asking for forums to be seperated from game accounts. If we take the hacker at his word that he emailed them and posted on the forums telling them all about the security hole. We know that Turbine didn't decide to take the forums offline after the hacker contacted them by email and on the forums.
They could of at least emailed him back right? or took the forums offline as a precaution to check this security issue out? They didn't. As a result a day or 2 later the hacker posted proof of the security hole as he believed Turbine was going to do nothing about it. Why? maybe due to the fact every hour the forum was left up was another hour that any hacker could gain access to our information.
It doesen't matter what his motives were at the time. What matters is the hole was there in the first place for months (since eu migration if you believe the hacker) and the forums were left up AFTER someone contacted them with information about the security hole. Thats what matters.
Everyone should think themselves lucky that this guy wasen't a hacker looking to sell the information although how many hackers have already found this security hole and already done that? After all anyone saying they have been hacked automatically gets blamed and reffered to customer support. Turbine has always told us that our information was secure.
A few posters have pointed out that companys or goverment organisations have to promptly inform their clients if their information was left unsecure or compromised by a third party. It's been a week and Turbine hasen't told us what information was compromised. (thats if you want to get into the legal side of the issue) More importantly we still don't know if credit card information was compromised.
I will stick to the original point as this is going off track. The most important thing right now is for clients to be informed as to exactly what personal data was compromised due to the breach and for how long. Everyone needs to be contacted with that information so they can protect themselves from fraud, raided accounts and third party credit card bills.Last edited by Victiswolf; Oct 18 2011 at 06:21 PM.
Victuswolf - Rank 7 Warg
VaeVictis - Rank 7 Weaver
Server Snowbourn - Member of the Blackpact
-
Oct 18 2011 06:10 PM #267
Re: Official Thread: Community Site Issues Discussion
Its incredibly difficult to try to debate this here with you arbalister as to point out the actual technical details here would obviously go against this forums rules. Perhaps you should consider setting up an account at the lotrocommunity.com for further more detailed discussion.

-
Oct 18 2011 06:10 PM #268
-
Oct 18 2011 06:15 PM #269
Re: Official Thread: Community Site Issues Discussion
While we are all wondering about our security can someone tell me why we don't have those keychain fobs? They can't really be that expensive/hard to implement can they? My husband has one for work, some other games use them...
-
Oct 18 2011 06:20 PM #270
Re: Official Thread: Community Site Issues Discussion
This I believe 100%. People are asking why there hasn't been any input for the last week but the truth is that in regards to the forums there really hasn't been much input since the forums changed 13 months ago, other than one of the blue names saying," The forums isn't going anywhere.". I remember that quote to this day.
I was hoping Turbine would wake up after this but I feel it's not gonna happen. I really honestly hate their style just letting complaints about the forums die down without saying a word. This time it's really biting them in the rear.Life is not a journey to the grave with the intention of arriving safely in a well preserved body, but rather to skid in broadside, totally worn out & proclaiming "WOW, what a ride!"
Civ II rules after all these years......

-
Oct 18 2011 06:23 PM #271
-
Oct 18 2011 06:23 PM #272
Re: Official Thread: Community Site Issues Discussion
>outdated<
Last edited by NepherDaan; Oct 19 2011 at 04:49 AM.

-
Oct 18 2011 06:26 PM #273
-
Oct 18 2011 06:30 PM #274
Re: Official Thread: Community Site Issues Discussion
Well maybe attracting the attention of a mod isn't such a bad thing. I mean this thread has been up a day now, they must be realizing how people are feeling; still no response from anyone from Turbine. I just wish they could pretend to care. They obviously made this thread so people could voice their opinions, but it does very little if they aren't listening, and that's what it feels like right now.

-
Oct 18 2011 06:31 PM #275
Re: Official Thread: Community Site Issues Discussion
Try posting on the general forums about any of this. Better yet, look at how many threads have been closed and redirected to here.
This is the official thread so it does not have to follow those rules because Turbine knows many people are very upset and will vent. If they don't allow people 1 thread to vent in, they know it will result in a mass exodus. I've seen it before. The moment there was a hint that Asheron's Call 2 might be shut down, people fled in droves. Sure it did eventually end, but by the time the servers were finally pulled offline, the player base was so small we all fit on 1 server.Achiever 26.67%
Explorer 86.67%
Killer 6.67%
Socializer 80.00%
-
Oct 18 2011 06:37 PM #276
Re: Official Thread: Community Site Issues Discussion
Whats the penalty for attracting a mods attention on the forums? If you get banned here does it also ban you in game? I could say a few swears in hopes that a mod would be forced to respond, but I don't want to not be able to play. ;p
Here goes....
Jimminy Crickets, it is a load of fudge that nobody has responded to our legitimate concerns. Turbine being so mum on this issue is a bunch of crabapples.
-
Oct 18 2011 06:37 PM #277
-
Oct 18 2011 06:41 PM #278
Re: Official Thread: Community Site Issues Discussion
More like "an anonymous person on the Internet claiming to be a white hat hacker, and posting a heavily edited screenshot purporting to be a legitimate screenshot of a successful hack, but which actually shows very little of interest, and certainly doesn't show access to encrypted passwords or credit card info."
Oh, and this too:
-
Oct 18 2011 06:44 PM #279
Re: Official Thread: Community Site Issues Discussion
So it was all just a coincidence that Turbines forums were taken offline AFTER he posted the images and that Turbine hasen't denied that credit card or other personal information hasen't been compromised. right......
If he provided them with the same screen shots and detailed information that he published online about the security hole then the only reason they kept the forums up was because it wasen't public knowledge. Turbine should take ANY and ALL measures to protect our private information when they are provided with proof or reasonable cause of a security issue. It would indicate that they knew about the issue or they woulden't of taken the forums offline after the images were posted. It is logical.
If someone else had informed them about the security hole then we would have to assume that Turbine kept the forums up despite knowing about it. Thats not exactly a good idea....Last edited by Victiswolf; Oct 18 2011 at 07:06 PM.
Victuswolf - Rank 7 Warg
VaeVictis - Rank 7 Weaver
Server Snowbourn - Member of the Blackpact
-
Oct 18 2011 06:46 PM #280
Re: Official Thread: Community Site Issues Discussion
Look, it's commendable that they are allowing us a thread where we can discuss, vent, ask questions and debate this issue in.
It's commendable, it truly is.
What is the issue now, for a lot of us, is that we're not being informed about the severity of the breach. That we are having to rely on information from a third party site isn't good enough.
Valid questions have been asked about exactly what has been compromised, information we are all entitled to know, since it's our information to start with.
The simple fact that there is only one Community Rep post in this thread, the opening post, is not good enough.
This has no bearing on how I feel about the game, it's quality or lack thereof. But this is a 2-way street, Turbine.
We need some answers. Please, provide us with those.
I said before that the ball has been dropped. It's right there in your court, Turbine. Please pick it up. This is a great game(imho), but you can and must improve on your handling of this situation.
Hir i Meigol Bruinen/High Council Member of the EoI/Of the Exiles of the Hidden City/Meigol Bruinen, Uncle Seregnin's Misguided Children, Curse the name of Maeglin, the Treacherous Villain, forever, may he rot in the Halls of Mandos for all time....
-
- Community Guidelines
- New Posts
- Dev Tracker
- Forum List
- Discussion Forums
- Classes
-
Worlds
- Arkenstone
- Brandywine
- Crickhollow
- Dwarrowdelf
- Eldar
- Elendilmir
- Evernight
- Firefoot
- Gilrain
- Gladden
- Imladris
- Landroval [EN-RE]
- Laurelin [EN-RP]
- Meneldor
- Nimrodel
- Riddermark
- Silverlode
- Snowbourn
- Vilya
- Windfola
- Withywindle
- Anduin [DE]
- Belegaer [DE-RP]
- Gwaihir [DE]
- Maiar [DE]
- Morthond [DE]
- Vanyar [DE]
- Estel [FR-RP]
- Sirannon [FR]
- Bullroarer (Public Test Server)
- Community
- Gameplay
- PvMP











