<?xml version="1.0"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
<title>Massively</title>
<link>http://massively.joystiq.com</link>
<description>Massively</description>
<image>
<url>http://www.blogsmithmedia.com/http://massively.joystiq.com/media/feedlogo.gif</url>
<title>Massively</title>
<link>http://massively.joystiq.com</link>
</image>
<language>en-us</language>
<copyright>Copyright 2012 Weblogs, Inc. The contents of this feed are available for non-commercial use only.</copyright>
<generator>Blogsmith http://www.blogsmith.com/</generator><item><title><![CDATA[Player identifies "huge security hole" in RIFT's authentication system, Trion seals it]]></title><link>http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/</link><guid isPermaLink="true">http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/</guid><comments>http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/#comments</comments><description><![CDATA[<p>Filed under: <a href="http://massively.joystiq.com/category/fantasy/" rel="tag">Fantasy</a>, <a href="http://massively.joystiq.com/category/game-mechanics/" rel="tag">Game mechanics</a>, <a href="http://massively.joystiq.com/category/rumors/" rel="tag">Rumors</a>, <a href="http://massively.joystiq.com/category/rift/" rel="tag">RIFT</a></p><div style="text-align: center;">
	<a href="http://www.riftgame.com/en/"><img src="http://www.blogcdn.com/massively.joystiq.com/media/2011/03/security.jpg" style="border-width: 1px; border-style: solid; margin: 4px;" /></a></div>
Hacking and account hijacking have been severe issues for <a href="http://www.riftgame.com/en/"><em>RIFT</em></a> ever since launch, even though <a href="http://massively.joystiq.com/tag/trion/">Trion Worlds</a> anticipated the onslaught from the beginning. Yesterday we saw Trion implement the so-called <a href="http://massively.joystiq.com/2011/03/18/rift-adds-coin-lock-to-improve-security-probably/">Coin Lock patch</a> to prevent hackers from selling other players' items in-game, which some see as a novel (partial) solution to the problem.<br />
<br />
However, this may not be enough to stop the truly malicious invaders from getting into <a href="http://massively.joystiq.com/category/rift/"><em>RIFT</em></a> accounts. One player, identified as "ManWitDaPlan" on the forums, <a href="http://forums.riftgame.com/showthread.php?127127-Account-Security-Discussion&amp;p=1747442&amp;viewfull=1#post1747442">claims to have circumvented the account login completely</a>, leaving a "huge security hole" for hackers to exploit:<br />
<br />
<em>"I have verified the authentication system can be bypassed by successfully logging into another account without needing its credentials. Worse, all it took was about thirty seconds of time once I got all of the details locked down. I did trigger Coin Lock, but I was fully able to access that handy delete-character button, so this exploit is a griefer's dream. I will not post details on how to do this (so don't ask), but I'm positive that I can reproduce this at will and likely on any account on the system."</em><br />
<br />
Later in the thread, <a href="http://forums.riftgame.com/showthread.php?127127-Account-Security-Discussion&amp;p=1749887&amp;viewfull=1#post1749887">a Trion representative added</a>: <em>"We have some things in the works right now and have been passing on your feedback, concerns, and thoughts throughout the day (no matter how radical or unlikely). Sharing sensitive information about our actions (no matter how broad) naturally also informs those carrying out these attacks. This puts us in a tight spot with how much information we can provide, and the questions we can answer."</em><br />
<br />
And it looks as though the problem may be fixed, <a href="http://forums.riftgame.com/showthread.php?127127-Account-Security-Discussion&amp;p=1752989&amp;viewfull=1#post1752989">as ManWitDaPlan posted late last night</a>:<em> </em><em>"Got word back from Steve Chamberlin, the development lead for Rift. This hole is sealed."</em><p style="padding:5px;background:#ffffcc;border:1px solid #ffff99;clear:both;"><a href="http://massively.joystiq.com"><img src="http://massively.joystiq.com/media/feedlogo.gif" alt="Massively" style="float:left;padding:0 5px 5px 0;" /></a><a href="http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/">Player identifies "huge security hole" in RIFT's authentication system, Trion seals it</a> originally appeared on <a href="http://massively.joystiq.com">Massively</a> on Sat, 19 Mar 2011 13:00:00 EST.  Please see our <a href="http://www.weblogsinc.com/feed-terms/">terms for use of feeds</a>.<br style="clear:both;"></p><h6 style="clear: both; padding: 8px 0 0 0; height: 2px; font-size: 1px; border: 0; margin: 0; padding: 0;"></h6><a href="http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/" rel="bookmark" title="Permanent link to this entry">Permalink</a>&nbsp;|&nbsp;<a href="http://massively.joystiq.com/forward/19885053/" title="Send this entry to a friend via email">Email this</a>&nbsp;|&nbsp;<a href="http://massively.joystiq.com/2011/03/19/player-identifies-huge-security-hole-in-rifts-authentication/#comments" title="View reader comments on this entry">Comments</a>]]></description><category>account-exploits</category><category>account-security</category><category>authentication</category><category>authentication-system</category><category>coin-lock</category><category>coin-lock-system</category><category>griefers</category><category>hack</category><category>hacked</category><category>hackers</category><category>manwitdaplan</category><category>rift</category><category>rift-planes-of-telara</category><category>trion</category><category>trion-worlds</category><dc:creator><![CDATA[Justin Olivetti]]></dc:creator><pubDate>Sat, 19 Mar 2011 13:00:00 EST</pubDate></item><item><title><![CDATA[Potential smoking gun found for Guild Wars security issues]]></title><link>http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/</link><guid isPermaLink="true">http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/</guid><comments>http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/#comments</comments><description><![CDATA[<p>Filed under: <a href="http://massively.joystiq.com/category/fantasy/" rel="tag">Fantasy</a>, <a href="http://massively.joystiq.com/category/guild-wars/" rel="tag">Guild Wars</a>, <a href="http://massively.joystiq.com/category/exploits/" rel="tag">Exploits</a>, <a href="http://massively.joystiq.com/category/news-items/" rel="tag">News items</a>, <a href="http://massively.joystiq.com/category/rumors/" rel="tag">Rumors</a></p><div style="text-align: center;"><a href="http://guildwars.wikia.com/wiki/Locked_chest"><img hspace="4" border="1" align="top" vspace="4" alt="" src="http://www.blogcdn.com/massively.joystiq.com/media/2010/01/gw-smokinggun-epl-101.jpg" /></a></div>
It started as a surprise. <a href="http://www.guildwars.com"><em>Guild Wars</em></a> players reported suddenly finding themselves <a href="http://massively.joystiq.com/2009/11/30/guild-wars-account-security-issues-continue/">hacked</a>, their accounts cleaned out, no indication of what could have caused the problem. <a href="http://www.ncsoft.com/global/">NCsoft</a> and <a href="http://www.arena.net/">ArenaNet</a> offered suggestions, security safeguards, <a href="http://massively.joystiq.com/2009/12/23/ncsoft-taking-first-visible-steps-to-improve-security/">new measures being taken</a>, hints that the problem lay in a popular third-party website with an undisclosed name. But with the recent rash of problems that <a href="http://www.aiononline.com"><em>Aion</em></a> players have been having regarding security, new facts have begun coming to light, and they paint a picture that isn't pretty.<br />
<br />
Specifically, some players seem to be finding that <a href="http://www.guildwarsguru.com/forum/account-hackings-source-t10419779.html?s=ee7a3706fb5ee3b389eac505cc7383cc&amp;amp;">it doesn't take any skill to wind up hacking someone's account accidentally</a>. And all it takes is a few log-in attempts to find yourself with access to someone's account name, password, and billing information for all of a player's <a href="http://massively.joystiq.com/tag/NCsoft/">NCsoft</a> games.<p><a href="http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/" rel="bookmark">Continue reading <em>Potential smoking gun found for Guild Wars security issues</em></a></p><p style="padding:5px;background:#ffffcc;border:1px solid #ffff99;clear:both;"><a href="http://massively.joystiq.com"><img src="http://massively.joystiq.com/media/feedlogo.gif" alt="Massively" style="float:left;padding:0 5px 5px 0;" /></a><a href="http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/">Potential smoking gun found for Guild Wars security issues</a> originally appeared on <a href="http://massively.joystiq.com">Massively</a> on Sat, 02 Jan 2010 10:00:00 EST.  Please see our <a href="http://www.weblogsinc.com/feed-terms/">terms for use of feeds</a>.<br style="clear:both;"></p><h6 style="clear: both; padding: 8px 0 0 0; height: 2px; font-size: 1px; border: 0; margin: 0; padding: 0;"></h6><a href=http://www.guildwarsguru.com/forum/account-hackings-source-t10419779.html?s=ee7a3706fb5ee3b389eac505cc7383cc&amp;>Read</a>&nbsp;|&nbsp;<a href="http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/" rel="bookmark" title="Permanent link to this entry">Permalink</a>&nbsp;|&nbsp;<a href="http://massively.joystiq.com/forward/19300183/" title="Send this entry to a friend via email">Email this</a>&nbsp;|&nbsp;<a href="http://massively.joystiq.com/2010/01/02/potential-smoking-gun-found-for-guild-wars-security-issues/#comments" title="View reader comments on this entry">Comments</a>]]></description><category>account-exploits</category><category>account-security</category><category>aion</category><category>arenanet</category><category>breaking-news</category><category>gaile-gray</category><category>guild-wars</category><category>gw</category><category>hacking</category><category>ncsoft</category><category>regina-buenaobra</category><category>security-breach</category><category>security-issues</category><dc:creator><![CDATA[Eliot Lefebvre]]></dc:creator><pubDate>Sat, 02 Jan 2010 10:00:00 EST</pubDate></item></channel></rss>
