Go Back   EQ2Flames Forum > Information and Resources > Dev Tracker from Official EQ2 Forums

Reply
 
LinkBack Thread Tools
Old 07-22-2009, 07:00 PM  
L337 Poster
 

Posts: 14,536
Photos: (0)

Icon3 (Kiara) Account Security

Account security is important! Third party programs can download spyware onto your computer and enable your SOE account to be compromised. More seriously, it can result in identity theft. Likewise, buying plat or power leveling services can endanger your account. Below is some information on how to keep yourself safe, as well as what we can do to help you. This information was originally posted by Greeblen when he was the CS Manager for EQII.

We encourage you not to install anything on your computer that does not come from a trusted source. Please be very careful when choosing and installing programs onto your computer.

"Compromised Accounts? WTH is that?"

Let me explain. When someone logs into someone else's account and takes all their items, their coin, deletes characters, spams obscenities, loots the guild bank, and performs any other manner of maliciousness, CS refers to that account as a Compromised Account. Customers often petition us saying, "My account was Hacked, hepl pls!" In a nutshell, what basically happened is that the account login and password was not kept secure by the account owner or they did not protect their computer properly from malicious access.

As many of you may know, sharing your account information (login/password) is against SOE policies and keeping your account information secure is the responsibility of the owner of the account. I've been with SOE CS for over 6 years now and I couldn't tell you how many times I've seen a customer's ex-wife/husband/girlfriend/boyfriend, brother/sister, mother/father/grandparent, roommate/guildmate, child/dog/cat (yes, people have claimed their pets deleted stuff on their account ‘accidentally&#39, log into an account and have a field day of revenge for some unknown wrong that was done to them. That in and of itself, should be warning enough to keep your login info to yourself and not to write it down where others can find it or post it on your super-secret guild website that only a few friends have access too.

"So how does this relate to Buying Plat and Power Leveling services?"

Very simple, and here is the crux of the concern we want to bring to the attention of our customers: The plat selling and power leveling websites are now actively compromising accounts, stripping them of everything (and stripping guild banks too), and using the plat they gain from this malicious access to sell to players. We've been seeing more and more instances of this over the last several weeks.

We even had a case recently where an account purchased plat from a website plat seller, the account was later accessed and stripped of all items by that very same plat seller, and on the next day was sold back the same plat that was taken from their account.

How does CS know this? When we investigate these issues, we can track where the money goes. Sure the plat sellers use different techniques to try to mask what is actually happening, but our logs record what they do and with some time we can see exactly what happened and take action from there.

The plat sellers and power leveling services are likely obtaining account information in a number of possible ways, be that in a clandestine manner such as virus's, worms, and keystroke loggers imbedded in their websites, or as obvious as saving your account info for later exploitation when you give it to them for power leveling your character.

"What is CS doing about the plat seller/spammer issue?"

This is a bigger topic and can best be addressed in a different forum post or blog entry, but in short, CS is constantly working with our Dev, QA, and Platform teams to come up with new ways to track, remove, prevent spammers, plat sellers, etc from doing the disruptive things they do. As the bad guys adjust their tactics to try and avoid detection, CS responds in turn and counters their activities. Heck, we even have a team of GMs specifically dedicated to investigating and removing plat selling/spamming/hacking/illegal farming accounts from the game.

As for this specific issue, when CS receives a petition from someone that has had their account compromised and is missing all their hard earned coin, items, etc, we do our very best to assist with restoring characters and guild banks back to the way they were before they were accessed maliciously and then we go after the culprit. These investigations can take a significant amount time to do and we cannot guarantee that we can return you back to the exact point you were before this happened. These types of issues also take time away from answering customer petitions for other important issues involving bugged quests, items, etc.

The bottom line is this; the plat sellers and power leveling services, while never trustworthy to begin with, are now actively double crossing the very people that trusted them and have taken this problem to another level. This also means that if you have shared your account information with anyone at any time in the past, you have put your account at risk for losing the rewards of your long hours of game play. In my experience with seeing Compromised Account issues time and time again, no one you share your account information with will treat it with the respect it deserves and this situation almost always ends with a petition for help.

If you have ever shared your account information with anyone in the past or have ever bought plat or used a power leveling service, I strongly suggest you do the following:
- Change your account password immediately and change it often.
- Update your security question.
- You can do both of these by going to www.station.sony.com
- Mouse over the My Account link at the top
- Click on Update Account Information
- Log in
- Click on the Change Password button on the right
- The Secret Question/Answer options are at the bottom of the page
- Never share your account information with anyone again.
- Use anti-virus software, run regular virus scans, and keep your anti-virus definitions up to date.
- Never, ever, visit a plat selling / power leveling service website.

These suggestions will help you keep your account information secure and will go a long way towards preventing your account from being compromised. Also, not buying plat or power leveling will help reduce the problem as a whole, as without a demand, they will not be able to operate.

While it is our current policy to assist with these issues and to restore characters and guild banks to the best of our ability, please remember that we may not be able to assist with repeated occurrences of compromised accounts and that we cannot guarantee that we can restore you back to exactly where you were when your account was compromised.

If you are interested in finding out more info about our EULA or Account Security Policy, please see the links below.

EULA:
http://help.station.sony.com/cgi-bi...p?p_faqid=12248

Account Security Policy:
http://help.station.sony.com/cgi-bi...p?p_faqid=16231



LINK
Official Forums is offline   Reply With Quote
Old 07-23-2009, 01:39 PM  
L337 Poster
 
Diknak's Avatar
 
Character: Diknak
Guild: Conquest
Server: Butcherblock

Posts: 1,618
Photos: (0)

Default Re: (Kiara) Account Security

Is it me, or is this whole post about blaming the victim?

My account got hacked and I never bought plat/power leveling and never gave my info to anyone. The ass sold everything on me and I only recovered about 30% of my plat.
Diknak is offline   Reply With Quote
Old 07-23-2009, 01:44 PM  
راضیه
 
razieh's Avatar
 
Character: Razieh
Guild: Equestrian Prep
Server: Unrest

Posts: 2,952
Photos: (29)

Send a message via MSN to razieh
Icon8 Re: (Kiara) Account Security

Your password must suck. On a second note you should frequently change your password and not use obvious logins. :/
__________________
J'avance plus vite que la musique!
Quote:
Originally Posted by Dants View Post
How come when I type /mvp in game after we kill a raid mob it always displays razieh?
razieh is offline   Reply With Quote
Old 07-23-2009, 01:48 PM  
The Most Interesting Man in the World.
 
KFizzle's Avatar
 
Character: KFizzle/Antarafein/Kajar
Guild: Has Gone Linkdead/Treadstone
Server: Nektulos

Posts: 2,433
Photos: (0)

Send a message via AIM to KFizzle Send a message via MSN to KFizzle
Default Re: (Kiara) Account Security

Quote:
Originally Posted by Diknak View Post
Is it me, or is this whole post about blaming the victim?
I never had my account hacked, but yes this totally seems about blaming the victim. You shouldn't have worn that dress if you didn't want to be raped. Why were you driving at night down that highway, if you didn't want to be hit by a drunk driver. You shouldn't have gone to that neighborhood if you didn't want to be robbed. It's your fault.
__________________


Quote:
Originally Posted by Hoss View Post
Kfizz, I'm suing you for raping me.
KFizzle is online now   Reply With Quote
Old 07-23-2009, 01:53 PM  
L337 Poster
 
Character: Deson
Guild: Unbound
Server: Lucan

Posts: 4,725
Photos: (0)

Default Re: (Kiara) Account Security

Actually it looks more like blaming the victim that genuinely deserved it. while there are hacks that do occur that aren't the victims fault, CS will tell you flat out, as will most victimized users, almost all hacks occur because the user did something that compromised security. This isn't like blaming the rape victim, it's more like blaming the person who responded to the prince in Nigeria.
__________________
Quote:
Originally Posted by Locke View Post
I need to stop visiting this site, but I need my seasonal dose of spectating trainwrecks.Locke's story of game development; Locke's story of Eq2 development
Deson is offline   Reply With Quote
Old 07-23-2009, 02:04 PM  
Done
 
Character: Calaglin
Guild: Dissolution
Server: Nektulos

Posts: 11,726
Photos: (0)

Send a message via ICQ to Pinski Send a message via AIM to Pinski Send a message via MSN to Pinski Send a message via Yahoo to Pinski
Default Re: (Kiara) Account Security

A vast majority of times an account in an MMO gets "hacked", it's done so through Social Engineering. People aren't going around brute-forcing their way in, they're attacking the user to get them to install software to get your user/password. So yeah, it generally IS the user's fault.
__________________
Calaglin, Former Illusionist/Guild Leader of Dissolution on Nektulos
Calaglin, Former Illusionist/Guild Leader of Confirmed on Unrest
Pinski is online now   Reply With Quote
Old 07-23-2009, 02:39 PM  
25 Star General
 
Argyuile's Avatar
 
Character: Argyuile/Serpicos
Server: Unrest

Posts: 2,863
Photos: (0)

Default Re: (Kiara) Account Security

Quote:
Originally Posted by Pinski View Post
A vast majority of times an account in an MMO gets "hacked", it's done so through Social Engineering. People aren't going around brute-forcing their way in, they're attacking the user to get them to install software to get your user/password. So yeah, it generally IS the user's fault.
Thats why I change my PW every week and post on my blog so I remember where it is.
__________________
Quote:
Originally Posted by oddyophile View Post
All thanks to Argyuile's ass.
Essential guide for posting on Flames

I'm willing to entertain your idiotic notion of how reality works if it'll get you to the point faster - Black Mage

It's time to prove to your friends that you're worth a damn. Sometimes that means dying, sometimes it means killing a whole lot of people. - Dwight
Argyuile is offline   Reply With Quote
Old 07-23-2009, 05:24 PM  
Lulz
 
Pink Poodle's Avatar
 
Character: Rhoslyn/Imtithal
Guild: Circle of the Greater Wyrm/Disciples of Chaos
Server: Befallen/Nagafen

Posts: 10,725
Photos: (0)

Send a message via AIM to Pink Poodle
Default Re: (Kiara) Account Security

And phishing. Remember that TSO beta thing a while back?
__________________

Rave Ghost says: "EQ2Flames on ED: Click here! And Part two! Some NSFW content present."
Pink Poodle is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


Sponsor Ads


All times are GMT -4. The time now is 03:30 AM.


Design By: Miner Skinz.com Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0
Template-Modifications by TMS