2011-10-03 Path of Exile brute force attack incident report

Thanks for the info, guys.

Glad to see measures are being taken.
"
Ryukaki wrote:
Thank you for the quick, efficient response, GGG.

The steps you are taking should be sufficient, although I would recommend you also include the requirement that people include at least one (1) number and one (1) capital letter in their passwords. In this day and age with the ability to do things like brute force over proxy servers, change MAC addresses, and other such tools, an attacker who is more sophisticated could still cause problems attacking all accounts, with simple passwords. (123456, password, etc.)

These kinds of attacks are incredibly common and fairly easily mitigated and I'm very glad nothing was seriously compromised.

Your detailed incident reports and your ability to be honest, forward, and list a plan of action in rectifying the situation is stellar customer service and only reflects well on you.

Thanks a bunch :)


Number of characters are a lot more prudent at defending against brute forcing than stupid rules like 1 big letter and 1 number. If you have a 6 digit code with numbers, small letters and big letters, an 8 digit code with only small letters would mathematically be about 4 times better(assuming 10 numbers and 26 letters)...
At the same time its often easier to remember an 8 small letters code than a 6 digit combined code.
Therefore I can recommend a mathematical approach to password-protection rather than rule-based. (Another later user explains it digitally in a picture).
I appear to be living in "Romance Standard Time". That has to be good! :)
Good to see that you are this involved with the community!

Loving the honest and emidiate response, letting everyone know when, how and why. This only makes me more confident in both the game and the company behind it.

I tip my hat to you GGG.
"It is my conviction that killing under the cloak of war is nothing but the act of murder" - Albert Einstein.
I see this as only a good thing:

Bored kid gets nothing
Security improves
People get some password education
We all see how transparent GGG are :)
All above speeling mistakes are intentional.
what i can say, timer drives people crazy))))
I was bound to happen eventually. Some douchebag of the first degree gets it up their bum that they are going to break into this or that because they are impatient and weak minded, or were severely picked on in school. I don't advocate bullying at all, but douchebags who do THIS deserve their asses kicked.

And a message for mister hacker: Ever heard of thing called delayed gratification? Too bad your dad didn't understand the concept when he was slipping your mom his little flesh data stick.

Last edited by Quellan#4867 on Oct 3, 2011, 9:13:10 AM
I am glad that security is being tightened. I was afraid that there were little to no security measures. Amazing response time by GGG to inform their customers immediately, instead of waiting for a week like Sony did with the ps3.

See Sony? A huge team of lawyers and too big to fail tech giants pails in comparison to a small developer with a pulse on their customer base.

Scores for customer support?

GGG - 1,000,000,002
Sony - 1 (they only get this because they own Kratos and he is fun!)
Glad to see a quick response from you, and knowing how to react. Shame other companies don't seem to be "on the ball" like that.
I am not a female, but I really wish I was. <3
"
Quellan wrote:
I was bound to happen eventually. Some douchebag of the first degree gets it up their bum that they are going to break into this or that because they are impatient and weak minded, or were severely picked on in school. I don't advocate bullying at all, but douchebags who do THIS deserve their asses kicked.

And a message for mister hacker: Ever heard of thing called delayed gratification? Too bad your dad didn't understand the concept when he was slipping your mom his little flesh data stick.



Or maybe he did that,because he can ?
"
I was bound to happen eventually. Some douchebag of the first degree gets it up their bum that they are going to break into this or that because they are impatient and weak minded, or were severely picked on in school. I don't advocate bullying at all, but douchebags who do THIS deserve their asses kicked.

And a message for mister hacker: Ever heard of thing called delayed gratification? Too bad your dad didn't understand the concept when he was slipping your mom his little flesh data stick.




"
Or maybe he did that,because he can ?


Hey a douche bag is still a douche bag! Lol
But yeah, some people hack for sport. The new world we live in. Amazing isn't it?
Last edited by Ingmartin#0616 on Oct 3, 2011, 10:28:49 AM

Report Forum Post

Report Account:

Report Type

Additional Info