Unauthorised Access to ingame accounts
Posted: Thu Jul 17, 2008 11:40 pm
Well, as the majority of you will know there have been some recent incidents where people have made unauthorised access to other people's ingame accounts, and stripped them of their resources. The most recent incidents involved Marshall and Celestial Being where both received unauthorised access on their accounts, trades made between both accounts and then accounts ascended. Admin's stance on this seems to be that if game accounts have been hacked that no resources will be returned, but they will give out details of where resources were sent to. viewtopic.php?f=8&t=119588&p=1438135#p1438135
Now I'm sure there will be plenty of you that completely disagree with Admin's desicion, there will be some that agree and some that sit on the fence. Even though I feel people that cheat in this game are complete scum, I do kind of agree with Admin but only under certain circumstances.
You'll notice I titled this thread "Unauthorised Access to ingame accounts" as opposed to "Hacked ingame accounts". The reason for this is because I personally feel that the term "hacked" is used way too often on this forum, and in 99% of the cases it is likely that accounts were NOT hacked. Some people I feel do not understand the concept of being hacked. If SGW were to be hacked, then this means that there is a security flaw within the game that has been breached. If this is the case then it is of no fault of the user that has lost resources and I personally feel in these occasions that resources should be returned.
However, I do understand that it would be very difficult to track resources if they have been sent on to numerous accounts or sold to other account for ingame resources as it becomes too difficult to decide what resources to take away from people, and sometimes would probably require the game to be temporarily shutdown while it is sorted out to prevent those resources moving any further. If that happens then you get people complaining that they can’t access the game and it’s a lose lose situation for Admin.
However, on 99% of these situations where accounts have had unauthorised access, I believe it is of NO fault by the admin because there is no security flaw that has become vulnerable. In majority of cases it is most likely that the victims have fallen victim to a virus or trojan attack on their PC and their login details for SGW have been obtained via that method.
The number of times I have received a message on MSN with a very obvious link that is not genuine, and will either direct me to a website that will automatically attempt to download a virus/Trojan to my PC if I click on the link, or will send me to a website of familiarity such as ebay, my bank or Facebook where it will bring up the login screen is crazy. It happens constantly, and in fact I received a similar only a few days ago. This sort of method would quite clearly be an attempt to get you to login to the relevant accounts and login details would be phished by someone. The person trying to obtain those details could attempt to use them in SGW and try and access your account. Or a Trojan could be installed on your PC with a key logger and obtain your SGW login details that way.
If this is the case then it is of NO fault by Admin because there has been no security flaw identified and abused on the game. Therefore in this type of case the personal responsibility falls down to the individuals playing the game. Even if a user is not aware they have a virus or Trojan on their PC and their SGW login details have been obtained then they are still (in my eyes) not entitled to receiving any lost resources because it is not a fault of the game. However if the person making the unauthorized access happens to delete the account then I feel it is only right for admin to get it back and access given back to the rightful owner.
It is not only virus and trojan attacks on users PCs that could be a cause of Unauthorised Access to ingame accounts. Many of you will be members of various forums. Some of you may use the same login details (which is down right stupid) and some will use different login details. However, these forums are also at risk of “back-door” attacks. I have my own forum, and quite often there are patch updates that need to be installed due to security flaws etc being identified by the company behind the forums etc. If someone gets illegal access to a database of a forum you are on and obtains login details and tries them in SGW and gets access, then again that is of no fault by Admin and no resources lost should be returned.
Admin would quite clearly be able to see whether someone has obtained illegal access to the game database by hacking methods. Therefore in any cases where Admin do not provide lose resources then it is likely that the Account in question was NOT hacked.
As I said earlier, the term “hacked” is used way too often and most of the time it is used incorrectly.
So I personally feel that any loss of resources or accounts due to an abuse of a security flaw INGAME should be returned to the rightful owner. Any loss of resources or accounts due to non-ingame related abuse (i.e. login details obtained elsewhere) should not be returned to their rightful owner.
I’d like to know other thoughts on this?
I'm not using this thread as a platform to launch an attack against the Admin about their decision. Please can you not use this as an attack either, but more to just put views forward. If I see any posts that personally attack any of the Admins on their decision I will be asking for this thread to be closed immediately.
Now I'm sure there will be plenty of you that completely disagree with Admin's desicion, there will be some that agree and some that sit on the fence. Even though I feel people that cheat in this game are complete scum, I do kind of agree with Admin but only under certain circumstances.
You'll notice I titled this thread "Unauthorised Access to ingame accounts" as opposed to "Hacked ingame accounts". The reason for this is because I personally feel that the term "hacked" is used way too often on this forum, and in 99% of the cases it is likely that accounts were NOT hacked. Some people I feel do not understand the concept of being hacked. If SGW were to be hacked, then this means that there is a security flaw within the game that has been breached. If this is the case then it is of no fault of the user that has lost resources and I personally feel in these occasions that resources should be returned.
However, I do understand that it would be very difficult to track resources if they have been sent on to numerous accounts or sold to other account for ingame resources as it becomes too difficult to decide what resources to take away from people, and sometimes would probably require the game to be temporarily shutdown while it is sorted out to prevent those resources moving any further. If that happens then you get people complaining that they can’t access the game and it’s a lose lose situation for Admin.
However, on 99% of these situations where accounts have had unauthorised access, I believe it is of NO fault by the admin because there is no security flaw that has become vulnerable. In majority of cases it is most likely that the victims have fallen victim to a virus or trojan attack on their PC and their login details for SGW have been obtained via that method.
The number of times I have received a message on MSN with a very obvious link that is not genuine, and will either direct me to a website that will automatically attempt to download a virus/Trojan to my PC if I click on the link, or will send me to a website of familiarity such as ebay, my bank or Facebook where it will bring up the login screen is crazy. It happens constantly, and in fact I received a similar only a few days ago. This sort of method would quite clearly be an attempt to get you to login to the relevant accounts and login details would be phished by someone. The person trying to obtain those details could attempt to use them in SGW and try and access your account. Or a Trojan could be installed on your PC with a key logger and obtain your SGW login details that way.
If this is the case then it is of NO fault by Admin because there has been no security flaw identified and abused on the game. Therefore in this type of case the personal responsibility falls down to the individuals playing the game. Even if a user is not aware they have a virus or Trojan on their PC and their SGW login details have been obtained then they are still (in my eyes) not entitled to receiving any lost resources because it is not a fault of the game. However if the person making the unauthorized access happens to delete the account then I feel it is only right for admin to get it back and access given back to the rightful owner.
It is not only virus and trojan attacks on users PCs that could be a cause of Unauthorised Access to ingame accounts. Many of you will be members of various forums. Some of you may use the same login details (which is down right stupid) and some will use different login details. However, these forums are also at risk of “back-door” attacks. I have my own forum, and quite often there are patch updates that need to be installed due to security flaws etc being identified by the company behind the forums etc. If someone gets illegal access to a database of a forum you are on and obtains login details and tries them in SGW and gets access, then again that is of no fault by Admin and no resources lost should be returned.
Admin would quite clearly be able to see whether someone has obtained illegal access to the game database by hacking methods. Therefore in any cases where Admin do not provide lose resources then it is likely that the Account in question was NOT hacked.
As I said earlier, the term “hacked” is used way too often and most of the time it is used incorrectly.
So I personally feel that any loss of resources or accounts due to an abuse of a security flaw INGAME should be returned to the rightful owner. Any loss of resources or accounts due to non-ingame related abuse (i.e. login details obtained elsewhere) should not be returned to their rightful owner.
I’d like to know other thoughts on this?
I'm not using this thread as a platform to launch an attack against the Admin about their decision. Please can you not use this as an attack either, but more to just put views forward. If I see any posts that personally attack any of the Admins on their decision I will be asking for this thread to be closed immediately.