

Forum Db Compromised? Spam To Unique Address...
#21
Posted 07 January 2013 - 07:43 AM
#22
Posted 07 January 2013 - 08:38 AM
SmackZ, on 07 January 2013 - 07:43 AM, said:
...same.
#23
Posted 07 January 2013 - 08:40 AM
#24
Posted 07 January 2013 - 08:55 AM
Has anyone noted any strange behaviour on their credit cards? paypal? bank accounts?
No?
All is well.
Edited by DV McKenna, 07 January 2013 - 08:55 AM.
#25
Posted 07 January 2013 - 09:02 AM
Bryan Ekman, on 13 December 2012 - 04:14 PM, said:
- At no time were any databases containing personal information compromised. This includes e-mails and passwords.
- PGI and IGP does not store, nor have access to any user credit card information.
- Account passwords are encrypted, salted, peppered and stored in databases not affected by today’s incident.
It's hard to have any faith in the latter given the lack of truth and feedback on the former.
#26
Posted 07 January 2013 - 09:14 AM
#27
Posted 07 January 2013 - 09:25 AM
Inertiaman, on 07 January 2013 - 09:02 AM, said:
It's hard to have any faith in the latter given the lack of truth and feedback on the former.
Your card details go to a third party who deals with the transaction, PGI do not hold that info it quite clearly states that.
And its your monetary info, that is important.
#28
Posted 07 January 2013 - 09:29 AM
#29
Posted 07 January 2013 - 09:32 AM
DV McKenna, on 07 January 2013 - 09:25 AM, said:
Your card details go to a third party who deals with the transaction, PGI do not hold that info it quite clearly states that.
Yeah I'm fairly au fait with ecomm - but again - the point is that it also clearly states that the no email addresses were compromised yet they were. Generally were this to happen you'd change your password and crack on. In this case though is there any latent security issue remaining? Have they fixed the problem? What was the impact? Will we be given the functionality to change email address on our profile etc.
just saying "it clearly says everything is ok" hardly answers any of the above - and doesn't demonstrate if it's a serious or trivial problem either way.
#30
Posted 07 January 2013 - 09:35 AM
Yet the question remains, aside from your monetary info, what else is there to gain from your MWO account?
There are no transfers possible, except for spite there is no physical gain for any hackers, Chinese farmers.
#31
Posted 07 January 2013 - 09:39 AM
The Penny Arcade tutorial and free premium time showed up by either a link in the forums or an ad on home (I can't remember which) on that same day and you had to put in your email to redeem the premo time. Just a thought.
I know nothing about Penny Arcade so total speculation.
I did not redeem that day.
#32
Posted 07 January 2013 - 09:47 AM
DV McKenna, on 07 January 2013 - 09:35 AM, said:
Yet the question remains, aside from your monetary info, what else is there to gain from your MWO account?
There are no transfers possible, except for spite there is no physical gain for any hackers, Chinese farmers.
Well if the website was compromised, it's entirely possible for them to have implemented code into the form used for entering your payment info, and having that sent to both the processor and the 3rd party individual who compromised the website. There's a lot of unknown's that could have happened, I would be watchful of entering my info on the website.
#33
Posted 07 January 2013 - 09:53 AM
#34
Posted 07 January 2013 - 09:55 AM
Anyways, posting about this on the forums is not the most efficient way to notify the webmaster about it or to receive Support assistance. If there was a significant problem, then telling the non-employees won't help as much as telling the employees. You can always write an email to support@mwomercs.com to get an official report generated.
(also, remember that the MC purchases you do over this website takes place on ultimatepay servers (playspan servers) through a secure link to their website in the new frame that pops up - the financial transactions are not hosted on mwomercs.com servers and neither is your payment/CC info. the only "account info" they store here is your MC spending in the game client, viewable whenever you click the "Buy MC" button on the game homepage)
Edited by Prosperity Park, 07 January 2013 - 09:55 AM.
#35
Posted 07 January 2013 - 10:00 AM
#36
Posted 07 January 2013 - 10:02 AM
Point 1) Your email database was lifted at least in part. This is supported by the number of using using MWO specific aliases and not even a debate at this point.
Point 2) Our comments on the forums are there in response to the pinned Official Announcement on the matter. If you'd like a deluge of support mails on the subject feel free to post in the Official Announcement telling everyone with an issue to do so.
Point 3) The ultimatepay setup is easily replicable if the MWO site is compromised. If PGI have verification in place to ensure that the content their site serves is consistent and secure I'm not seeing any evidence of it from an external pov.
I'd really recommend taking some advice from the forums once in a while. On most matters some people seem a few steps ahead of the management.
Moreover - if you're handling money for people you have an obligation to ensure their security. It is not obvious at all that this obligation is being taken seriously.
Edited by Inertiaman, 07 January 2013 - 10:01 AM.
#37
Posted 07 January 2013 - 10:05 AM
#38
Posted 07 January 2013 - 10:06 AM
Inertiaman, on 07 January 2013 - 10:00 AM, said:
Point 1) Your email database was lifted at least in part. This is supported by the number of using using MWO specific aliases and not even a debate at this point.
Point 2) Our comments on the forums are there in response to the pinned Official Announcement on the matter. If you'd like a deluge of support mails on the subject feel free to post in the Official Announcement telling everyone with an issue to do so.
Point 3) The ultimatepay setup is easily replicable if the MWO site is compromised. If PGI have verification in place to ensure that the content their site serves is consistent and secure I'm not seeing any evidence of it from an external pov.
I'd really recommend taking some advice from the forums once in a while. On most matters some people seem a few steps ahead of the management.
Point 1 ) It is not his email database, he is a community moderator, not an employee, you'd do well to learn the difference in that aspect
Point 3) Given that nobody has had any suspicious transactions for any of their payment methods as yet, that answers that question
What PP is actually saying is correct, once you choose the amount of MC you want, your then directed outside of PGI's servers, you can quite clearly see that in the pop up window, you'd have to more than a simple injection script to change that part.
GioAvanti, on 07 January 2013 - 10:00 AM, said:
Not great news, but ultimately harmless unless they have access to your actual inbox.
Edited by DV McKenna, 07 January 2013 - 10:07 AM.
#39
Posted 07 January 2013 - 10:06 AM
Edited by Inertiaman, 07 January 2013 - 10:07 AM.
#40
Posted 07 January 2013 - 10:10 AM
This lets them browse the forums more efficiently.
Edited by Prosperity Park, 07 January 2013 - 10:11 AM.
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users