Jump to content
LOTROCommunity
Sign in to follow this  
Malindruil

MyLotro Hacked as well .........?

Recommended Posts

A known issue? Damn Turbine - I really want Codies back :(

Thanks SoDT your fix worked for a few minutes anyway ;)

Ellie

Happened to me yesterday as well. Made a thread in the "General Discussion" forum about it and it was moved to the "Community Site General Discussion and Feedback" forum without any reply.

http://forums.lotro.com/showthread.php?403587-Logged-in-as-someone-else

Its been happening for months now. Even if its not a security issue, it certainly looks worrying, so why haven't they fixed it yet?

Share this post


Link to post
Share on other sites

Even if its not a security issue, it certainly looks worrying, so why haven't they fixed it yet?

The possibility exists for one user to log in under another user's profile. Even in the simplest terms that is a security issue, no matter how many ways Turbine may wish to spin it.

Share this post


Link to post
Share on other sites

How can they say it's not an issue? The thought of potentially being banned because someone managed to log in to their forums using my profile and post all sorts of garbage certainly sounds like a problem to me. And no doubt if that happened, it would then be for me to somehow prove innocence.

I think we really do need to specifically log out of sites before closing browers these days...not something I've been doing as a matter of course but if these companies have such poor security systems in place...

Share this post


Link to post
Share on other sites

The possibility exists for one user to log in under another user's profile. Even in the simplest terms that is a security issue, no matter how many ways Turbine may wish to spin it.

It depends whether you are actually logged in, or only appear to be and what pages you'll see when it happens. If you only see the main forum page or an error screen, and as soon as you click anything you'll be back on your account, there isn't really anything that can happen because of it. Obviously there's no way to know if this is the case or not, so as I said whether it is an issue or not, they should still fix it.

How can they say it's not an issue? The thought of potentially being banned because someone managed to log in to their forums using my profile and post all sorts of garbage certainly sounds like a problem to me. And no doubt if that happened, it would then be for me to somehow prove innocence.

I think we really do need to specifically log out of sites before closing browers these days...not something I've been doing as a matter of course but if these companies have such poor security systems in place...

As soon as I clicked a link, I was back on my own page. If that always happens, then no one can actually do anything on your account if it happens. Its still worrying obviously.

Share this post


Link to post
Share on other sites

Ah, well that doesn't sound quite so bad.

It did remind me of my early days on that there internet thingy. Fired up my fabulously fast 300 baud modem and connected to my email provider. Wondered why I wasn't asked to log in...very soon realised I was already logged in on someone elses account. Could see his inbox, went through the motions of creating a new email. Didn't send it of course, or look at any of his stuff. Just logged it out properly and logged myself back in. It was an early wakeup call though and something that I'd forgotten all about till now.

Share this post


Link to post
Share on other sites

Even if you cant do anything the fact that there is a flaw in there systems is worrying and the fact hat they dont seem to want to do anything about it is just as bad. Given that flaw exists it is not unreasonable to assume that someone could find other more serious flaws

Share this post


Link to post
Share on other sites

Just got an e-mail saying Bioware had been hacked to and advising me to change my EA account password.

http://social.bioware.com/forum/1/topic/6/index/7653193

This is starting to get seriously irritating now.

Edit: oops meant to post this in the Codemasters Hacked thread, oh well...

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
Sign in to follow this  

×
×
  • Create New...