Play Now Login Create Account
illyriad
  New Posts New Posts RSS Feed - Account Hacks
  FAQ FAQ  Forum Search   Register Register  Login Login

Topic ClosedAccount Hacks

 Post Reply Post Reply Page  <1 2345>
Author
Ander View Drop Down
Postmaster General
Postmaster General
Avatar

Joined: 24 Apr 2011
Status: Offline
Points: 1269
Direct Link To This Post Posted: 02 Dec 2015 at 13:48
Originally posted by Serpentina Serpentina wrote:


Rikoo, can you see if Bob's abandonment was done during the same session?  Or in a subsequent session from the same IP?  If it was done from a different IP, and that traceroutes to a different geographical location, it'd sure lend credence that this may have been a hack.

This could also find out if the abandon was done by a sitter, exploiting the bug in the game. (If he had a sitter that is).

This bug hasnt occurred to me lately, but it occurred 3-4 times in a span of a few months when I used to log into my sitter's account frequently (when i was taking resources from her city to build up). So it is not all that uncommon.


Back to Top
Ander View Drop Down
Postmaster General
Postmaster General
Avatar

Joined: 24 Apr 2011
Status: Offline
Points: 1269
Direct Link To This Post Posted: 02 Dec 2015 at 14:06
I have found the IGM discussing this problem, will forward to GM Rikoo. The IGM has a snapshot of the problem also.
Back to Top
GM Rikoo View Drop Down
Moderator Group
Moderator Group
Avatar
Community & PR Manager

Joined: 28 Mar 2014
Location: Mars
Status: Offline
Points: 1233
Direct Link To This Post Posted: 02 Dec 2015 at 14:29
OK, one second.

If there is a separate issue with sitters, etc, please use the petition system and send me the information. Let's keep this topic on track or it will not work. I believe we have already spoke in game about the sitter issue, but I received an IGM, ****not a petition****.

I cannot stress this enough:

PLEASE petition issues. If you think it is something urgent or gamebreaking, send me an IGM. If a petition seems important and has gone unanswered for months or years, LET ME KNOW. I CANNOT READ MINDS.

Seriously... we created a petition system that is a bit TOO good for such a small team. There are too many of them, most that can be shut down because the issues have been fixed or can be fixed now, quickly. POINT THEM TO ME. Help me out, please. 

Having said that:

1) No, we ***will not*** compensate players who have been hacked, claim to have been hacked, or somehow lost control over their account. We have successfully used this system for years, with tens of thousands of abandons, with barely any issues.

2) We will not add a delay or a chance to "take back" an abandon. Imagine: Tony marks his account as abandoned, gets a bunch of attacks coming in, then claims it back and goes "HELP!!" - drama ensues. 

We will look into other possible things we can tweak, but the system works great as it is. 

Rikoo




Illyriad Community Manager / Public Relations / community@illyriad.co.uk
Back to Top
Brandmeister View Drop Down
Postmaster General
Postmaster General
Avatar

Joined: 12 Oct 2012
Location: Laoshin
Status: Offline
Points: 2396
Direct Link To This Post Posted: 02 Dec 2015 at 17:20
This really isn't a problem with the Abandon function. It's a problem with account security, probably caused by password problems. Even if the devs "fixed" the Abandon function with extra steps or a timer, someone can still trash your account by demolishing cities, wasting your resources, disbanding your troops, exhausting your prestige, or any number of other undesirable things.
Back to Top
Sheza View Drop Down
Forum Warrior
Forum Warrior
Avatar

Joined: 16 Oct 2012
Location: Kumala
Status: Offline
Points: 325
Direct Link To This Post Posted: 02 Dec 2015 at 18:05
Brand, that is true. but from that I can recover. I cant recover abandon. 
if I sign in and see my caravans going to your castle I pretty much know whos the bad guy 
(Brand you are not a bad guy. in fact a hero type) 
But Just saying 
If Horses don't go to Heaven when they die. then I want to go where they go.
Back to Top
Bobtron View Drop Down
Wordsmith
Wordsmith
Avatar

Joined: 21 Mar 2015
Location: Canton
Status: Offline
Points: 123
Direct Link To This Post Posted: 03 Dec 2015 at 02:19
 For the people who think I abandoned on purpose - Why on earth would I ever do that?!? 1.5 billion gold in trade hubs, equipment, and prestige, along with some nicely situated towns. An according to my browser history on all home computers, I didn't visit illy at all during November, let alone account abandon, except on my main desktop. I had no sitters for at least 6 months, and since my password registers as 'strong', I am forced to accept that my account was compromised/hacked in some way. (SQL injection?)

Why not make some sort of a delay, or password reentry, or email verification, or that account abandons don't fully wipe out everything? You can make it so then Tony's account is only marked abandoned when everything is officially wiped, and not when there is still a chance of recovery, during a (3 day?) period. And the password reentry would stop, say, an account abandon when you're on a bathroom break. The email verification would serve to ensure that a player consents to such an abandonment, and if the email address is changed right before the abandonment, the gms can recompensate such players.

In overarching sense, yes, the system might work "great", but remember, just because no one complains, it doesn't mean that all the parachutes are fine. Maybe there were more cases of mysterious abandonment that went unnoticed because the players didn't want to go to the trouble of rebuilding everything, or other players that simply went solo.
I support the Undying Flame!
Back to Top
GM Rikoo View Drop Down
Moderator Group
Moderator Group
Avatar
Community & PR Manager

Joined: 28 Mar 2014
Location: Mars
Status: Offline
Points: 1233
Direct Link To This Post Posted: 03 Dec 2015 at 02:24
1) I will not discuss the particulars of your issue in the forums.

2) We already discussed why a delay would be a bad idea. We cannot allow a player to mark themselves as abandoned, only to return shortly... for many reasons.

3) We have already taken suggestions for email verification, etc, in this thread and in communications with you.

4) We do not register problems only when people complain. We have other ways of noticing when an issue is an issue. Again, the system has worked almost perfectly for many years. 

If anyone has any new suggestions, please feel free to post them here. Going over the same points we have already gone over would do no good, as I can only copy them down once.

Thanks all!


Rikoo


Illyriad Community Manager / Public Relations / community@illyriad.co.uk
Back to Top
jcx View Drop Down
Forum Warrior
Forum Warrior


Joined: 09 Oct 2013
Location: Tallimar
Status: Offline
Points: 281
Direct Link To This Post Posted: 03 Dec 2015 at 05:38
Have you tried entering wrong password for 5 times in a row? if you haven't yet. Try it.

I think Illyriad has properly put security processes in place. 

I think the real problem here is when we share our passwords to other in-game players. 

I suggest you change your passwords: put something like in UPPER CASE + lower case (Letters) + 5p3ci@l Ch@rat3r$ + 1234567890. 

And please no sharing for Illyriad's login and password. :)

I agree with GM Rikoo! 
Disclaimer: The above is jcx|orcboy's personal opinion and is not the opinion or policy of Harmless? [H?] or of the little green men that have been following him all day.

jcx in H? | orcboy in H?
Back to Top
Angrim View Drop Down
Postmaster General
Postmaster General
Avatar

Joined: 02 Nov 2011
Location: Laoshin
Status: Offline
Points: 1212
Direct Link To This Post Posted: 04 Dec 2015 at 00:35
Originally posted by GM Rikoo GM Rikoo wrote:

1) No, we ***will not*** compensate players who have been hacked, claim to have been hacked, or somehow lost control over their account.
compensation cannot be a serious suggestion. imputing a value to whatever players feel they have invested in an account would lead to a pandora's box of legal implications i cannot begin to fathom, and here i am passing blithely over the issue of "has the account really been hacked?", which would suddenly become the responsibility of the devs to determine. this way leads to madness. Rikoo's reaction seems kind compared to what i would expect to see from GM Stormcrow.

Originally posted by GM Rikoo GM Rikoo wrote:

We have successfully used this system for years, with tens of thousands of abandons, with barely any issues.
i read this as "the burden of proof is on you (BobTron) to demonstrate there is a problem with a system that has worked so well for so long." if information will help you construct a timeline, ask for that (privately, not via the forum).

Originally posted by GM Rikoo GM Rikoo wrote:

2) We will not add a delay or a chance to "take back" an abandon. Imagine: Tony marks his account as abandoned, gets a bunch of attacks coming in, then claims it back and goes "HELP!!" - drama ensues.
i'm not sure i'm in favour of this, but the way to make this work is to allow a player to register his/her intention to abandon and then execute the actual abandonment after a three days absence (or appropriate period). nothing is done to the account during the countdown. if the player signs into the game during those three days, s/he is greeted with a "glad you changed your mind" message and the game tosses out the timer. if the player stays out for the required time, the account is abandoned at the end of the waiting period. (again, not trying to convince anyone of this, just laying out how it might be done *if* the devs were interested.)
Back to Top
GM Stormcrow View Drop Down
Moderator Group
Moderator Group
Avatar
GM

Joined: 23 Feb 2010
Location: Illyria
Status: Offline
Points: 3926
Direct Link To This Post Posted: 04 Dec 2015 at 01:56
I've resisted commenting on this thread, but now that this is raising questions about the security of the entire system, I feel I have to.  

I certainly don't want anyone feeling that our system is compromised in any way whatsoever.

Originally posted by Bobtron Bobtron wrote:

I am forced to accept that my account was compromised/hacked in some way. (SQL injection?)

Put simply, no.  Sorry.

Illyriad has really quite serious security features - most of them invisible.  

We completely log every single click ingame, with full audit trails.  

We're not - and have never been - vulnerable to SQL injection, and I'd be grateful if people could stop stirring up potentially damaging clouds of FUD on subjects they know little about.  However, for obvious reasons, we don't specifically outline our security policies and protocols.

What I can say is that we know who was logged in, what credentials they used to log in - and even the details of their specific browser and session, logged to the millisecond with every single click that anyone makes on anything in the entire game.  

This is stuff *way* beyond the fairly blunt instrument of IP addresses; we track to the actual browser session itself (and beyond).

Suggestions about "delays" and "2 factor verification" etc are nice and all... but they're a sideshow to the fundamental truth that we do actually know what buttons were pressed, when they are pressed, and what credentials, IPs and browser session cookies were being used to authenticate their usage.  

Regards,

SC
Back to Top
 Post Reply Post Reply Page  <1 2345>
  Share Topic   

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.03
Copyright ©2001-2019 Web Wiz Ltd.