| Pages: 1 [2] :: one page |
| Author |
Thread Statistics | Show CCP posts - 7 post(s) |

Pilk
Axiom Empire
|
Posted - 2007.11.29 10:41:00 -
[31]
Originally by: Andrue Pilk, I think you are overreacting. The warning was timely (as you say) but also brief and to the point. It contains useful advice that every computer user should follow all the time.
The fact that so many people are asking MS how to hide the warnings and how to turn off UAC and run as administrator is a sad reflection on the users. I bet those people don't whine and moan to the builder for putting security locks on doors and windows. Then again a fair number do moan about seatbelts in vehicles so perhaps we just have to accept that a large minority of the population are fools.
The rest of us need to be sympathetic, try to educate them and if all else fails put them in a locked room and throw away the key. Er.. Sorry. That last bit may have sounded a litle harsh 
True, I probably am overreacting, but I think not without some jusification. I have become sick of the UI designers who have forgotten the hard-won lessons of dancing pigs, and of self-proclaimed "security experts" who know nothing more than how to install their favored suite of protective software, proclaiming how they are under constant attack by the eeeeeebil hackers, as evidenced by the log showing over THREE HUNDRED cookie deletions. The reality is, computer security is complex, and security software and advice should be designed to insulate the user from that complexity, while silently allowing them to go about their business.
Really, even an "if possible" prepended to the recommendation to avoid use of email to communicate with fellow players would have placated me. As it stands, the recommendation combines the worst elements of security communication:
- It doesn't help; the attacker(s) will just send their victim to a website, which is a far easier attack vector than an email, anyway.
- It's opaque; for instance, users may think that by following it, they may safely open emails purporting to be from CCP because nobody but CCP has their address, when the malicious party in fact just happened to guess correctly.
- And last but not least, it is draconian in the extreme. This attribute guarantees that the average user won't follow it, and studies show that once users dismiss any part of a security scheme, product or process, they are very likely to bypass the offending element as a whole.
--P
Kosh: The avalanche has already started. It is too late for the pebbles to vote. |

Purlon
|
Posted - 2007.11.29 11:17:00 -
[32]
You know it might be time for online game companies to start offering extra layers of security themselves.
A simple floating keypad would almost eliminate keyloggers, might be a pain to use but at least you would be using your mouse to type in your password. Many banks are rolling this stuff out now.
What about one time passwords? Could CCP send a one time password via sms or some other out of band authentication? Hmmmm
Customers (in my field of work) are now starting to understand the value of their identity and how easily it can be stolen and on sold (to hackers or whoever) from the internet channel. And now they are demanding extra layers of security to keep using products (like internet banking for example).
Also, a floating keyboard would eliminate macro's that login to eve online automatically as the keyboard would be in a differnet position everytime.
Anyways, my 2 cents.
|

Snowcrash Winterheart2
Gallente Vanguard Venture
|
Posted - 2007.11.29 12:20:00 -
[33]
Worth keeping in mind that your system is as secure as a 50p Mars bar. That's the going rate to get your average commuter to cough up their username/password (at least 49% if I remember the story).
----- Four paws... four sets of claws. |
|

CCP Wrangler

|
Posted - 2007.11.29 12:22:00 -
[34]
If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.11.29 13:40:00 -
[35]
Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

Jupiter Sun
|
Posted - 2007.11.29 17:17:00 -
[36]
Originally by: Purlon You know it might be time for online game companies to start offering extra layers of security themselves.
A simple floating keypad would almost eliminate keyloggers, might be a pain to use but at least you would be using your mouse to type in your password. Many banks are rolling this stuff out now.
What about one time passwords? Could CCP send a one time password via sms or some other out of band authentication? Hmmmm
Customers (in my field of work) are now starting to understand the value of their identity and how easily it can be stolen and on sold (to hackers or whoever) from the internet channel. And now they are demanding extra layers of security to keep using products (like internet banking for example).
Also, a floating keyboard would eliminate macro's that login to eve online automatically as the keyboard would be in a differnet position everytime.
Anyways, my 2 cents.
runescape offers this.
yes, runescape, that much derided mmo.
|

Xaroth Brook
Minmatar BIG Ka-Tet
|
Posted - 2007.12.01 02:26:00 -
[37]
95% of staying virus-free comes from your own grey cells.. in the now 5 years i've had this rig setup i've not have a single virus -_-
some tips:
never, EVER, install stuff from the internet unless you're ABSOLUTELY sure it's a valid program. ALWAYS check the site you're actually browsing on, this goes for internet banking as well.. your local bank is rich enough to make sure you're on the www.yourbankname .com domain name, so if you're on some dodgy ip, it's NOT YOUR BANK. never give out more personal information than needed.. remember your mother telling you not to talk to strangers? well, the internet is full of em, so a random person in a random system is NOT a good person to give your email address to (nor your account password, for that matter) use STRONG passwords for all your accounts ( http://en.wikipedia.org/wiki/Strong_password#strong_passwords ).. stuff like 't3wahSetyeT4' might take 50 times longer to memorize, but it sure beats 'password' as a password (and yes i ripped that password from wikipedia...) as pointed out before, limited user accounts are less prone to crude backdoor bandit hacks, and for the common user they will save a lot of hassle (especially since you have to relog to install an app, giving you enough time to re-think the validity of said app)
if you value your performance, don't use stuff like norton or mcaffee (no offence), they are bloated and decrease your system performance by a LOT.. free ('open source' and alike) antivirus scanners perform just as well and generally don't mess your pc up that much after uninstalling.
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Xaroth Brook -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Look ma, my sig is too good to be highjacked by the mods |
|

CCP Wrangler

|
Posted - 2007.12.03 11:21:00 -
[38]
Originally by: ry ry Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?
Create a petition. 
And I'm gonna create one to report you!!!  
Wrangler Community Manager CCP Games, EVE Online Email / Netfang
"The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it." |
|

Pitt Bull
Caldari
|
Posted - 2007.12.03 15:23:00 -
[39]
Originally by: Nisd A good way to defende windows on is installing a anti-malware/spyware, Like Comodo Firewall Pro i got this feacture that is call IDefence, it monitors for hook's and dll injections. And it is just a good firewall.......
Agreed.
|

Lucas Avignon
|
Posted - 2007.12.03 16:16:00 -
[40]
I'd just like to ask about key loggers, isn't it the case if you don't open attachments then a key logger can't get on your puter. Also don't web clients like hotmail and yahoo scan attachments for viruses/keyloggers if you do decide to download it. Also is in only if you open the attachment not download it that a key logger can get installed.
Thanks in advance for this info.
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.12.03 16:45:00 -
[41]
Originally by: Lucas Avignon I'd just like to ask about key loggers, isn't it the case if you don't open attachments then a key logger can't get on your puter. Also don't web clients like hotmail and yahoo scan attachments for viruses/keyloggers if you do decide to download it. Also is in only if you open the attachment not download it that a key logger can get installed.
Thanks in advance for this info.
ideally, yeah. but if you're using an un-patched copy of.. say.. outlook express there are a few ways of forcing the app to execute code without opening the attachment.
although just never using outlook express is half the battle.
Please resize image to a maximum of 400 x 120, not exceeding 24000 bytes, ty. If you would like further details please mail [email protected] - Cortes |

Jolliejoe
Caldari
|
Posted - 2007.12.04 14:06:00 -
[42]
CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
|

Lisento Slaven
Amarr Capitalism Amuck
|
Posted - 2007.12.04 15:13:00 -
[43]
Does this mean I should petition everyone (that I can recall) I have given my private e-mail address to on EVE as a precaution? ---
Put in space whales!
|

RaTTuS
BIG Ka-Tet
|
Posted - 2007.12.04 15:31:00 -
[44]
Originally by: Jolliejoe CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
here we go again ,,, what friend ? and you cannot transfer accounts - only characters - -- BIG Lottery, BIG Deal, InEve [Now Verified] & Recruiting
|

Jolliejoe
Caldari
|
Posted - 2007.12.06 09:13:00 -
[45]
Originally by: RaTTuS
Originally by: Jolliejoe CCP Wrangler,
Why do you post this??? Since when is CCP serious about preventing ISK buying, account stealing and such? A friend om mine has waited for more than a month with a -5 bil debt on his account because you refused to correct the issue and punish the previous owner of his account.
If you are serious about all of this, why not actively monitor and moderate the timecode/bazar subforum and demand that people include the necessary information when selling a character?? There are rules for it as posted by CCP but nobody with CCP gives one **** about enforcing those rules other than punished innocent people.
There are a couple of very simple steps CCP can take to prevent a lot of problems but you don't..
Ludricous I find this..
here we go again ,,, what friend ? and you cannot transfer accounts - only characters -
I meant player dude and you seriously think I'm going to name him here in public... LOL... But hey, I expected to not get a responde from CCP while a CCP rep responded to a number of other replies here.
|

Xurx
Wreckless Abandon Triumvirate.
|
Posted - 2007.12.06 13:24:00 -
[46]
Originally by: ry ry Edited by: ry ry on 29/11/2007 13:40:20
Originally by: CCP Wrangler If someone asks for your email, please petition it in the harrassment category. This will help us find the people who are trying to steal your accounts!
cool, i'll email you. what's your email address?

|

Aramis Rosicrux
Gallente Canadia Security Institute PROBABLE CAUSE
|
Posted - 2007.12.06 17:50:00 -
[47]
Let's take a moment to actually educate the readers of this thread.
Security is a good thing. It protects you and your Eve charaacters.
Security means several things you have to do, not just one.
Guard your Infos Giving out personal details invites identity theft, a smart person will not give out personal details to strangers. Just because someone has been a buddy to you in the game does not mean they are your friend in real life. Real hackers use "social engineering" to rob you. The "social" part is they do things to gain your trust.
Guard your E-mail Opening an E-mail sometimes allows programs and scripts to be run on your computer automatically. Outlook Express, and other e-mail programs have functions that can be used to launnch programss. Picture files can have code embedded in them that can, under the right circumstances, run a script. Hackers can use programs and scripts to install nasty code on your computer.
Guard your Web Use Opening a web page means you let that web page give instructions to your web browser. Some web browsers can be tricked into following instructions to install nasty code. Also, multimedia content, including pictures, music and even videos can be altered so that they can install nasty code.
Now these attacks do not work every time. They may only work one time out of a hundred. But if you are that hundredeth user, you have the problem.
What is nasty code??? There are several varieties, and hackers have been cross-breeding them to make stronger versionss.
Virus- Code that replicates the instructions to install the virus into other programs. It makes a safe file become infected and then the infected file is now also spreading thwe virus.
Trojan Horse- A one-time program that drops a nasty onto your system. These can be from web sites, mails or even a program installed from a CD-ROM, diskette or a flash memory chip.
Keylogger- A program that gets between the stream of data coming from your keyboard that goes to the operating system, and usually records every key you press and writes it to a secret location. Periodically, the keylogger sends the data it collects to a secret location on the internet, where the hacker(s) can save a copy and study what you typed... this can be a password, your credit card number, or even your secret loveletters... if you type it, the logger gets a copy!
Rootkits- A program designed to install nasties and also includes a "backdoor" that allows the hacker(s) to remotely use your computer. Many thousands of computers have been converted into a veritable army of computers and used to attack other web sites (Denial of Service cloud attacks). Usually the hackers use them to send spam, but they can also read, write and delete your files. They can place data on your computer for safe keeping, access your microphone and even your video camera!
Malware- Semi-professiobnally written code installed as part of some "freebie" gimmick, like a free screen saver, a free program or (often) free p0rn players. The software "watches" your web surfing and alters web pages with the goal of selling you something. So you look at car ads, they put fake links to car sales on the page you are on.
Anyway, please, if you think you want to give away your e-mail address, go to a free e-mail service and create a single-use account for the purpose. Do not ever use the e-mail for any other purpose.
Even if you have a special e-mail account to use to send mail to your alliance mates, you still want to keep some details to your self. Last name, employer, street address, personal phone number, it is a good idea to not share these.
So, play smart, play safe, and assume everyone in the world is reading your e-mail, watching your web browsing and maybe even peeking in your room using your camera!
Just cuz' I am paranoid does not mean thar are NOT out to get me!
- Aramis Rosicrux
Humility is the hallmark of honorable character. Aramis Rosicrux
|

ry ry
StateCorp Veritas Immortalis
|
Posted - 2007.12.09 18:59:00 -
[48]
just a small point, but most malware is professionally wrote, rather than 'semi-professional', which suggests some kind of bedroom coders.
*again. |

DEFF DSP
|
Posted - 2007.12.10 11:43:00 -
[49]
now those guys are sending links in game to corp mates using already stolen accounts. file: First_Screensaver_Attempt.rar contains: Awsome Ships and Stations -- no name yet though.scr
did not work on my test pc, but worked on my friends pc who dont have an eve client :D
so theres key logger named klog AFAIK. its making directory C:\WINDOWS\system32\Ms32 with files klog.dat, win32.exe etc. its impossible to rename or delete it - only using some process killers.
that crap can't be detected by anti viruses /o\ i guess its making a connection to host (bad guy who made this thing) so firewall should block it but i'm not sure about that.
|

Loyal Servant
Caldari Viper Intel Squad Pure.
|
Posted - 2007.12.23 07:38:00 -
[50]
Some of you are killing me.
Don't give out your email address!
Is it really that friggin hard? It is not hysteria, you want your account stolen by a fracking isk farmer... so he can launder your isk and items?
DO WHAT THEY SAY and DO NOT GIVE OUT YOUR EMAIL ADDRESS.

|

Mother Inlaw
|
Posted - 2008.03.01 08:55:00 -
[51]
Edited by: Mother Inlaw on 01/03/2008 08:56:44 If you have a keylogger just send the email address of the person who sent it to your freindly mother inlaw and let her sort them out.
But seriously for a second - can anyone recommend some good software to check and remove these? IS it worth using specific programmes for this apart from the preffered antivirus / firewall packages bundles we all use?
I'm sure many of us have been in the position where we have previously given out the email address many times. Not me of course 
Capital Sales You're worth it! |

AndrewRyan
|
Posted - 2008.03.01 09:00:00 -
[52]
Grab the holy water and the stakes its alive! ========================================= A Man chooses, a slave obeys. |

Mother Inlaw
|
Posted - 2008.03.01 09:08:00 -
[53]
Edited by: Mother Inlaw on 01/03/2008 09:08:12
Originally by: AndrewRyan Grab the holy water and the stakes its alive!
/me waves to AndrewRyan
Capital Sales You're worth it! |

Drahcir Nasom
Independent Manufacturers
|
Posted - 2008.04.29 20:51:00 -
[54]
The account of one of our corp members has been hacked through the use of a keylogger today and we have lost about 40Bn worth of stuff from our corp hangars.
Drahcir
|
| |
|
| Pages: 1 [2] :: one page |
| First page | Previous page | Next page | Last page |