Showing Posts For Chris Cleary:

Scammed selling arah p2, buyer killed Brie

in Players Helping Players

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

If someone completes the dungeon while you are attempting to selling it, we are not going to take action against that person. If you invite them into your group or list the group via LFG, they are well within their right to finish the dungeon if you decide to leave the boss at 1%.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Selling dungeon paths, reportable?

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Closing this thread as it has gone well beyond the original point and has turned into a rather large misinformation campaign. The user mentioned later in this thread was not unbanned, but had their account termination changed to a temporary one due to leniency for first offense (as is the case for many users who are just now getting their first account action).

I honestly believe that after 2 years, it might be difficult for some players to understand what an exploit is and what isn’t. This is why leniency (in some cases) is just as valuable as a permanent block for the health of the game. Education of our user base is important, but repeat education is not something that we are going to put up with. Repeat offenders will be actioned heavily.

I’m not going to go into any more particulars for this specific case, the forums are not the proper place to get into this conversation. If you wish to discuss this further, feel free to open a ticket with Customer Support.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Breaking the ice (exploit)

in Guild Wars 2 Discussion

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

We are already working on a fix for this event chain. In the mean time, please report players that are being overly toxic (chat) during these events for “Verbal Abuse” as this is a violation of the User Agreement and Rules of Conduct.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Safespots and Exploits

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Avoiding mechanics by standing in a singular area isn’t an exploit, it’s possible bad dungeon design (for example the cage room in the newer flame and frost fractal…sorry I can’t remember the name of the dungeon it’s late). In that fight there are areas in which you can avoid almost the entire fight mechanic, that’s an example of poor dungeon mechanic design.

Standing on a rock/ledge/platform while the boss attempts to hit you from below (yes there are some bosses that still have abilities that hit you), is a problem with pathing and the boss not resetting when it can’t reach the target. This is exploiting a bug.

Kiting and using geometry (running AROUND pillars and such) is a perfectly valid tactic.

Standing outside a stationary boss’s range is not an exploit, the boss “should” reset after an extended period of time, but is not. This is an example of poor boss implementation, and not an exploit.

Using terrain to block/dodge boss mechanics is also considered a valid tactic (standing behind a pillar when a boss charges).

At this point we are getting very nitpicky at each individual boss and each mechanic in question. I’m sure most of you are aware of what is an exploit and what is a mechanic/tactic. We are working on fixing these “Safe Spots”, but it’s going to take some time to get it done, and will probably happen over time. (Sorry I am not going to go into particulars for fights/changes)

I’ll be very clear here:
If a GM finds a player that is using a “Safe Spot”, that player will be moved out of the safe spot and warned (via in-game text). If they are caught again, that account will be temporarily suspended.

If a GM finds a player that is using a “Safe Spot” and selling the dungeon run, that account will be temporarily suspended without warning.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Selling dungeon paths, reportable?

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

I’ll go ahead and play this game. The “screenshot” you’ve provided while “awesome”, doesn’t discount the fact that no one in this screenshot has been actioned. You are posting on the forums, which is a clear indication that you are not banned. None of the people in this party chat are banned. So while the “Legit” is being put into say (according to this screenshot), no action was taken against anyone here.

I know you wanted to post a screenshot of an account being banned, but you are posting a screenshot from the launcher back in 2012. We are on build 38057 not 15377.

My guess is that the GM was putting into question the validity of the tactic being used, but did not action as there was nothing against the rules.

I’ll go ahead and supply the screenshot that the GM took in context of this text. GM Stuffs and Character Name of person in question are blurred (sorry!)

Attachments:

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Safespots and Exploits

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

“Safe Spot” – Standing in a location to hold aggro or attack a monster/boss while it is unable to damage you (basic attack) and does not leash back to its original starting position.

This is an abuse of a geometry and/or pathing bug, and is considered an exploit.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Beware the dungeon police!

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

This thread is getting seriously off topic here and is delving into a much different topic. Closing it before it derails any further.

We have absolutely no problem if you solo a dungeon, or even if you like to explore. However when this becomes a tactic to complete content quicker, or tarnishing other’s play experience by doing so (by “selling” exploited runs), then we have a problem.

Edited for Clarification

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Beware the dungeon police!

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Ok, let me clarify

“Skips” generally require abuse of terrain to accomplish. An example of this would be “breaking out” of the map in order to bypass content. Doing such would be quantified as exploitation, using an exploit and profiting (“selling” runs) would be quantified as selling an exploit.

I am not talking about running past monsters, or using creative use of leashing/pathing.

Without going into punishment or policy, we are going to be ramping up on GM coverage in dungeons. If you believe that someone is exploiting, please do report them in-game.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Friend's account was hacked?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Your friend’s account has been blocked due to an account dispute (multiple contacts trying to get control of the account). Most of the times this happens when an account is purchased/sold or account information is seriously compromised. There won’t be anything “I” can do to help your friend, they will need to go through the Customer Support ticket process to get this resolved.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Beware the dungeon police!

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Yes, I meant report the players exploting the dungeons (in-game report is fine, not a bug report).

:) Sorry for confusion!

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Beware the dungeon police!

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

If you report them, we will come.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Friend's account was hacked?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Login status is dictated by launcher login state or game launch status. The reason that you are able to see your friend online is because they have sucessfully logged in via the launcher. That being said, the login process will keep your friend logged in while the launcher session is in an active “logged in” state. The state that you are seeing is when the user logs into an account via the launcher and remains on the post-login suspended/banned prompt.

This is a limbo state, and is reflected by the friend’s list not displaying a location for your friend.

As far as your friend being suspended, we can’t look into it unless you provide a ticket # or an account name.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

About that blix exploit....

in Guild Wars 2 Discussion

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

There are really two sides to this, and when it comes down to it, you are both right – and you are both wrong. Both sides have the right to complete the task that they set out to do (completing or not completing).

Challenging another player’s play style is the issue here, and since this revolved around an event that was designed to be completed, it is being changed so that the original design of the event can be carried out.

When something in the game (such as this event) changes negatively as this has, we need to step in and remediate the toxicity. The byproduct of this change happens to be that a champion farm is being slowed, but since that was the originating factor for the toxicity, it’s unavoidable.

I encourage players to remember that not everyone has the same goals when they play, and sometimes they will clash.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

About that blix exploit....

in Guild Wars 2 Discussion

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

A fix is currently being prepared for this issue.

While the behavior (design) of this event was acceptable in the past, changes in the game over time have created an environment around this event that has become increasingly toxic (for the community) due to unintended use/change of mechanics.

Players should not feel that they are in the wrong for completing an event (or event chain), and that is what is happening with this event. The respawn timer for this event will be significantly increased.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Banned for keyboard Macros?!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

This forum is not a place for appealing a ban, but since you went into so much detail on why you think you got banned, I’ll go into the same level of detail on why you actually got banned.

Your account was terminated due to use of a 3rd Party Botting program. In regards to your reference to Cursed Shore, that is where you were reported (thanks players that reported you) and investigated. After watching your character, our GM team was able to determine that you were running a bot.

To extend further on that investigation, I looked into the logs and it looks like you were leaving your bot on for a couple of hours then playing the game later.

I also find it very interesting that a user by the name of kitten Cracked also has a post on a known botting forum where that user goes into depth about botting in Cursed Shore and is attempting to help others do the same.

Closing this thread. Please open a ticket with Customer Service if you wish to appeal.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

cant login into the game

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

I have started password reset flows for both of you. Please reset your password. You should be able to get into the game after doing so.

If anyone else is having this problem with brand new accounts, please reply here so I can look into the issue.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

cant login into the game

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

I’m looking into this issue now.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Using Autoclicker

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Locking this thread as this is not to have a debate about a queue system and the original question has been answered.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Email talkin about Combat tips-is it real or?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

We have halted the sending of this email, but some users will still be getting them due to them being already queued in the batch send system. We intend on solving the issue before sending out any more emails of this nature to players.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Using Autoclicker

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

I fully understand what you are trying to accomplish here, a simple macro that will attempt to swap to a party member’s megaserver map that is full. Our stance is very clear on using any third-party program to automate game tasks (which has been gracefully copy/pasted above).

What you should know is that even if you decided you want to do this and spam join a megaserver map, it will not help you. Recently we implemented a system that will throttle and prevent a player from sending too many “join map” requests in short sucession. While this is not a solution to help players join full maps, it does somewhat even the playing field for multiple players attempting to join a full map.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Email talkin about Combat tips-is it real or?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Sorry about this! This got sent out on accident to a segment of our playerbase that it was not intended for. It was meant to be sent to players who are just now joining us in Guild Wars 2.

Reguarding email security, it is always good practice to be cautious about emails and links. If you aren’t sure about an email or link, you can always inspect the links that are embeded before clicking them.

That being said, there is nothing wrong on a refresher for base game mechanics!

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Did I get hacked?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Hey Ranos.3927,

Your account shows all the signs of being compromised. Please contact Customer Support and they can sort you out.

Here’s the link:
https://help.guildwars2.com/anonymous_requests/new

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

My friends need help!

in Account & Technical Support

Posted by: Chris Cleary

Chris Cleary

Game Security Lead

Next

Thank you for appealing for your “friend” that was responsible for Payment Fraud. Please do not attempt to appeal on these forums, we take Payment Fraud very seriously.

Closing this thread, your account, and your 384 other accounts.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Authenticator App

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Contact Customer Support if you wish to remove a mobile authenticator you no longer have access to.

Kim.4152 is correct, when you authorize a location, as long as you remain inside that IP range it will not prompt you to input your authenticator again.

Closing this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Hacked - Unable to Disconnect Hacker

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

As the original poster’s account was compromised due to their email also being compromised (and has now had their access restored), I am closing this thread.

If you believe your account is compromised, please contact Customer Support.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Acct banned for pinging to find network issue

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Your account was banned for botting in Cursed Shore, and has nothing to do with using a traceroute to diagnose your connection. Please use your Customer Service Ticket if you have any further questions.

Closing this thread. This forum is not a secondary place to appeal a ban.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Best Practices

Phishing – If an email links you to a site that asks you to type in your password, don’t type in your password. It could be a fake site. Go to the real account management site by typing “account.guildwars2.com”, or use a bookmark.

Social engineering – If someone claims to work for ArenaNet or NCsoft and asks you for your password, don’t tell them your password. Our customer support team doesn’t need your password.

Trojan horses and Spyware – Don’t download and run software, or open files attached to emails, from a source you aren’t 100% sure about. Malicious software can install a keylogger on your system to record your passwords and transmit them.

Email security – Keep the email address associated with your Guild Wars 2 account secure, just like you keep your Guild Wars 2 account itself secure. Use a strong, unique password there too, which you’ve never used anywhere else.

The Root Cause

Why do hackers work so hard to steal accounts? Because they make money from it.

Real-money trading companies want to sell you gold for cash. To do that, they have to collect the gold, and they have to advertise it. They collect gold by looting it off stolen accounts, and by using stolen accounts for botting. They advertise it by using stolen accounts for spamming.

If people wouldn’t buy gold from these real-money trading companies, the cash incentive to steal accounts would disappear. We’d see almost no account hacking, account looting, organized botting, or spamming ads.

We used to think wistfully about that with the original Guild Wars, and posted challenges to our players to stop supporting the real-money trading companies. But we knew that it was ultimately a lost cause. You can’t stop people from buying something they want to buy.

So with Guild Wars 2, we legitimatized buying gold, but did it in a way that puts the power in the hands of the players, not in the hands of the real-money trading companies. Players who want to buy gold can now do it in the game, in an open market with other players, trading gold for gems, which the receiving players can use to buy any microtransactions they want but can’t convert back to cash. As long as players purchase their gold this way, there isn’t a flow of cash back to the real-money trading companies, and thus there isn’t a profit incentive to hack accounts.

So the roots of our protection go deep into the design of Guild Wars 2, and we’ll leverage that design to keep Guild Wars 2 a safer environment than traditional MMOs.

But nothing is black-or-white. No matter how much we remove profit incentive, the fact remains that Guild Wars 2 is a popular game, and any popular game will attract hackers. So we keep security at the forefront of everything we do. We introduce new features, such as email authentication, two-factor authentication, and password blacklisting, to help keep accounts secure. We maintain an open dialog with our players about what the real threats are, so that players know how to protect themselves. And we have a team of GMs standing by to help those who do get hacked.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Database Breaches

We’ve seen some players theorize that hacked accounts were due to a Guild Wars database breach. We have very strict blocks in place to keep network attacks from reaching our customer databases, and a team constantly monitoring for any signs of intrusion, and we’re confident that there has been no such breach.

We take security very seriously. Perhaps you can tell from this blog post. And of all the things we protect at ArenaNet, we protect our customers’ data most of all.

Companies like Blizzard and Valve presumably also had a commitment to security, yet they ultimately suffered breaches of their account databases. One day will we become such a target that a hack attempt will finally overwhelm our defenses?

If that ever were to happen, we’d be up-front with you about it, and we’d take immediate steps to ensure that it didn’t lead to widespread account hacking. And here’s something else to think about. Because we’re requiring all Guild Wars 2 players to use unique passwords for Guild Wars 2, there’s actually nothing a hacker can steal from Guild Wars 2 to help attack other games or web sites. Using unique passwords benefits you both ways. In general, making a commitment to use a unique password for each account you care about is the best way to protect yourself, not only from being hacked today, but also from being hacked as the result of any future security breach of any company you deal with.

Commerce Security

We’ve seen a very few cases where hackers purchased gems on accounts after hacking them. This is an uncommon type of attack because we do have in-game restrictions in place to prevent wealth from being transferred off an account in a case like this.

We’ve deployed new restrictions to prevent hackers from using stored credit cards on stolen accounts in this way, and we also now provide users the option to delete stored credit cards.

Of course, if any customer finds that a hacker has created unauthorized charges against his credit card, that player can contact our support team to get the charges refunded.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Password Blacklisting

Since we’ve been observing hackers constantly scanning accounts that don’t even exist yet, waiting for someone to create those accounts, we obviously want to make sure that if those new customers do join the game, they don’t use the password that the hackers are waiting for. Thus we’re building a blacklist of all the passwords that hackers are scanning for — it’s already at 20 million passwords and growing — and we’re preventing new customers from choosing any of those passwords. (The blacklist contains passwords only, not account names.)

This system has substantially eliminated hackers’ ability to steal new accounts, as all new accounts now cannot possibly match what the hackers have been scanning for. The rate of account hacking was about 1.5% for accounts created before this blacklist was in place, and is about 0.1% for accounts created after.

Because this has been so successful at protecting new accounts, we want to extend it to protect existing accounts too. But it’s harder for us to know whether passwords of existing accounts are known to hackers: it’s difficult to distinguish between a login attempt by the real customer and a login attempt by a hacker.

When you change your password, the system won’t allow you to pick your previous password, or any password that we’ve seen tested against any existing or non-existent account. Thus, after changing your password, you’ll be confident that your new password is unique within Guild Wars 2. (However, your password only stays unique if you then don’t use it for other games and web sites, so please don’t!)

By the way, if you have trouble thinking of a new unique password, now that millions of possible passwords are blacklisted, we advise you to build a password out of four random words, as shown in this comic strip . Use a password like “correct horse battery staple”. As the comic strip calculates, even if everyone selects their words from the same 2,000 most common words, that’s still 16 trillion possible passwords.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Two-Factor Authentication

With email authentication in place, you can further protect your account by setting up two-factor authentication on your email account. Which, honestly, is a good idea anyway. Using email authentication this way protects your account in a very similar way to typical game implementations of two-factor authentication: the game will challenge any login attempt from a new location in a way that you’ll have to use two-factor authentication to approve.

We know customers also want a native implementation of two-factor authentication, and we want it too. This is an area where we should act faster as a company, and we’re going to. We had our own homegrown implementation of smartphone two-factor authenticator in testing, but we’re going to pull it back and instead integrate Guild Wars 2 with Google Authenticator, which already has robust authenticator implementations on most major smartphone platforms. This feature is already rolled out and ready to be used.

You can find all these options under My Account > Security or by visiting https://account.guildwars2.com/account/security

Two-factor authentication is a great tool for security-conscious customers to protect their accounts. But we know it will take time to get a significant portion of our customer base to adopt two-factor authentication, and in the meantime people are getting hacked every day by creating accounts with account names and passwords that hackers already know. So we need a solution that can protect everyone, not just the most security-conscious, and do it quickly. Thus we’ve rolling out our next initiative, password blacklisting.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Email Authentication

We have a feature in place, email authentication, that’s designed to help keep your account secure even if a hacker does know your account name and password.

Here’s how it works. When you first login, we ask you to validate your email address. After that, whenever you attempt to login from a new location, we send email asking you to approve or deny the login attempt.

So keep in mind, if you ever see an unexpected email asking you to validate a login attempt from a location where you’re not playing from, that means a hacker already knows your account name and password! The only thing that’s keeping him from logging in as you is the email authentication system! Change your password immediately.

Unfortunately, even with this system in place, people still get their accounts hacked. Here’s how:

First, about a third of players haven’t verified their email address yet. We can’t require email authentication for players with unverified email addresses.

Second, in many cases hackers have stolen credentials for the player’s email account too, and thus can access the authentication email message and approve their own login attempt. In particular this happens because people use the same password for their email account as they do for their Guild Wars 2 account and other accounts.

So, to be protected, be sure to verify your email address, and be sure to use a different password for your email account than you use for your game account.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account Security - What you need to know!

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

How Hackers Steal Accounts

Most of the security advice we’ve all seen through the years has focused on how to choose a strong password. You might therefore think that the primary way hackers break into accounts is by preying on accounts with weak passwords, perhaps scanning every word in the dictionary looking for matches. That’s rarely the case.

The basic truth is this: hackers steal game accounts because they already know the account name and password. They know them because they stole them (via security breaches or spyware) from another game or site where the person used the same account name and password.

So unfortunately, if the lesson you’ve learned from security advice through the years is to pick a single complicated password, memorize it, and then use it everywhere, that’s exactly the wrong lesson for today’s security environment. To keep accounts on different sites secure in today’s environment, you need to use a unique password for each account.

We have some ability at ArenaNet to watch hacking attempts live, and it tells a fascinating story. We watch as hackers use tens of thousands of different IP addresses to scan through millions of attempted account names and passwords, almost all of which are for accounts that don’t even exist in our database, looking for matches. They’re not guessing or brute-forcing passwords; they’re trying a very specific account name and password for each attempt. For example, account name “joe.user@example.com”, password “alligator101?. If they don’t get a match immediately, they may try a variant like “alligator100? or “alligator102?, then they quickly move on to the next entry on their list. And it’s interesting to see that the passwords on these lists are mostly quite good passwords. For every one account on the hackers’ lists with a password like “twilight” (real example, ?_?), there are dozens of accounts with good strong passwords. So the world at large clearly knows how to pick good passwords; the reason people are still getting hacked is because they use the same passwords on multiple sites.

The security environment has certainly changed. We didn’t see hackers testing these vast lists of stolen account names and passwords when we launched the first Guild Wars. But in recent years, a truly staggering number of game companies and web sites have had their account databases breached. These reports of security breaches — 77 million accounts, 25 million accounts, 24 million accounts, untold millions more — may seem abstract, too big to be real, but they’re obviously not. The information stolen from database breaches is worth a lot of money to hackers, who can take the stolen account credentials and use them to attack each new game that’s released.

So if it ever seemed safe to memorize one strong password and then use it for multiple accounts, it certainly isn’t safe anymore. Today it’s critically important to use a unique password for each account you care about and want to keep.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Heart Bleed bug

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

All our first-party HTTPs sites (including the commerce panel) are behind IIS, which doesn’t suffer from heartbleed. Our third-party hosted HTTPs sites (buy.guildwars2.com, in-game purchasing flow, and CDNs) were not vulnerable when I checked Tuesday morning.

The CDNs at least were vulnerable before that but no user-specific data ever flows through those so it shouldn’t have been an issue.

Just to be sure we’ll be issuing new certs for all our secure domains in the near future, but we’re pretty confident that there were no issues for our sites.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Actions against gold selling pages?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

This is not an account issue. Please use the report or block function in game to report this type of activity. Closing this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

PVPBANK

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

This is not an account issue. Please use the report function in game to report this type of activity. Closing this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

selling

in Fractals, Dungeons & Raids

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Locking this thread as it has devolved significantly.

Please refer to my original post on this topic//
https://forum-en.gw2archive.eu/forum/game/dungeons/Banned-for-selling-dungeon-paths/page/2#post3606021

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Black Lion Trading Post Issues - 2/2

in Black Lion Trading Co

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

The Black Lion Trading post is currently experiencing issues that are causing delays in loading, posting, and delivering of items/gold. We are currently investigating these issues and hope to have them resolved shortly.

Update: We have placed the Black Lion Trading Post into Maintenance mode while we resolve the issues.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Account locked, cannot recover

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Edited the main post due to personal content. Please do not create threads for users and include personal info. Locking this thread as there is already another post.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Account banned for name ??

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Account has been unblocked as the system did not unblock your account after censoring your bad character name. My apologies.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Skyhammer Gloryfarmers

in PvP

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

The abuse of Custom Arenas and the Skyhammer map in particular has been fixed.

We do not comment about account actions taken against players that violate our Rules of Conduct. If you feel that a particular player(s) is in violation of the Rules of Conduct, or would like to report an exploit, please send an email to exploits@arena.net with your report.

Locking this thread. Any additional threads with this same request may be closed.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Reporting names

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Your name was changed because it closely resembles that of a religious figure. While I agree that sometimes there are names that do not intend to be offensive, if they are borderline, GMs are forced to to make a judgement call. Given the name of your past characters, and the number of infractions for their character names, the GM made the correct decision to change your character name.

If you would like to appeal your character rename, please contact Customer Support by opening a support ticket.

Locking this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

ARENA: double standards on names

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

You have 17 different Bad Names infractions and continue to use variations and special characters of those names, I would highly suggest you stop. Usage of Guild Wars characters is not allowed in character names.

Locking this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Unaceptable name?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Locking this as it has more than served its purpose.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Account suspended?

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

I have corrected your suspension to be for the proper amount of time.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Lunatic Inquisition and Idleness

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Looking into this now

Update: Your account has been reinstated, I apologize for the inconvenience.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

(edited by Chris Cleary.8017)

Hacked / Account help.

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Your account was blocked yesterday due to the usage of bad language and will remain blocked until your suspension is served. Opening Customer Support tickets will not help you in this matter as your account was not compromised during this period. Locking this thread.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Friend keeps getting hacked

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

Unless I know your friend’s display name, I am unable to help with any account security questions he may have. As for the login from Texas, that is a known issue.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Account suspended

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

You were blocked for something saying something much more profane than you imply in your OP. If you truly feel that this was an error, please file a Customer Support Ticket.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Account suspend

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

You were blocked for something saying something much more profane than you imply in your OP. If you feel that this was an error, please file a Customer Support Ticket.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”

Constant attempts to hack

in Account & Technical Support

Posted by: Chris Cleary

Previous

Chris Cleary

Game Security Lead

Next

When you log into the forums it will display a login from Texas occasionally due to the connection that needs to be made to tie the forums and the login servers. This is not a bug, and not an account hijack attempt.

Professor of Bearbow Math @ Tyria State // @Shazbawt // “The Crippler”