We have detected that cookies are not enabled on your browser. Please enable cookies to ensure the proper experience.
Results 1 to 13 of 13
  1. #1
    Join Date
    Apr 2007
    Posts
    4,799

    How can you be so cavalier with my password?

    it used to be that the only way for someone to get my LotRO password was with an active keylogger running on my system. Now anything that can hack my browser can pick up my game password. If I go to the public library and log into the forums while I'm there, well, those computers all are basically the "same" computer -- it's the same problem that Gmail had when it first launched -- passwords are recoverable from one of the other library computers while I'm logged in.

    Turbine, I know you want to "autolog" people into the forums when they browse them from the game, but how can you be so cavalier with my password? Haven't you been telling us for years that we shouldn't, ever, use the same password for the game and the forums? And now, without any warning or discussion, you just changed all of our forum passwords to our game password?

    I thought you were better than this.
    As a level 1 burglar, Bilbo got a pony when he joined the Smaug The Dragon raid. Then he asked for leadership, looted the chest, assigned himself the 1st age Arkenstone and mailed it to an alt (Bilbo's a VIP so can mail from anywhere). They did some PvMP and an Epic Battle, then he apologized and gave the Arkenstone back because it wasn't BoA. He kept the pony.

  2. #2
    Join Date
    Mar 2010
    Posts
    430

    Re: How can you be so cavalier with my password?

    I completely agree, this is a very un-secure situation. There is absolutely no reason we should be using our game logins on this website or any website for that matter.

  3. #3
    Join Date
    May 2007
    Posts
    1,578

    Re: How can you be so cavalier with my password?

    Agreed, it is worrisome.
    Level 65 Hunter // Level 65 Warden // Level 65 Captain // Level 65 Lore Master // Level 65 Champion
    Level 65 Minstrel // Level 65 Burglar // Level 65 Rune Keeper // Level 50 Guardian
    Ongbúrz Tracker says, "Stop hittin' me, you slug!"

  4. #4
    Join Date
    Mar 2007
    Posts
    368

    Re: How can you be so cavalier with my password?

    Whatever do you mean? It's totally secure.



    What a joke.

  5. #5
    Join Date
    May 2007
    Posts
    871

    Angry Re: How can you be so cavalier with my password?

    Epic fail Turbine once again you show you do not care at all about our security. Game log in information same as account page log in information, then account information in-game with no password, and now this. Whats next?

  6. #6
    Join Date
    Jul 2006
    Posts
    1,240

    Re: How can you be so cavalier with my password?

    In spite of some errors, the logins are secure. They use SSL for your login, which is the same system that banks and online retailers use when they take credit card information. Or for something more relevant to this discussion, it the same system we use on the myaccount page that we all created our game accounts on.

    We would not be implementing a system like this if we were not confident about the security of our users.

  7. #7
    Join Date
    Feb 2008
    Posts
    1,388

    Re: How can you be so cavalier with my password?

    Quote Originally Posted by Frelorn View Post
    We would not be implementing a system like this if we were not confident about the security of our users.
    That's a keeper.

    /only partially kidding

  8. #8
    Patience's Avatar
    Patience is offline Senior Community Manager, Turbine, Inc.
    Join Date
    Jan 2005
    Posts
    2,948

    Re: How can you be so cavalier with my password?

    Just to add, the error message that's popping up is actually in error itself, and will be fixed in the near future!
    [B][COLOR=DarkOrchid]“Behold the Chinchillas! They ride to war!”[/COLOR][/B]

  9. #9
    Join Date
    Mar 2007
    Posts
    368

    Re: How can you be so cavalier with my password?

    Quote Originally Posted by Frelorn View Post
    In spite of some errors, the logins are secure. They use SSL for your login, which is the same system that banks and online retailers use when they take credit card information. Or for something more relevant to this discussion, it the same system we use on the myaccount page that we all created our game accounts on.

    We would not be implementing a system like this if we were not confident about the security of our users.
    With all due respect:

    Funcom changed the system for Anarchy Online to separate logins/passwords for forums and accounts because hackers were getting the info from the forums though packet sniffers and other tricks. Hacked accounts in WoW actually went UP after the change to Battle.net, the same setup you have just implemented. Forums are not secure enough for this type of system, period. One easily seen point of reference - http://forums.lotro.com

    I appreciate your response, but I respectfully disagree with it.

    Edit: Also, this is something that should have been announced to the community long before implementation, not snuck in a post the day it's planned to be done.
    Last edited by Korandon; Sep 08 2010 at 08:21 PM.

  10. #10
    Join Date
    Jan 2007
    Posts
    1,558

    Re: How can you be so cavalier with my password?

    Quote Originally Posted by Frelorn View Post
    In spite of some errors, the logins are secure. They use SSL for your login, which is the same system that banks and online retailers use when they take credit card information. Or for something more relevant to this discussion, it the same system we use on the myaccount page that we all created our game accounts on.

    We would not be implementing a system like this if we were not confident about the security of our users.
    And why should we believe this when you used to tell us to NOT do the very thing you just implemented?!?!

  11. #11
    Join Date
    Apr 2007
    Posts
    1,041

    Re: How can you be so cavalier with my password?

    What has been posted is correct. Since the cert is invalid the browser is not loading the site securely. Everything is transmitting in the clear.

    When this is fixed please let people know by some public forum method, as I will not be using the forums until this is fixed.
    \\ Rawlor \\ Unpossible \\ Durglar \\
    ...::: Brandywine :::...

  12. #12
    Join Date
    Jan 2009
    Posts
    1,230

    Re: How can you be so cavalier with my password?

    Quote Originally Posted by Frelorn View Post
    In spite of some errors, the logins are secure. They use SSL for your login, which is the same system that banks and online retailers use when they take credit card information. Or for something more relevant to this discussion, it the same system we use on the myaccount page that we all created our game accounts on.

    We would not be implementing a system like this if we were not confident about the security of our users.
    I agree that the network transaction is secure, but your are assuming that the computer is secure. I would never dream of using a credit card on a public computer such as at school or library, I used to not worry about logging into the forums from such a place. A simple key-logger will now get access to my account, prior it could just get access to the forums.

    Please re-consider having a separate forum account/password. If I want to get to my account, I don't mind having to type my real id and password for those rare events.

  13. #13
    Join Date
    Sep 2009
    Posts
    2,962

    Re: How can you be so cavalier with my password?

    The SSL connection helps neither against keyloggers attached to web browsers nor against an attack on vBulletin, e.g. via a cross-site scripting attack targeting people's passwords.

    Really bad move, IMHO.

 

 

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

This form's session has expired. You need to reload the page.

Reload