Guild Wars 2 Accounts Hacked Immediately After Launch

Me and my sidekick Weenie.
Latest Videos FromTom's Hardware
TOPICS
Kevin Parrish
Contributor

Kevin Parrish has over a decade of experience as a writer, editor, and product tester. His work focused on computer hardware, networking equipment, smartphones, tablets, gaming consoles, and other internet-connected devices. His work has appeared in Tom's Hardware, Tom's Guide, Maximum PC, Digital Trends, Android Authority, How-To Geek, Lifewire, and others.

  • schnitter
    Well, when tons of hacking attempts occur that means the product is worth their time... so I guess Guild Wars 2 is off to a great start.
    Reply
  • memadmax
    There's an easy way to stop list bruteforce tactics: 30 minute timeout with an email enforced password change after 3 failed login attempts... also, forced password change after first time login, with previous passwords cached for non-use later(if the user attempts to use a previous password again, it fails)...

    These password tactics are very, very, very easy to implement... few lines of code in most cases....
    Reply
  • Kami3k
    Uh, how do fansites can someone's main account info...

    Oh right, ID10T errors.
    Reply
  • samwelaye
    these are ALL user errors. If the fansite gets hacked, and you use the SAME email and password for that and your gw2 account, that isnt gw2 accounts being hacked. That is you being stupid.
    Reply
  • samwelaye
    also, passwords like h324o3!@ arent secure. they are short and easy to brute force. passwords like toastersdonttoastsoggybread are VERY secure, as it is extremely hard for a computer to brute-force through something that long, and they are also VERY easy to remember! if anything, add a . or a , between each word if that makes you feel any better. just dont use an 8 letter password no matter how complex you think it is.
    Reply
  • master_chen
    Hmmmm...I wonder if Angry Joe's account would get hacked? Probably not...
    Reply
  • cmcghee358
    samwelayealso, passwords like h324o3!@ arent secure. they are short and easy to brute force. passwords like toastersdonttoastsoggybread are VERY secure, as it is extremely hard for a computer to brute-force through something that long, and they are also VERY easy to remember! if anything, add a . or a , between each word if that makes you feel any better. just dont use an 8 letter password no matter how complex you think it is.
    I just tried to log into tomshardware.com with your username and the password of toastersdonttoastsoggybread

    Was worth a try
    Reply
  • Kami3k
    master_chenHmmmm...I wonder if Angry Joe's account would get hacked? Probably not...
    Hahaha. He does use Angry Joe for everything.
    Reply
  • esrever
    My account was hacked, took 5 days to get it back with all my items gone. It was not phishing since I just got the game and I did not visit any guild wars 2 fan sites. Although my password would have been easy to bruteforce, the hacker bypassed email conformation somehow. The fact that that was the case made me think arenanet is to blame. I did not have the same password for my email as for my guildwars 2 account. The emails conformations were also unread, just 2 emails saying request password change and the last one, request email change. Someone would have to have fooled the authentication process.

    I don't know how they handle things but I hope they tighten up security... I also made my account password over 12 chars just to be more secure but if companies can't secure their end, it makes everything I do pointless.
    Reply
  • wildkitten
    While I agree with these being user errors such as using the same email and passwords on fan sites, as well as going to gold selling sites (and yes, the spam is already rampant in chat and the game mail system), one of the few things Anet has not done properly was not having authenticators ready for launch.

    Everyone knew GW2 would be popular, and authenticators have been being asked for for well over a year and the devs have talked about adding them in. They should have been there for launch.
    Reply