Gaiscioch Select Chapter
POPULAR ADVENTURES:



ACTIVE ADVENTURES:





ADVENTURES:
Palia
Caliber
Pirate101
Chrono Odyssey
Havenhold
Once Human
Camelot Unchained
ArcheAge Chronicles
Warborne Above Ashes
Deep Rock Galactic
Genshin Impact
- Full List -
CHAPTERS:
Chapter 8:
Conqueror's Blade (2019)
Chapter 7:
New World (2021)
Chapter 6:
World of Warcraft: Classic (2019)
Chapter 5:
Elder Scrolls Online (2014)
Chapter 4:
Guild Wars 2 (2012)
Chapter 3:
RIFT (2011)
Chapter 2:
Warhammer Online (2008)
Chapter 1:
Dark Age of Camelot (2001)
Community
Events
CHARITY:

LEGACY EVENTS:


Search Gaiscioch.com:
138 Tuatha Guilds:
9,308 Members:
13,933 Characters:
11,709 Items:
  • Views: 1,337
  • Replies: 11

Player identifies "huge security hole" in RIFT's authentication system, Trion seals it

Fine de na Sailetheach
Morreion
Fine de na Sailetheach
Posted On: 03/19/2011 at 01:40 PM
Awards & Achievements
Devotion Rank 20Scholar Rank 1

Response:

Seaimpin de na Capall Buí
Bach2099
Seaimpin de na Capall Buí
Replied On: 03/19/2011 at 02:08 PM PDT
  • Twitter

Cool article. Here's hoping that's the only major problem with this game. That would be sweet.

Awards & Achievements
Devotion Rank 20Valor Rank 9Fellowship Rank 12Explorer Rank 2Scholar Rank 2Artisan Rank 5
Curadh de na Ulchabhan
Bashir
Curadh de na Ulchabhan
Replied On: 03/19/2011 at 05:51 PM PDT

great. now restore my character so I can play again. I haven't been able to play my main for about a week now.

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Explorer Rank 3Scholar Rank 5Artisan Rank 3
Curadh de na Ulchabhan
Bashir
Curadh de na Ulchabhan
Replied On: 03/19/2011 at 05:54 PM PDT

oh and I want to know what he found and how he did it. I hate being so ignorant of network security. One of these days I am going to have to find out more about it.

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Explorer Rank 3Scholar Rank 5Artisan Rank 3
Fine de na Sailetheach
Morreion
Fine de na Sailetheach
Replied On: 03/19/2011 at 07:18 PM PDT
Awards & Achievements
Devotion Rank 20Scholar Rank 1
Seaimpin de na Aracos
Gordon
Seaimpin de na Aracos
Replied On: 03/20/2011 at 08:16 AM PDT
  • Twitch

In a nutshell, Bashir (though I don't know the nitty-gritty details), this is how I understand it: once you provide good credentials at login, the game gives you a "token" to say you're an ok guy. Think browser cookies, or better yet, you visit some high security place and they give you a badge you have to wear so the security guys can see it or they'll kick you out. From there on out, each transaction with the server has to reference that token in order to "prove" you have a right to be there. What this guy found is that if you have a pre-validated token (i.e., you log in as yourself), you could then just replace the account ID (a unique number assigned by Trion to your account) in that token with that of someone else,and not have to re-validate to "become" that person. No one accessed particulars of any Trion database (as far as anyone can tell), so it's thought that the hackers were just trying random account IDs, hit or miss, until they found one that worked.

Awards & Achievements
Devotion Rank 20Fellowship Rank 11Scholar Rank 3Social Rank 1
Curadh de na Ulchabhan
Bashir
Curadh de na Ulchabhan
Replied On: 03/20/2011 at 02:38 PM PDT

Got it. I have a bit of an understanding of tokens from a basic understanding of VPN connections so that makes sense.

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Explorer Rank 3Scholar Rank 5Artisan Rank 3
Saighdiuir de na Capall
Mac1
Saighdiuir de na Capall
Replied On: 03/21/2011 at 02:32 AM PDT

BTW folks, the fact that this hole was found and fixed does NOT mean that there aren't other issues with security. It is still up to you to take normal precautions for your own security. For example NEVER use the same email address for two games. People have been selling WoW email addresses for years, if you use the same email address for Rift, you may well already be on some hackers list. Unique email address and strong passwords (also unique) go a long way to keeping you safe.

Awards & Achievements
Devotion Rank 20Fellowship Rank 10Scholar Rank 4
Curadh de na Ulchabhan
Bashir
Curadh de na Ulchabhan
Replied On: 03/21/2011 at 05:21 AM PDT

I gave in a few days ago and created an email just for rift. Still think they are making a mistake using email addy as account names.

Awards & Achievements
Devotion Rank 20Fellowship Rank 9Explorer Rank 3Scholar Rank 5Artisan Rank 3
Seaimpin de na Fhiaigh Buí
MikeyDee
Seaimpin de na Fhiaigh Buí
  • GW2: MikeyDee.2708
Replied On: 03/21/2011 at 10:50 AM PDT
  • Twitch

The ZAM interview was great to read. Granted Coin-Locked now every day cause I play from home and work. But I can deal with it if it makes it more secure game overall.

Awards & Achievements
Devotion Rank 20Valor Rank 9Fellowship Rank 11Explorer Rank 3Scholar Rank 3Artisan Rank 10
[0.444]