<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Guild Wars 2 players filed over 8,500 account issue tickets in one weekend</title>
	<atom:link href="http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/feed/" rel="self" type="application/rss+xml" />
	<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/</link>
	<description>For all your latest Gaming News, Files, Servers &#38; Discussion - Powered by Internode</description>
	<lastBuildDate>Thu, 23 May 2013 12:38:16 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: hadokenx</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-6004</link>
		<dc:creator>hadokenx</dc:creator>
		<pubDate>Mon, 10 Sep 2012 07:49:11 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-6004</guid>
		<description><![CDATA[&lt;strong&gt;&lt;a href=&quot;#comment-5975&quot; rel=&quot;nofollow&quot;&gt;bronzed&lt;/a&gt;&lt;/strong&gt;, 

Ah yes... the reset mails come to the new email address, not the original. Apologies for not specifying...I always get really angry about this in every single thread on the subject that I&#039;ve read about or posted in, and I often get carried away, forgetting to mention details about the situation. If they were emails coming to the old email address, I&#039;d find that perfectly understandable, because the third party has that email address already....but the new address getting these emails is, to say the least, a bit discouraging, because that email has never been exposed.

I&#039;ve had to repeatedly respond to posts of people saying: 
&quot;You can see anyone&#039;s account in game, blah blah blah.&quot;; 
&quot;You must have a virus...&quot;; 
&quot;Your email is part of a list that some hacker cracker has and your emails are the same for everything and your passwords are the same for everything&quot;; 
...and any other run of the mill comment that anyone could possibly think of, on multiple occasions, because people don&#039;t actually read all of the posts - they simply see one post on the 53rd page of a forum and blast you with comments essentially calling you an idiot.

The kicker that nobody seems to understand, is how the hell could I possibly be getting password reset notifications that are in fact legitimate, for an account that DOES NOT EXIST? The fact that I&#039;m getting the emails on a previously unexposed email account is only the second part of the issue.

I&#039;m not worried about a GW2 account...I don&#039;t have one to lose. Do you see where I&#039;m coming from with this?

Now, the second part (previously unexposed email) DOES have GW1 attached to it. A fresh email account that had no other previous ties to the game BECAUSE the account had been stolen on a separate occasion. The only way someone could get the email is through database exposure. My last post describes a way that it could have happened....It may have, or may not have happened that way, but it is a distinct possibility, and people keep coming back and telling me it&#039;s my fault - it can&#039;t be my fault if I don&#039;t have the GW2 account in question....]]></description>
		<content:encoded><![CDATA[<p><strong><a href="#comment-5975" rel="nofollow">bronzed</a></strong>, </p>
<p>Ah yes&#8230; the reset mails come to the new email address, not the original. Apologies for not specifying&#8230;I always get really angry about this in every single thread on the subject that I&#8217;ve read about or posted in, and I often get carried away, forgetting to mention details about the situation. If they were emails coming to the old email address, I&#8217;d find that perfectly understandable, because the third party has that email address already&#8230;.but the new address getting these emails is, to say the least, a bit discouraging, because that email has never been exposed.</p>
<p>I&#8217;ve had to repeatedly respond to posts of people saying:<br />
&#8220;You can see anyone&#8217;s account in game, blah blah blah.&#8221;;<br />
&#8220;You must have a virus&#8230;&#8221;;<br />
&#8220;Your email is part of a list that some hacker cracker has and your emails are the same for everything and your passwords are the same for everything&#8221;;<br />
&#8230;and any other run of the mill comment that anyone could possibly think of, on multiple occasions, because people don&#8217;t actually read all of the posts &#8211; they simply see one post on the 53rd page of a forum and blast you with comments essentially calling you an idiot.</p>
<p>The kicker that nobody seems to understand, is how the hell could I possibly be getting password reset notifications that are in fact legitimate, for an account that DOES NOT EXIST? The fact that I&#8217;m getting the emails on a previously unexposed email account is only the second part of the issue.</p>
<p>I&#8217;m not worried about a GW2 account&#8230;I don&#8217;t have one to lose. Do you see where I&#8217;m coming from with this?</p>
<p>Now, the second part (previously unexposed email) DOES have GW1 attached to it. A fresh email account that had no other previous ties to the game BECAUSE the account had been stolen on a separate occasion. The only way someone could get the email is through database exposure. My last post describes a way that it could have happened&#8230;.It may have, or may not have happened that way, but it is a distinct possibility, and people keep coming back and telling me it&#8217;s my fault &#8211; it can&#8217;t be my fault if I don&#8217;t have the GW2 account in question&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bronzed</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5975</link>
		<dc:creator>bronzed</dc:creator>
		<pubDate>Mon, 10 Sep 2012 02:18:34 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5975</guid>
		<description><![CDATA[Wait, up until the part where the GW1 account email is changed to a new isolated one i still followed...

but to which address does this phishing emails came to? The new isolated address? or the old email address that were tied to the GW1 account when it was breached?

I assume that for relevance it has to be the new isolated address, but i am just double checking if we&#039;re on the same page here...]]></description>
		<content:encoded><![CDATA[<p>Wait, up until the part where the GW1 account email is changed to a new isolated one i still followed&#8230;</p>
<p>but to which address does this phishing emails came to? The new isolated address? or the old email address that were tied to the GW1 account when it was breached?</p>
<p>I assume that for relevance it has to be the new isolated address, but i am just double checking if we&#8217;re on the same page here&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bourneh</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5965</link>
		<dc:creator>bourneh</dc:creator>
		<pubDate>Sun, 09 Sep 2012 14:20:53 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5965</guid>
		<description><![CDATA[Hello, I own a Guildwars2 account which i played frequently without any problems until I went to the Hall of Monuments calculater to see what I was elligible to get to my Gw2 account, the next day I tried logging in to find that I couldn&#039;t access my account, I checked my email to notice that I had received an email saying the following, 


Someone -hopefully you!- has requested to change the email address associated with your Guild Wars account.
Need help or have questions about your Guild Wars account? Visit our support site: http://support.guildwars2.com/.
Thanks!
-The ArenaNet Team

Upon reporting this to the ANet support team no real answers were given to me just the good old FAQ link for all your solutions, so I haven&#039;t been able to play or access anything related to my GW2 account as well as my GW1 account. Of course I&#039;m still waiting for an actually helpful response. Yet they keep sending me password recovery links and stuff, completely disregarding me stating that the email attached to my account had been changed.  So Hadokenx I agree completely with you.]]></description>
		<content:encoded><![CDATA[<p>Hello, I own a Guildwars2 account which i played frequently without any problems until I went to the Hall of Monuments calculater to see what I was elligible to get to my Gw2 account, the next day I tried logging in to find that I couldn&#8217;t access my account, I checked my email to notice that I had received an email saying the following, </p>
<p>Someone -hopefully you!- has requested to change the email address associated with your Guild Wars account.<br />
Need help or have questions about your Guild Wars account? Visit our support site: <a href="http://support.guildwars2.com/" rel="nofollow">http://support.guildwars2.com/</a>.<br />
Thanks!<br />
-The ArenaNet Team</p>
<p>Upon reporting this to the ANet support team no real answers were given to me just the good old FAQ link for all your solutions, so I haven&#8217;t been able to play or access anything related to my GW2 account as well as my GW1 account. Of course I&#8217;m still waiting for an actually helpful response. Yet they keep sending me password recovery links and stuff, completely disregarding me stating that the email attached to my account had been changed.  So Hadokenx I agree completely with you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nekosan</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5961</link>
		<dc:creator>nekosan</dc:creator>
		<pubDate>Sun, 09 Sep 2012 11:52:47 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5961</guid>
		<description><![CDATA[I&#039;ve had multiple friends who are rather net savvy get suspended since launch, neither had any reasonable way that someone could have their details other than ArenaNet&#039;s security being breached. 

Neither had a Guild wars 1 account or anything else MMO related connected to that username or password, I&#039;m pretty damn sure that their servers were breached and they just aren&#039;t saying. Keep in mind that this happened to the first friend THE DAY AFTER LAUNCH, luckily that&#039;s when they freaked out about email authentication (what&#039;s the point if you can log in without authenticating?) and he got his account back within 12 hours, he was told it had been locked because of access attempts from Korea.

Second friend only purchased a week after launch, account got locked yesterday and tonight it lists his home server as one of the EU ones.


It really doesn&#039;t help that You can (or could) just skip the authentication page, or that it took THREE DAYS for their server to send me my email confirmation (and then the email was fucked and I couldn&#039;t click the link because it was half as long as it should have been).]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve had multiple friends who are rather net savvy get suspended since launch, neither had any reasonable way that someone could have their details other than ArenaNet&#8217;s security being breached. </p>
<p>Neither had a Guild wars 1 account or anything else MMO related connected to that username or password, I&#8217;m pretty damn sure that their servers were breached and they just aren&#8217;t saying. Keep in mind that this happened to the first friend THE DAY AFTER LAUNCH, luckily that&#8217;s when they freaked out about email authentication (what&#8217;s the point if you can log in without authenticating?) and he got his account back within 12 hours, he was told it had been locked because of access attempts from Korea.</p>
<p>Second friend only purchased a week after launch, account got locked yesterday and tonight it lists his home server as one of the EU ones.</p>
<p>It really doesn&#8217;t help that You can (or could) just skip the authentication page, or that it took THREE DAYS for their server to send me my email confirmation (and then the email was fucked and I couldn&#8217;t click the link because it was half as long as it should have been).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hadokenx</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5959</link>
		<dc:creator>hadokenx</dc:creator>
		<pubDate>Sun, 09 Sep 2012 11:37:23 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5959</guid>
		<description><![CDATA[Ok wanell, we’ll play it that way.
You’ve obviously investigated the situation for yourself, and apparently understand exactly how their system works. To get things started, let’s talk about how that Hall of Monuments calculator works.

For those unaware of what I’m talking about, with the announcement of GW2, an “incentives” event was staged, by which people could grind for titles within GW1. The more titles you gain, the more “inheritance” items you would receive in GW2. To help people out, ANet created a little app on the GW2 website that is able to tell you which of those inherited items you would get by simply putting in a character name.

Let me ask you this: How can an app, directly available on the website, be able to access the information saved for your character? Do they magically create this information by directly accessing your character? No, they do not…it connects to the actual game database, and for each character, there is an account, and for each account, there is an email address.

Now, on to your SQL injection point: If it USES SQL, yes, it’s vulnerable. But maybe it’s a different database that doesn’t use SQL? No. It’s not. Their website is a Wordpress website (check for yourself by looking at the source, and find wp-content and wp-admin lines in the code…that’s Wordpress), and Wordpress uses SQL based databases. For their website to have the ability to directly query the actual game database, it most likely uses SQL, and in turn is most likely vulnerable to SQL injection attacks.

And onto my next point…My email was changed due to my account having been stolen previously…it wasn’t third party crap like fan sites; it wasn’t a virus; it wasn’t social engineering; It was a flaw in the NCSoft website that allowed people to login and back out of their accounts in rapid succession, and those people would randomly end up logged into someone else’ account. I was one of the unfortunate ones that this happened to. So the argument of “it HAS to be your fault” doesn’t always apply. It’s the internet…everything is vulnerable.]]></description>
		<content:encoded><![CDATA[<p>Ok wanell, we’ll play it that way.<br />
You’ve obviously investigated the situation for yourself, and apparently understand exactly how their system works. To get things started, let’s talk about how that Hall of Monuments calculator works.</p>
<p>For those unaware of what I’m talking about, with the announcement of GW2, an “incentives” event was staged, by which people could grind for titles within GW1. The more titles you gain, the more “inheritance” items you would receive in GW2. To help people out, ANet created a little app on the GW2 website that is able to tell you which of those inherited items you would get by simply putting in a character name.</p>
<p>Let me ask you this: How can an app, directly available on the website, be able to access the information saved for your character? Do they magically create this information by directly accessing your character? No, they do not…it connects to the actual game database, and for each character, there is an account, and for each account, there is an email address.</p>
<p>Now, on to your SQL injection point: If it USES SQL, yes, it’s vulnerable. But maybe it’s a different database that doesn’t use SQL? No. It’s not. Their website is a WordPress website (check for yourself by looking at the source, and find wp-content and wp-admin lines in the code…that’s WordPress), and WordPress uses SQL based databases. For their website to have the ability to directly query the actual game database, it most likely uses SQL, and in turn is most likely vulnerable to SQL injection attacks.</p>
<p>And onto my next point…My email was changed due to my account having been stolen previously…it wasn’t third party crap like fan sites; it wasn’t a virus; it wasn’t social engineering; It was a flaw in the NCSoft website that allowed people to login and back out of their accounts in rapid succession, and those people would randomly end up logged into someone else’ account. I was one of the unfortunate ones that this happened to. So the argument of “it HAS to be your fault” doesn’t always apply. It’s the internet…everything is vulnerable.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: syncourt</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5957</link>
		<dc:creator>syncourt</dc:creator>
		<pubDate>Sun, 09 Sep 2012 09:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5957</guid>
		<description><![CDATA[&lt;strong&gt;&lt;a href=&quot;#comment-5935&quot; rel=&quot;nofollow&quot;&gt;flabcab&lt;/a&gt;&lt;/strong&gt;, 

Do you mean account? not email? Because if so I would suggest reporting that to customer support.

I&#039;ve read other people who had the same messages. It basically means they have your account details already, but just cannot get past the e-mail validation yet. Some users have reported that eventually the account was stolen after a buttload of attempts.]]></description>
		<content:encoded><![CDATA[<p><strong><a href="#comment-5935" rel="nofollow">flabcab</a></strong>, </p>
<p>Do you mean account? not email? Because if so I would suggest reporting that to customer support.</p>
<p>I&#8217;ve read other people who had the same messages. It basically means they have your account details already, but just cannot get past the e-mail validation yet. Some users have reported that eventually the account was stolen after a buttload of attempts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: trb</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5952</link>
		<dc:creator>trb</dc:creator>
		<pubDate>Sun, 09 Sep 2012 09:06:47 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5952</guid>
		<description><![CDATA[Do the people claiming end user fault realise there is no limit to log-in attempts on the account page?
This means that a bot can be used to attempt to log in with brute force type attacks until they get the right combination.
20,000 successes out of 1mil accounts doesn&#039;t seem too far fetched.
 there are a raft of other security flaws as well.]]></description>
		<content:encoded><![CDATA[<p>Do the people claiming end user fault realise there is no limit to log-in attempts on the account page?<br />
This means that a bot can be used to attempt to log in with brute force type attacks until they get the right combination.<br />
20,000 successes out of 1mil accounts doesn&#8217;t seem too far fetched.<br />
 there are a raft of other security flaws as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: syncourt</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5951</link>
		<dc:creator>syncourt</dc:creator>
		<pubDate>Sun, 09 Sep 2012 09:03:08 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5951</guid>
		<description><![CDATA[Whats worse is the account recovery page doesn&#039;t work either. I enter my associated username/e-mail, the serial key and a character name which resulted in an &#039;error&#039; with no information what the error was, just to contact CS. 

But I guess that&#039;s useless if they have changed the e-mail or deleted your characters anyway.]]></description>
		<content:encoded><![CDATA[<p>Whats worse is the account recovery page doesn&#8217;t work either. I enter my associated username/e-mail, the serial key and a character name which resulted in an &#8216;error&#8217; with no information what the error was, just to contact CS. </p>
<p>But I guess that&#8217;s useless if they have changed the e-mail or deleted your characters anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: syncourt</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5950</link>
		<dc:creator>syncourt</dc:creator>
		<pubDate>Sun, 09 Sep 2012 09:00:55 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5950</guid>
		<description><![CDATA[I just had my account hacked today. Kicked from in-game due to another client logging into my account and then changing my password with no e-mail confirmation.

The e-mail validation might have helped me to keep my account more secure, but unfortunately every time I&#039;ve tried to validate my e-mail the link is broken and gives me nothing but &#039;an error has occurred&#039;]]></description>
		<content:encoded><![CDATA[<p>I just had my account hacked today. Kicked from in-game due to another client logging into my account and then changing my password with no e-mail confirmation.</p>
<p>The e-mail validation might have helped me to keep my account more secure, but unfortunately every time I&#8217;ve tried to validate my e-mail the link is broken and gives me nothing but &#8216;an error has occurred&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wanell</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5945</link>
		<dc:creator>wanell</dc:creator>
		<pubDate>Sun, 09 Sep 2012 04:06:28 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5945</guid>
		<description><![CDATA[All aboard the conspiracy fail boat. You do realise you are able to link a GW1 account to a GW2 account? If your GW1 account address was changed to something totally unrelated to the email address that is being used now how logically do you think arenanet would have your current email address in it&#039;s databases if isn&#039;t used in your GW1 account and you currently don&#039;t have a GW2 account?

Which means your current email address was obtained from a 3rd party and is being used in a phishing attempt. It&#039;s great how everyone thinks every database is vulnerable to SQL injection. The sony case was entirely different to anything else that has happened. Sony pissed off people by removing linux on the playstation after it was jailbroken, the contents of their databases were posted on the internet. That was the proof sony was comprimised regardless of how long it took sony to publically announce it many people knew a long time beforehand. Nothing like this has happened yet and until there is some proof, SQL injection this SQL injection that oh look ArenaNet has been hacked.]]></description>
		<content:encoded><![CDATA[<p>All aboard the conspiracy fail boat. You do realise you are able to link a GW1 account to a GW2 account? If your GW1 account address was changed to something totally unrelated to the email address that is being used now how logically do you think arenanet would have your current email address in it&#8217;s databases if isn&#8217;t used in your GW1 account and you currently don&#8217;t have a GW2 account?</p>
<p>Which means your current email address was obtained from a 3rd party and is being used in a phishing attempt. It&#8217;s great how everyone thinks every database is vulnerable to SQL injection. The sony case was entirely different to anything else that has happened. Sony pissed off people by removing linux on the playstation after it was jailbroken, the contents of their databases were posted on the internet. That was the proof sony was comprimised regardless of how long it took sony to publically announce it many people knew a long time beforehand. Nothing like this has happened yet and until there is some proof, SQL injection this SQL injection that oh look ArenaNet has been hacked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: flabcab</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5935</link>
		<dc:creator>flabcab</dc:creator>
		<pubDate>Sun, 09 Sep 2012 02:14:37 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5935</guid>
		<description><![CDATA[I&#039;ve received a couple of emails saying that someone has tried to access my email from an unknown ip, one was in beijing another in korea.

I chose to delete and ignore these emails and haven&#039;t had any issues.....so far.]]></description>
		<content:encoded><![CDATA[<p>I&#8217;ve received a couple of emails saying that someone has tried to access my email from an unknown ip, one was in beijing another in korea.</p>
<p>I chose to delete and ignore these emails and haven&#8217;t had any issues&#8230;..so far.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hadokenx</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5934</link>
		<dc:creator>hadokenx</dc:creator>
		<pubDate>Sun, 09 Sep 2012 01:49:28 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5934</guid>
		<description><![CDATA[&lt;strong&gt;&lt;a href=&quot;#comment-5933&quot; rel=&quot;nofollow&quot;&gt;samurai&#048;&#052;&#055;&lt;/a&gt;&lt;/strong&gt;, 

Apparently, I haven&#039;t made myself clear. If you were at all interested in what I&#039;ve actually said, instead of questioning me (again with my recursive responses)you might actually go look at those GuildWars2Guru posts, and note that I ONLY signed up there for this specific purpose...different email; different password for everything. 

Seriously..if there wasn&#039;t an actual problem, they wouldn&#039;t have disabled the password reset system. There&#039;s at least a flaw in the system; in a more reasonable situation, the email address list for accounts has been exposed (a breach).

&quot;Hackers don’t just go after guildwars related websites.&quot; 
Are you mental? Hackers go after any and every vulnerability they possibly can.

&quot;There is no breach, if there was, they would say. It’s not like they would lose subscribers if they admitted a breach or anything.&quot;
Sony took 8 days....yes, 8 days to come forth and tell the world that they had been breached, and they wouldn&#039;t have even told then if it wasn&#039;t law. Why would they do this? Because they risk losing customers. If there is a breach in the system in which a hacker was able to gain access to the database through the website, you bet your ass they&#039;re going to try to keep quiet - they might not lose subscribers immediately, but they&#039;d have to pull the servers offline to find the flaw and fix it...in that time, the people that were playing the game would have to find something else to do to fill their time, and eventually lose interest. In other words, they risk losing customers. They cannot risk that at this point in time because they&#039;ve invested too much time into the project.]]></description>
		<content:encoded><![CDATA[<p><strong><a href="#comment-5933" rel="nofollow">samurai&#048;&#052;&#055;</a></strong>, </p>
<p>Apparently, I haven&#8217;t made myself clear. If you were at all interested in what I&#8217;ve actually said, instead of questioning me (again with my recursive responses)you might actually go look at those GuildWars2Guru posts, and note that I ONLY signed up there for this specific purpose&#8230;different email; different password for everything. </p>
<p>Seriously..if there wasn&#8217;t an actual problem, they wouldn&#8217;t have disabled the password reset system. There&#8217;s at least a flaw in the system; in a more reasonable situation, the email address list for accounts has been exposed (a breach).</p>
<p>&#8220;Hackers don’t just go after guildwars related websites.&#8221;<br />
Are you mental? Hackers go after any and every vulnerability they possibly can.</p>
<p>&#8220;There is no breach, if there was, they would say. It’s not like they would lose subscribers if they admitted a breach or anything.&#8221;<br />
Sony took 8 days&#8230;.yes, 8 days to come forth and tell the world that they had been breached, and they wouldn&#8217;t have even told then if it wasn&#8217;t law. Why would they do this? Because they risk losing customers. If there is a breach in the system in which a hacker was able to gain access to the database through the website, you bet your ass they&#8217;re going to try to keep quiet &#8211; they might not lose subscribers immediately, but they&#8217;d have to pull the servers offline to find the flaw and fix it&#8230;in that time, the people that were playing the game would have to find something else to do to fill their time, and eventually lose interest. In other words, they risk losing customers. They cannot risk that at this point in time because they&#8217;ve invested too much time into the project.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: samurai047</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5933</link>
		<dc:creator>samurai047</dc:creator>
		<pubDate>Sun, 09 Sep 2012 00:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5933</guid>
		<description><![CDATA[&lt;strong&gt;&lt;a href=&quot;#comment-5915&quot; rel=&quot;nofollow&quot;&gt;hadokenx&lt;/a&gt;&lt;/strong&gt;, 

You do realize that guildwars2guru is a third party website right? Also, do you use the same password anywhere else? Hackers don&#039;t just go after guildwars related websites. There is no breach, if there was, they would say. It&#039;s not like they would lose subscribers if they admitted a breach or anything.]]></description>
		<content:encoded><![CDATA[<p><strong><a href="#comment-5915" rel="nofollow">hadokenx</a></strong>, </p>
<p>You do realize that guildwars2guru is a third party website right? Also, do you use the same password anywhere else? Hackers don&#8217;t just go after guildwars related websites. There is no breach, if there was, they would say. It&#8217;s not like they would lose subscribers if they admitted a breach or anything.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hadokenx</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5928</link>
		<dc:creator>hadokenx</dc:creator>
		<pubDate>Sat, 08 Sep 2012 11:32:21 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5928</guid>
		<description><![CDATA[&lt;strong&gt;&lt;a href=&quot;#comment-5920&quot; rel=&quot;nofollow&quot;&gt;bronzed&lt;/a&gt;&lt;/strong&gt;, 

Yes bronzed, completely isolated. I had an issue with my GW1 account being stolen previously, in which when I got the account back, the email address was then changed to an email address that had no ties to anything else.

Literally, a single day after the official release of GW2, I started getting emails to change my GW2 password; the pitfall here, is that the emails are legitimately coming from  with a link aiming at https://account.guildwars2.com/reset-password/, and not the emails that &quot;look&quot; like they are coming from a legitimate source, like those of the battle.net phishing emails.

While one may assume that I have a virus that is causing the issue...fresh installs, and no GW installed for quite some time, up until I got these emails so I could check to make sure my account hadn&#039;t been stolen again.

My problem with this, is the fact that support are overlooking my circumstances because I don&#039;t have a GW2 account...If I&#039;m getting these emails, and I don&#039;t have a GW2 account, but do have a GW1 account that is attached to that email, that means the database has likely been accessed by someone that shouldn&#039;t have, in which case, there is a breach that ArenaNet or NCSoft is failing to inform the public about - think of the Sony debacle and the 8 days that it took them to actually mention something about it....

Explaining the issue is like a recursive algorithm checking over and over and over again to see if I&#039;m crazy or stupid, because it&#039;s simply not possible that the database has been breached.....]]></description>
		<content:encoded><![CDATA[<p><strong><a href="#comment-5920" rel="nofollow">bronzed</a></strong>, </p>
<p>Yes bronzed, completely isolated. I had an issue with my GW1 account being stolen previously, in which when I got the account back, the email address was then changed to an email address that had no ties to anything else.</p>
<p>Literally, a single day after the official release of GW2, I started getting emails to change my GW2 password; the pitfall here, is that the emails are legitimately coming from  with a link aiming at <a href="https://account.guildwars2.com/reset-password/" rel="nofollow">https://account.guildwars2.com/reset-password/</a>, and not the emails that &#8220;look&#8221; like they are coming from a legitimate source, like those of the battle.net phishing emails.</p>
<p>While one may assume that I have a virus that is causing the issue&#8230;fresh installs, and no GW installed for quite some time, up until I got these emails so I could check to make sure my account hadn&#8217;t been stolen again.</p>
<p>My problem with this, is the fact that support are overlooking my circumstances because I don&#8217;t have a GW2 account&#8230;If I&#8217;m getting these emails, and I don&#8217;t have a GW2 account, but do have a GW1 account that is attached to that email, that means the database has likely been accessed by someone that shouldn&#8217;t have, in which case, there is a breach that ArenaNet or NCSoft is failing to inform the public about &#8211; think of the Sony debacle and the 8 days that it took them to actually mention something about it&#8230;.</p>
<p>Explaining the issue is like a recursive algorithm checking over and over and over again to see if I&#8217;m crazy or stupid, because it&#8217;s simply not possible that the database has been breached&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: azza82</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5924</link>
		<dc:creator>azza82</dc:creator>
		<pubDate>Sat, 08 Sep 2012 07:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5924</guid>
		<description><![CDATA[Could have been the battle.net breach they had. I&#039;ve starting  recieving blizz phising  emails to my battle.net / gw2 exclusive email address today. 
Damnit guess its time to create another email address.]]></description>
		<content:encoded><![CDATA[<p>Could have been the battle.net breach they had. I&#8217;ve starting  recieving blizz phising  emails to my battle.net / gw2 exclusive email address today.<br />
Damnit guess its time to create another email address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bronzed</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5923</link>
		<dc:creator>bronzed</dc:creator>
		<pubDate>Sat, 08 Sep 2012 07:31:44 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5923</guid>
		<description><![CDATA[Unlikely given they have trouble with capacity as it is and are reducing the rate of influx of new players, not the reverse... they&#039;ve seriously underestimated the number of players and load that the game inflict on the servers which caused the problems recently, especially with trade network server.

the trouble with phishing casualties is that once the address is out there, it&#039;ll likely circulate VERY quickly among the miscreant that are likely to use them.

Once that happens it&#039;s likely that the use of the email address in pretty much anything popular afterwards as a security risk in itself.]]></description>
		<content:encoded><![CDATA[<p>Unlikely given they have trouble with capacity as it is and are reducing the rate of influx of new players, not the reverse&#8230; they&#8217;ve seriously underestimated the number of players and load that the game inflict on the servers which caused the problems recently, especially with trade network server.</p>
<p>the trouble with phishing casualties is that once the address is out there, it&#8217;ll likely circulate VERY quickly among the miscreant that are likely to use them.</p>
<p>Once that happens it&#8217;s likely that the use of the email address in pretty much anything popular afterwards as a security risk in itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meji</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5922</link>
		<dc:creator>meji</dc:creator>
		<pubDate>Sat, 08 Sep 2012 07:01:32 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5922</guid>
		<description><![CDATA[I received an email saying my GW1 account password was successfully changed and that I had to authorise it.

Interestingly enough while I did have a GW1 account, it was over 7 years ago I last accessed it and on another entirely different email account which I haven&#039;t accessed, thought about or logged into over 7 years. 

So obviously my email has popped up somewhere and is being targeted by phishing attempts.  This particular email account I use now is used only two places, Battle.net and GoN.   So how would a legitimate ncsoft email turn up on an address they don&#039;t even know exists and has never been linked to any of their products, websites or affiliates?  Seems like it&#039;s just a broad phishing attempt  from stolen email addresses - ie maybe from the big Blizz hack that occurred a month ago.

Of course it could be a blanket email from NcSoft trying to drum up more interest in GW2 :P]]></description>
		<content:encoded><![CDATA[<p>I received an email saying my GW1 account password was successfully changed and that I had to authorise it.</p>
<p>Interestingly enough while I did have a GW1 account, it was over 7 years ago I last accessed it and on another entirely different email account which I haven&#8217;t accessed, thought about or logged into over 7 years. </p>
<p>So obviously my email has popped up somewhere and is being targeted by phishing attempts.  This particular email account I use now is used only two places, Battle.net and GoN.   So how would a legitimate ncsoft email turn up on an address they don&#8217;t even know exists and has never been linked to any of their products, websites or affiliates?  Seems like it&#8217;s just a broad phishing attempt  from stolen email addresses &#8211; ie maybe from the big Blizz hack that occurred a month ago.</p>
<p>Of course it could be a blanket email from NcSoft trying to drum up more interest in GW2 :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bronzed</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5921</link>
		<dc:creator>bronzed</dc:creator>
		<pubDate>Sat, 08 Sep 2012 06:47:13 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5921</guid>
		<description><![CDATA[incidentally i am curious which email specifically hadokenx meant with &quot;and am getting the same emails as GW2 players….&quot; since i can&#039;t think of one that he means here since he doesn&#039;t have a GW2 account.]]></description>
		<content:encoded><![CDATA[<p>incidentally i am curious which email specifically hadokenx meant with &#8220;and am getting the same emails as GW2 players….&#8221; since i can&#8217;t think of one that he means here since he doesn&#8217;t have a GW2 account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bronzed</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5920</link>
		<dc:creator>bronzed</dc:creator>
		<pubDate>Sat, 08 Sep 2012 06:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5920</guid>
		<description><![CDATA[Depends on how effective their email confirmation for IP location is, which should be effective unless the player&#039;s email itself is already compromised in which case he has an actual serious problem.

hadokenx:
whether you use the email for GW fan sites forums or what not frankly matters little, the more curious part is whether this email is used for other things before like other games and what not or if the address is completely isolated (never used before for other games, registration, etc).

because unless it is isolated, then there&#039;s practically no guarantee that the address and possible password combination were not already compromised prior to it&#039;s use in subsequent games or registration.]]></description>
		<content:encoded><![CDATA[<p>Depends on how effective their email confirmation for IP location is, which should be effective unless the player&#8217;s email itself is already compromised in which case he has an actual serious problem.</p>
<p>hadokenx:<br />
whether you use the email for GW fan sites forums or what not frankly matters little, the more curious part is whether this email is used for other things before like other games and what not or if the address is completely isolated (never used before for other games, registration, etc).</p>
<p>because unless it is isolated, then there&#8217;s practically no guarantee that the address and possible password combination were not already compromised prior to it&#8217;s use in subsequent games or registration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: palzer0</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5918</link>
		<dc:creator>palzer0</dc:creator>
		<pubDate>Sat, 08 Sep 2012 04:14:38 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5918</guid>
		<description><![CDATA[How long before we see authenticators similar to Blizzard or SWTOR?]]></description>
		<content:encoded><![CDATA[<p>How long before we see authenticators similar to Blizzard or SWTOR?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hadokenx</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5915</link>
		<dc:creator>hadokenx</dc:creator>
		<pubDate>Sat, 08 Sep 2012 03:54:55 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5915</guid>
		<description><![CDATA[In reply to BOTH of the first two comments:

Go to the Guild Wars forum here on GoN and read my post about Password Reset Emails.

It&#039;s many cases, it&#039;s NOT the players fault...ArenaNet or NCSoft have been breached...I don&#039;t care what anyone else says about it. I DO NOT have a GW2 account, and am getting the same emails as GW2 players....I DO have a GW 1 account, in which the only way the email could&#039;ve been exposed was through NCSoft PlayNC site, or through SQL injection attacks on the Guild Wars Hall of Monuments Calculator which connects directly to the player database.

No, I don&#039;t have a virus. No, I didn&#039;t use that email to sign up for GW fan sites forums. Stop jumping to conclusions.

Hell, if you want to see how their support team actually responds, go to guildwars2guru.com, search for Password Reset Emails, and find the posts by &quot;Temporarily Unavailable&quot; (which just happens to be me.) There is a screen shot of the email conversation, and nothing has ever been solved since. The support team isn&#039;t taking the problem seriously, and this article about them &quot;helping players&quot; is utter crap.]]></description>
		<content:encoded><![CDATA[<p>In reply to BOTH of the first two comments:</p>
<p>Go to the Guild Wars forum here on GoN and read my post about Password Reset Emails.</p>
<p>It&#8217;s many cases, it&#8217;s NOT the players fault&#8230;ArenaNet or NCSoft have been breached&#8230;I don&#8217;t care what anyone else says about it. I DO NOT have a GW2 account, and am getting the same emails as GW2 players&#8230;.I DO have a GW 1 account, in which the only way the email could&#8217;ve been exposed was through NCSoft PlayNC site, or through SQL injection attacks on the Guild Wars Hall of Monuments Calculator which connects directly to the player database.</p>
<p>No, I don&#8217;t have a virus. No, I didn&#8217;t use that email to sign up for GW fan sites forums. Stop jumping to conclusions.</p>
<p>Hell, if you want to see how their support team actually responds, go to guildwars2guru.com, search for Password Reset Emails, and find the posts by &#8220;Temporarily Unavailable&#8221; (which just happens to be me.) There is a screen shot of the email conversation, and nothing has ever been solved since. The support team isn&#8217;t taking the problem seriously, and this article about them &#8220;helping players&#8221; is utter crap.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bronzed</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5910</link>
		<dc:creator>bronzed</dc:creator>
		<pubDate>Sat, 08 Sep 2012 02:26:37 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5910</guid>
		<description><![CDATA[The simple fact is that most ppl usually used the same email address and password for most things, likely including their GW2 account.

It&#039;s also helped by the fact that ppl can link their GW1 account to it, which likely means it&#039;s using the email address of GW1.

the natural thing to do would be to change both after the merge of the account, but few ppl do it... since, well... since it&#039;s internet and most ppl simply are not used to taking safety precautions step.]]></description>
		<content:encoded><![CDATA[<p>The simple fact is that most ppl usually used the same email address and password for most things, likely including their GW2 account.</p>
<p>It&#8217;s also helped by the fact that ppl can link their GW1 account to it, which likely means it&#8217;s using the email address of GW1.</p>
<p>the natural thing to do would be to change both after the merge of the account, but few ppl do it&#8230; since, well&#8230; since it&#8217;s internet and most ppl simply are not used to taking safety precautions step.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: snex</title>
		<link>http://games.on.net/2012/09/guild-wars-2-players-filed-over-8500-account-issue-tickets-in-one-weekend/#comment-5908</link>
		<dc:creator>snex</dc:creator>
		<pubDate>Sat, 08 Sep 2012 01:40:51 +0000</pubDate>
		<guid isPermaLink="false">http://games.on.net/?p=4936#comment-5908</guid>
		<description><![CDATA[Some people just suck at the internet.]]></description>
		<content:encoded><![CDATA[<p>Some people just suck at the internet.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
