Saturday, March 19, 2011

RIFT Executive Producer Scott Hartsman addresses login validation bug

In the wake of Friday's update to fix the player-discovered bug with login validation between the Rift client and server, Executive Producer Scott Hartsman posted the following statement:
Weekend Security Update

Hi, everyone -- I wanted to get an update out for the weekend after the last day of excitement around here.

On last night's fix -- I'm very happy to confirm that we did fix a login vulnerability, with significant assistance from an extremely clever user.

The root cause was a very subtle bug in error checking of our login validations deep in the server code. No personal information or any such was leaked out, and no outside attacker penetrated our servers, networks, or databases.

We'd definitely like to thank Mr. ManWitDaPlan for the well-timed assist. Sir, we salute you and offer our most heartfelt thanks.

The rest of what I'd like to add isn't to detract from the above well-deserved compliment, but it's important to include in the comprehensive picture.

The sobering fact is that account security remains a multifaceted issue, as attacks from other sources continue.

It's important to remember is that while a hole was identified and fixed as rapidly as we possibly could, there are still hackers and botnets trying account/password combinations from compromised web sites and past MMOs.

They are doing this right now. Those attacks have been coming constantly since we launched the game. The only thing that changes are how many hundreds of computers are trying to get into your account at any given moment, where they're coming from, and how many are succeeding.

We do block them as they are detected, but the fact that they are using distributed botnets (compromised computers from across the globe) means that this will remain something that we will continue keeping an eye on, forever.

For users getting hacked this way, Coin Lock is currently doing its job protecting people's belongings, provided that your RIFT password and EMail password are both complex and entirely different.

Both the login fix and the Coin Lock addition have been doing their part in signficantly reducing overall incidents over the last 18 hours.

Neither one is a silver bullet, but so far it is looking to be a solid one-two punch for the weekend.

Then, with two-factor authentication coming very soon, we expect security to be improved even further.

All totalled up, under 1% of accounts with characters have had characters impacted. However, 1% of a surprisingly large number is still very noticeable.

Our staff has been, and will continue to be, working around the clock to get those impacted back in shape. We'll continue hiring on even more people to help people with issues of all kinds, as quickly as we can. (Another round of hires begin on Monday, and there will be even more to follow.)

As always, thanks very much for your time, your attention, your assistance, and your patience!

- Scott Hartsman
Exec Producer, RIFT
Hartsman's statement makes clear the magnitude of the support issue created by the bug. He indicated that there is a backlog of people waiting on Customer Support to repair the damage to their characters inflicted by the hijackers. The total number of people affected could number in the low thousands, but the exact figure is unknown as Trion has not released numbers for its player base.

ZAM followed up with an extensive interview of the player who discovered and reported the security bug: Ex-Hacker Finds RIFT Account Flaw, Talks to ZAM

Trion Worlds patches security hole in Rift

On Friday a member of the Rift player community with the handle ManWitDaPlan discovered an exploit in the login protocol for Rift which allowed the Rift client to access accounts without authentication. He promptly communicated directly with Trion's technical staff to convey the details about the exploit. An update to the game was released Friday evening which closed the hole.

Shortly after Trion learned of the exploit, James "Elrar" Nichols, Assistant Community Manager, posted this statement:
We have some things in the works right now and have been passing on your feedback, concerns, and thoughts throughout the day (no matter how radical or unlikely).

Sharing sensitive information about our actions (no matter how broad) naturally also informs those carrying out these attacks. This puts us in a tight spot with how much information we can provide, and the questions we can answer.


Apologies we can't be more forthcoming at this time, but we appreciate your understanding - its always our goal to ensure you can play and enjoy the game securely, and unfettered.
Later in the evening ManWitDaPlan posted:
Got word back from Steve Chamberlin, the development lead for Rift. This hole is sealed...the issue I found is no more.
In recent days the official forums had seen a marked increase in the number of complaints of hijacked accounts—players wrote of logging in to find their characters broke, or naked, or missing. Some players wrote of struggling with the hijackers over control of their accounts.

The closing of this security hole and the recent implementation of the Coin Lock feature should sharply reduce the number of hijacked accounts.

The login exploit and resulting hijacked accounts is the first blemish on what had until now been a very smooth and successful launch by Trion.

The response by Trion to the report of the exploit was very quick; just a few hours elapsed on Friday between when Trion first learned the details of the exploit and the restart for the update which closed the hole.

Update:  On Saturday, RIFT Executive Producer Scott Hartsman posted a statement addressing the situation.

Thursday, February 24, 2011

Rift opens with full servers, queues

This was the situation just minutes after launch:

Almost all servers were full

Long queues to join

Shortly after the above screenshots were captured, the last servers filled leaving none available for waiting players to join. More servers were brought online fairly quickly which absorbed many of the waiting players, but queues on the original group of servers remained lengthy due to the number of guilds which had prearranged to play on them.

Performance on the servers I was able to join seemed decent and they remained stable for several hours, with 15 minutes of downtime for a performance adjustment.

Rift's in-game Twitter integration and automatic tweets

Rift has built Twitter capability into its client so one can tweet messages (via /tweet) and screenshots (via /tweetpic) while in-game.

Of course Trion Worlds has done this to leverage the social web in an effort to drive adoption of the game.

In addition to user-initiated tweets, there is also the option to allow the client to tweet automatically. When this feature was first added during the open beta it immediately flooded the #rift hashtag with automatically-generated achievement spam. Trion quickly patched it to default to using a different hashtag, #riftfeed.

I'm interested to see what gets tweeted automatically and how spammy it is, but in order to avoid disturbing my tiny handful of followers with game activity, I've set up another account just for in-game tweets from the Rift client.

To see those tweets, check out the Twitter stream for Strat_in_game.

The capability for players to easily tweet while in-game, particularly to include screenshots, is quite cool. But the automatic tweets seem like useless spam if they can't be filtered by the player. I don't see how automatically-generated tweets are useful at all to players. Once Trion implements an Armory-like interface to character data over the web, it's likely to include achievements and anything else likely to be auto-tweeted.

Update: Shortly after launch, #riftfeed was flooded with auto-tweets, many for server-first acquisition of green and white items!

Tuesday, February 22, 2011

Rift starts with about 1/3 the zones of original WoW

[Update:  The purpose of this post is to point out the difference in zone count at launch and get reaction. Once I compiled the two lists I was struck by the magnitude of the difference, and thought it would be a good discussion starter. See the ensuing reactions on Bio Break and this GameFAQs thread.]

Rift has generated much enthusiasm as a result of its recent open beta. People have been wondering how the Rift game world compares to World of Warcraft. A comparison of the number of zones in Rift versus WoW at release is illuminating:

Zones at Launch
RiftWoW
  1. Mathosia (1-6)
  2. Terminus (1-6)
  3. Freemarch (6-20)
  4. Silverwood (6-20)
  5. Gloamwood (20-27)
  6. Stonefield (20-27)
  7. Scarlet Gorge (26-30)
  8. Scarwood Reach (30-35)
  9. Droughtlands (?)
  10. Iron Pine Peak (?)
  11. Lake of Solace (?)
  12. Moonshade Highlands (?)
  13. Shimmersand (?)
  14. Stillmoor (?)
  1. Dun Morogh (1-10)
  2. Durotar (1-10)
  3. Elwynn Forest (1-10)
  4. Mulgore (1-10)
  5. Teldrassil (1-10)
  6. Tirisfal Glades (1-10)
  7. Darkshore (10-20)
  8. Loch Modan (10-20)
  9. Silverpine Forest (10-20)
  10. Westfall (10-20)
  11. Barrens (10-25)
  12. Redridge Mountains (15-25)
  13. Stonetalon Mountains (15-27)
  14. Ashenvale (18-30)
  15. Duskwood (18-30)
  16. Hillsbrad Foothills (20-30)
  17. Wetlands (20-30)
  18. Thousand Needles (25-35)
  19. Alterac Mountains (30-40)
  20. Arathi Highlands (30-40)
  21. Desolace (30-40)
  22. Stranglethorn Vale (30-45)
  23. Dustwallow Marsh (35-45)
  24. Badlands (35-45)
  25. Swamp of Sorrows (35-45)
  26. Feralas (40-50)
  27. Hinterlands (40-50)
  28. Tanaris (40-50)
  29. Searing Gorge (45-50)
  30. Azshara (45-55)
  31. Blasted Lands (45-55)
  32. Un'goro Crater (48-55)
  33. Felwood (48-55)
  34. Burning Steppes (50-58)
  35. Western Plaguelands (51-58)
  36. Deadwind Pass (55-60)
  37. Eastern Plaguelands (53-60)
  38. Winterspring (53-60)
  39. Moonglade (55-60)
  40. Silithus (55-60)
(Source Telarapedia)(Source WoWWiki)

The score for zone count at release is 40-14 WoW over Rift.

A couple of caveats about the zone counts. Mathosia and Terminus, Rift's two initial zones, can only be revisited by starting a new character. WoW had three zones without much content at launch—Moonglade, Deadwind Pass, and Silithus.

WoW currently has 75 zones;  12 were added with The Burning Crusade, Wrath of the Lich King added another 12, and Cataclysm added 11 zones, nine new ones and two created by splitting existing ones.

It will be interesting to see if Trion Worlds is able to sustain the interest of players in Rift with such a low number of zones available to max level players.

Monday, October 12, 2009

WoW: Battle.net account merge incoming


Blizzard announced today a deadline for the conversion of World of Warcraft accounts to Battle.net accounts: November 11, 2009. That gives WoW account holders 30 days to make the switch.

As an incentive, Blizzard is offering an in-game penguin pet.

In light of the high number of stolen WoW accounts it will be interesting to see how Battle.net compares in security. While we can hope that Battle.net accounts will be more secure, a few things come to mind.

Battle.net uses the primary email address as the account name. It may be somewhat easier to guess, or in Tolbold's case, very publicly known, which is why he's all over the security ramifications in Blizzard sabotages WoW account security.

Instead of taking Tobold's suggestion of setting up another email account for use with Battle.net, gmail subscribers can use the alias feature to make the Battle.net account name hard to guess. In gmail, you can add +anything to an email address and still receive the email, so if your email address is foo@gmail.com, you will also get any email sent to the alias foo+anything@gmail.com. Replace anything with something obscure and your Battle.net account name becomes as unguessable as your old WoW account name was. This is a convenient alternative to Tobold's suggestion of setting up another email account just for Battle.net.

I just used a gmail alias to set up a new Battle.net account, and it worked. (With one small glitch, the link in the first verification email failed, so I had Battle.net send a second verification email.)

Of course the problem remains that using an email address for the account name is a very bad choice. Email addresses are not usually considered to be private information and are much less well protected than passwords. For example, email addresses are often sold to third parties, thus increasing the risk of the address becoming public. Indeed, Blizzard is well aware of the problems with email addresses becoming known, as shown by this forum post about Fake E-mails from "Blizzard Entertainment":
Why am I receiving these e-mails? What can I do to ensure malicious parties do not have my e-mail address?
    In most cases, e-mail addresses are gleaned from unofficial World of Warcraft web pages(guild websites, fan sites, etc) and social networking sites (Facebook, Myspace, etc). As such, you may wish to set-up a new, separate email address and register it to your account. When selecting the username and password for this new email address, ensure that these variables do not overlap with that of your WoW account or any other login type (guild websites, Facebook, MySpace, etc). Once this address is registered, do not use it for anything else: no additional registrations, no guild websites, no newsletter sign-ups, et al. Keep this address isolated.
First Blizzard tells people to protect their email addresses so they won't receive emails phishing for account info and then turns around with the new Battle.net and uses the email address as the login!

One indication of how bad the situation is with stolen WoW accounts is that the Blizzard Authenticator is being sold for $6.50 with free shipping. At that price Blizzard is making little if any money on them. It's cheaper for Blizzard to hand out the Authenticators essentially for free than to incur the support costs in dealing with customers whose accounts have been stolen.

To anyone who objects to the cost of the Authenticator: Blizzard charges $25.00 to move bits around if you purchase a Paid Character Transfer. Yet it will ship an actual physical object to you for $6.50, which is basically the cost of shipping. There's a reason for this: the Authenticators work. And by keeping accounts secure they save everyone grief and time. Well worth the money.

Sunday, October 4, 2009

WoW: You vill play how ve vant you to

Now that I've been playing WoW again for a bit, I've discovered that due to recent changes the game is a lot less alt-friendly for a player without a level 80 character. While there has always been a natural advantage in having a max-level character to pass items and gold to the alternates, the game has now added explicit benefits: there are new heirloom items that can be passed to any character on the account which boost experience gains. One heirloom, the Tome of Cold Weather Flight, allows flying in Northrend at level 68.

As a result, while I'd rather play the warlock, it made less sense to level it up from 41 than to first get the 70 shadow priest to 80 and start grinding for heirlooms. And the situation is even worse with the lower-level alts (yes, I'm an altoholic).

Of course the business reason for favoring the alts of dedicated players is to keep them engaged in WoW rather than wandering off to other games. While it's a bit frustrating for an atypical player like me to see certain play styles favored over others, in the end I decided to conform and play in the manner that Blizzard rewards with incentives.

But I'm not particularly happy about it.