Codemasters' Website Hacked
skybon writes "After similar attacks on Sony and Square Enix, Codemasters' website has now been hacked as well. The intrusion took place on 3 June, and is believed to have compromised members' names, usernames, screen names, email addresses, date of birth, encrypted passwords, newsletter preferences, any biographies entered by users, details of last site activity, IP addresses and Xbox Live Gamertags. In a letter sent out to CodeM subscribers, the company recommended changing passwords as soon as possible."
how is that news?
it's like suggesting there'd be more than a handful of intellectuals on crapdot.
Smile, don't click...
Absolutely Brilliant!
The Epic forums got hit too, with usernames and encrypted passwords. At least, the UDK forums did, and I assume the Gears and other game-specific ones did too. Got the email about that today. At least they encrypted passwords, hopefully with a good salt.
I am become
Hacked is not cracked !! Cracked is not hacked !!
Hey, you're not allowed to hack companies who aren't flagrantly, explicitly evil! It's almost like you're hacking companies whose security is weak, rather than acting as moral crusaders. How could that be?
You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
Viva la revolucion! This has all been just too funny of late I must say, especially to an IT manager of a global company who also have their collective heads up their asses & view IT as a cost centre & necessary evil. Don't even get me started on how much importance they place on security lol! :)))
I'm going to go right ahead and say they ain't codeMASTERS if they got hacked....
Just because you're paranoid doesn't mean they aren't out to get you
I have a flamebait theory for you: these kinds of hacks are a GOOD thing. Here's why:
In an increasingly connected world, as "consumers" of various services and products from various companies, we're subjected to literally INSANE amounts of information gathering exercises. Every company you buy things from has information about you (which is usually part of them providing services, or to further communicate with you regarding new service/product offerings, etc.). What we're finding is that there's billions of dollars to be made by mining this data for information on "consumer behavior", under the theory that better understanding that behavior will lead to advertising and marketing tactics that are more cost effective (more eyeballs out of a given set buy something).
The problem with this: when that information gets spread among various "entities" (government, credit and finance industry, software companies, facebook, etc.), it becomes a bit too personal, and frankly, dangerous. You don't need to know about my prostate health, what medicine I just bought at Wal-Mart, my last three residences over the past 5 years, AND my friends list on facebook. That's just fucking scary.
My hope is that the crazy amounts of hacks going on with these companies (Sony, Codemasters) make people wake the fuck up and DEMAND the cessation of information gathering and sharing. If these companies didn't have this information, neither the hack, nor any repercussions from it, would have and/or could take place.
It's only a matter of time until one of the "Big 3" credit bureaus gets hacked in a big way (assuming they haven't been already), along with various aggregators of medical data, insurance claims databases, etc. But the fact remains: if they didn't store such personal information, it wouldn't be a worthwhile target, and even if it was, the "thief" wouldn't get anything out of it.
Anonymous, are you listening? Your next target needs to be the "Big 3" credit bureaus in the United States: Equifax, Experian, TransUnion. Maybe that'll wake John Q Public up enough to demand some fucking privacy controls.
That was 8 days ago! I am so glad they reported this so promptly.
Our Epic Games web sites and forums were recently hacked. After some downtime, they're back up and running now.
The hackers may have obtained the email addresses and encrypted passwords of forum users. Plaintext passwords weren't revealed, but it's possible that those passwords could be obtained by a brute-force attack on the encrypted passwords. Therefore, we have reset all passwords. Your new password at the bottom of this message.
The Unreal Developer Network (UDN) hasn't been compromised. Thankfully, none of our web sites ask for, or store, credit card information or other financial data.
We're sorry for the inconvenience, and appreciate everyone's patience as we wrestle our servers back under control.
Tim Sweeney
Founder, Epic Games Inc
Seeing as a single ATI 6990 can crack a salt with 30length at 3.8billion tries per second.
If Valve's servers get hacked with disastrous consequences (Steam accounts get deleted/hacked/etc, credit card details, other personal info), all hell will break loose. There will also be much smugness from those who don't use Steam for this very reason.
IMHO this has been coming since codemasters decided to opt-out of dedicated PC servers for Operation Flashpoint: Dragon rising. Way to kill what could have been a great PC multiplayer game codemasters :p
However this crack, highlights several problems in our society today.
1) We are too comfortable trusting companies with our private information and trusting them to secure it (all credit card information stored everywhere is encrypted right? right???)
2) We are too comfortable using outdated and terribly insecure credit cards to authorize transactions
3) credit card companies get off scott free allowing illegal transactions, we are in a world where micro-second transactions can take place on the stock exchange but visa/mastercard/american express/etc can't cancel an illegal transaction?
4) It should be illegal for companies to store private information without conforming to some form of regulation such as encrypting ALL private information instead of simply "hashing" credit card numbers.
I'm sure there's more...
Evil enough for anyone. You don't get two products taken away from you if you don't suck to high heaven (Turbine took both DDO and Lotro back from Codemasters inept handling).
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
If it takes a cracker 0.3 seconds, as described in the article you cited, then it also takes the legit server 0.3 seconds to authenticate the user. If a lot of people submit the login form at once, this becomes a denial-of-service attack against the server.
the real lessons they should take here are that they should not even ask for things like date of birth - they could just ask for the year for example
Some web sites have legal reasons to require all users to be at least 13, 18, or 21 years old (to use examples of thresholds from U.S. federal law). Say your web site requires all users to be at least 18 years old. If the sign-up form asks for just the Gregorian year, how would the site distinguish an 18-year-old, whose birthday is before today, from a 17-year-old, whose birthday is after today?
Why is there so many hacking lately? I really don't understand people's motive to hack some servers, websites. Ok one could be money (credit card info, mail databases to sell, etc.) and maybe the other challenge for someone. But hacking is never harmeless.
Awlol
Game companys are clueless about security, and the feeding frenzy is just starting.
At least news like this gets me very worried... why? cos all this announcements ware not made by the companies who got their servers hacked... but ware made by the hackers who did that... i wonder how many hackings are done without anyone knowing ... without anyone making those attacks public... and in theory security engineers learn from things like that.... is called Forensics right? hmmm and some ppl say " There is not such thing as ethical hacking..".... why not? i know from experience that you need a thief to catch a thief.... and another things that gets me worried is the fact that many security engineers say " hackers have small penises" and things like that... but they should see them as enemies and and do not underestimate them... some of them are kids who do this to have fun... some of them do hacking shit cos they are payed to do so... and all this attacks who took place lately... all this has on propose : to take somebody else identity.... why? that is the big answer...
I hack my my own servers daily. My security is 31337 (Pull the Plug)
All cows eat grass!
Thanks for info, http://exercisesto-reducetummy.com/articles/exercises-to-reduce-tummy-how-i-lost-50-pounds