test content
What is the Arc Client?
Install Arc
Options

I just got TRIBBLE - what can I do about it?

1567810

Comments

  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited March 2012
    jkstocbr wrote:
    More accounts being TRIBBLE and cleaned out? .... call me paranoid but I'm changed changing password... its now really long with Letter/Numbers/Upcase/Lowercase.

    :D the best passwords you can't even remember without writing them on a sheet of paper (I'd not trust notepad...).
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Ani_Kai wrote:
    :D the best passwords you can't even remember without writing them on a sheet of paper (I'd not trust notepad...).

    Get an encrypted password vault like KeePass or something. Bonus: Comes with random gibberish password generator.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Get an encrypted password vault like KeePass or something. Bonus: Comes with random gibberish password generator.

    That won't give u any good if the username and password were stolen from the game server database....if they were encrypted in the database it would take them some time to crack but they'll crack them.

    If game's database has been compromised and TRIBBLE into Cryptic needs to inform us so we can change our password, faling to do that is tantamount to helping the hackers hack into our account.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    That won't give u any good if the username and password were stolen from the game server database....if they were encrypted in the database it would take them some time to crack but they'll crack them.

    If game's database has been compromised and TRIBBLE into Cryptic needs to inform us so we can change our password, faling to do that is tantamount to helping the hackers hack into our account.
    Brandon posted this in another thread:
    Branflakes wrote:
    Also, I'll have a chat with our Customer Service team in the morning, but some of the comments made in this thread about hackings happening due to our integration with PWE are unfounded rumors and speculations that are causing more harm than good. I can assure you that if this had happened, we would have notified every player who has ever played our game. Also, Here is a recent post I made in a different thread about your payment methods:

    We take the security of your payment information very seriously. *Let me reassure you that there is no way for credit card information to be compromised. If you have a card on your account, and a hacker gets in, they can never view the full card number. The only damage they can do is purchase a subscription or points using the payment method on file. Since these transactions would be through Cryptic, we can take care of it as soon as we receive notification (i.e. a ticket or an email sent to customerservice@perfectworld.com).
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    That won't give u any good if the username and password were stolen from the game server database....if they were encrypted in the database it would take them some time to crack but they'll crack them.

    If game's database has been compromised and TRIBBLE into Cryptic needs to inform us so we can change our password, faling to do that is tantamount to helping the hackers hack into our account.

    I know. I'm just saying that's a better way of keeping your passwords secure on your end of the chain. You can't do anything about the other side though.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    btw, when you submit a ticket in-game, is it supposed to show up in the "Your Tickets" window? Because mine isn't even though I have a ticket number.

    I noticed that too. I even had to start up a second ticket because they asked me to edit the first, which I couldn't find. The 2nd one showed up like it was supposed to, on the website and in-game.

    Have you tried making a PW account and linking your Cryptic account to it? That might help you find the tickets better. They might be hopping over to PW support. :confused:
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    well today i got TRIBBLE,

    i was online in the morning to start some Duty Offi Missions
    went off to get lunch, in less than 20 min i came back, and i could not login, it said already logged in, something like that, i saw in the char select screen, the last played char was not on top, was wondering whats going on, tried to get in again, but nothing, same message, changed my PW, and got in
    saw all my credits are gone, on all 3 toons, also some/many items are gone, from inventory and bank
    fleetbank was not touched

    so they had less than 20 min to clean the most stuff, even i stopped him, because changed my PW

    Unfortunately i saw this thread to late, so i wrote a ticket via cryptic support page earlier
    because i dont have a Perfect World account
    i might have to update my ticket, not sure where, because i cant see it ingame yet
    maybe i have to reply the standard Email i got earlier, as i dont have access to PW
    when i click the link (from the email) it says login :)

    or should i write another ingame ticket with subject TRIBBLE?, or should i just wait ?, we do have sunday, easter sunday ...
    nice easter egg i got today

    greetings Zdenka

    PS sorry about my english
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Zdenka wrote: »
    well today i got TRIBBLE,

    i was online in the morning to start some Duty Offi Missions
    went off to get lunch, in less than 20 min i came back, and i could not login, it said already logged in, something like that, i saw in the char select screen, the last played char was not on top, was wondering whats going on, tried to get in again, but nothing, same message, changed my PW, and got in
    saw all my credits are gone, on all 3 toons, also some/many items are gone, from inventory and bank
    fleetbank was not touched

    so they had less than 20 min to clean the most stuff, even i stopped him, because changed my PW

    Unfortunately i saw this thread to late, so i wrote a ticket via cryptic support page earlier
    because i dont have a Perfect World account
    i might have to update my ticket, not sure where, because i cant see it ingame yet
    maybe i have to reply the standard Email i got earlier, as i dont have access to PW
    when i click the link (from the email) it says login :)

    or should i write another ingame ticket with subject TRIBBLE?, or should i just wait ?, we do have sunday, easter sunday ...
    nice easter egg i got today

    greetings Zdenka

    PS sorry about my english

    I wrote a ticket to the pw site but I logged into game I decided to log another ticket thru the game, and it ths the ingame ticket that I got a response from . I did have to edit the with the subject being TRIBBLE. Fortunately they had me up and running again within a week
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    ok i got a response via email,
    i should update my (webpage)-ticket with more informations (its a PW-link)

    the problem is, i have tried to sign in twice (with a diffrent email adress) on the Perfect World account page, and got twice a confirmation email, which i clicked of course, but when i try to login (with both accounts, same result), it saiys accountname or PW or capacha code is wrong
    if i try to send back account name or try to reset PW, i get on both emails the error -> they arent known

    so now i should modify a ticket on Perfect World page, where i cant register

    so pls help me, what iam doing wrong, or should i just make an ingame ticket, as you said before with more detailed informations ?

    greetings Zdenka
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I was looking forwad to coming back to sto and playing the game with some friends but it looks like the cards will not fall that way for me. Yes I was TRIBBLE all of my stuff is gone and CS support was NO HELP at all and this stinks.

    Yes I submitted a ticket to them stating my case/problem and they were no help at all. Plus no phone support just really really stinks. Yes I have CS account and not a perfect world account.

    I really miss my lvl 45 toon right now. She was fun to play. I hope other ppl will have better luck then me
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I appeared on my starship bridge while my account was being TRIBBLE and actually saw another player standing there before the "dual account access" message booted us both.

    I managed to write down the hacker's Cryptic @tag and I reported it to Cryptic after I changed my password and locked the bastid out.

    As a result of accidentally "walking in" on the thief, he only stole my main character's Energy Credits. Cryptic has since restored the character after I filed an in-game ticket with the subject line TRIBBLE Account.

    EDIT: Forgot to mention that I had been playing the game in space for a while before I decided to visit my starship interior, and it was only after I appeared in the same gamespace (on my bridge) with the hacker that the game registered a dual login and responded to the outside presence.

    Note that it took about a day and a half for the hack ticket to appear in my tickets window, even though a Cryptic CS representative responded earlier than this (within a business day).

    I never did get an acknowledgement of whether or not the @tag I provided led to anything. I expect the character used by the hacker was built to be disposable -- and even lf Cryptic did identify the scumbag, I presume they wouldn't be allowed to tell me.

    KOS
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Logged in and found someone already there. Unfortunately I didn't log into the character at the top of the list, but my main, so I didn't get to see anyone standing around my bridge spiritting away my stuff. I hope your sighting pans out, but I'm not sure they still require proof of ID (credit card info) for membership to this game.

    Contacted Cryptic through the Request GM help button, as the help bits of the site have been replaced with PWE services, which I don't have an account for and no particular desire to start. I got my instructions back, same as the opening post of this thread, more or less, and sent in the information requested...

    I just hope this rollback thing, if it is possible, doesn't reach back too far. I made a lot of headway in the last couple of days in the doff system, on my main, put in a lot of effort to close those last few gaps to T4. I suspect I'm going to have to do that all over again. I'm also a bit worried about a character-unlock (100 doffslots) I bought on the C-store in the same period disappearing along with it, so I would've preferred a more manual, if inevitably incomplete manner of restoration for that one.

    I'm no closer to understanding how they got my password. I don't recall having signed up anywhere with my STO password, and the OP seems a bit dated for a single pass along STOwiki to have caused me trouble now, unless this guy's been sitting on these passwords for weeks. And I have found no trace of the program described. Yet, anway.


    Anyway, as to what can be done... I'm still a little ****ed this is even possible. While I was surveying the damage, so I could tell Cryptic what character's needed restoring and which didn't, I kept inputting my old password... That'll get on your nerves fast.

    People have asked for authenticators in the past. I've never used one for a game, but they're supposed to be fairly reliable, and I'm definately ready to do a 180 on those.

    It seems to me though that fighting keyloggers and phishing expeditions needn't even be that involved: Just ask whoever's logging in, whenever they're logging in from an IP adress that doesn't match the one they last successfully logged in from, to identify one of the characters contained in the account. Or ask them one of their super secret questions. It'd leave people who play the game on the move, off of a laptop and wi-fi, susceptible, as them inputting the information will be logged right along with their password, but for the vast majority of (desktop) users at least it creates one question for the hacker that he's never seen the account's owner type in the answer for. It's not 100% airtight, but it'd be a significant improvement.

    Edit: Just a quick thank-you to the guys at Cryptic. Thought I'd go this route rather than alarm anyone by editing a ticket that they're done with. The mess has been sorted, in what I think has been a fairly short amount of time. Three of my four affected characters have been restored, the fourth couldn't be, for reasons unspecified, but luckily that one was the least affected. (The thief was still unequipping weapons when I interrupted him.) The side-effects, if they can be called that, seem fairly minimal.

    Now if I can just stop entering the wrong password... :rolleyes:
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    finally i got all my chars restored, with all my credits and items, i lost maybe one day, well thats ok

    only problem than i had, few bought services via C-Store was lost, but now, i got this back too

    soo it took 3 days to fix my 3 chars
    very good work !

    thanks ones more

    greetings Zdenka
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I am having the same issues for the past week or so, no response yet to my tickets, I bought a lifetime membership ;(
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I got TRIBBLE today too. Sent a ticket and dunno why but its not on the list there. I know they got it cause i got the email saying they got the ticket.

    Anyway i found out about being TRIBBLE while talking with a friend on our TS and he told me im standing next to some guy in fleet escort in Aenigma Nebula. I went on and tried to login when it gave me a invalid password error.

    Then i got atuomated mail from Cryptic : "This is an automated notification regarding the changes made to your Cryptic Studios game account. Your email address has recently been modified through the Account Management Wesbsite." I got a link to revert ithe email being changed and i stopped it.

    Managed to reset the password and login again but it was tooo late. Over 320 Million ECs gone (collecting for over a month), 300 K dilithium gone, and exchange cleaned inside out. Also there were some REALLY valuable items on the exchange, in combined value of around 50ish million.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Josip1000 wrote: »
    I got TRIBBLE today too. Sent a ticket and dunno why but its not on the list there. I know they got it cause i got the email saying they got the ticket.

    Anyway i found out about being TRIBBLE while talking with a friend on our TS and he told me im standing next to some guy in fleet escort in Aenigma Nebula. I went on and tried to login when it gave me a invalid password error.

    Then i got atuomated mail from Cryptic : "This is an automated notification regarding the changes made to your Cryptic Studios game account. Your email address has recently been modified through the Account Management Wesbsite." I got a link to revert ithe email being changed and i stopped it.

    Managed to reset the password and login again but it was tooo late. Over 320 Million ECs gone (collecting for over a month), 300 K dilithium gone, and exchange cleaned inside out. Also there were some REALLY valuable items on the exchange, in combined value of around 50ish million.

    that sucks. i've been reading alot of TRIBBLE member accounts threads popping up alot in diffrent forums of this offical forums. however, i knew here was alot of dangers of F2P would bring, Cryptic did't thought about adding Security, new protection, new Account security, Updates, upgrades etc etc. that would protect STO and its players from hackers. unfortunely, that never happened because i'm pretty sure they never put any thought into or actually researched F2P alot more. however, i'm experienced player and i know alot of dangers that F2P brings. i actually created new security, protection for my fleet because i knew the F2P was coming in future. so i did utmost security, protection and settings to protect the fleet bank and my inventory everything etc etc. but that came to end when Cryptic decided to terminate my old account. you know, i would have helped other fleets or anyone who had been TRIBBLE. i would give my fleet resources to them. but unfortunely i can't do that because i don't have that account anymore. but you get the general idea of how that hackings happens through F2P.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I think I may have walked in on another attempt to hack my account tonight. I logged in with one of my secondary characters, which is part of the same fleet as my primary, and noticed my primary was listed as online in the fleet roster. I went and logged into my primary, and my ship was still sitting where I left it, and nothing was missing, so it was either a bug, or I got lucky and booted the hacker before he could do anything.

    Time for another password change.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I think I may have walked in on another attempt to hack my account tonight. I logged in with one of my secondary characters, which is part of the same fleet as my primary, and noticed my primary was listed as online in the fleet roster. I went and logged into my primary, and my ship was still sitting where I left it, and nothing was missing, so it was either a bug, or I got lucky and booted the hacker before he could do anything.

    Time for another password change.

    The fleet roster thing is a bug :)
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I think I may have walked in on another attempt to hack my account tonight. I logged in with one of my secondary characters, which is part of the same fleet as my primary, and noticed my primary was listed as online in the fleet roster. I went and logged into my primary, and my ship was still sitting where I left it, and nothing was missing, so it was either a bug, or I got lucky and booted the hacker before he could do anything.

    Time for another password change.

    Not only is that an old time bug which appears to have returned :( but it's impossible for anyone else to log into your STO account while you are all-ready logged in and playing. :)
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    AdamPD wrote: »
    I wonder if the amount of people being TRIBBLE is a direct result of their usernames being spammed across screens during this lockbox/cardassian galor thing? ;)

    I wouldn't put it past a hacker to collect usernames that are spammed by using some program to record their chatlog, then brute forcing those usernames


    Yeah, that disturbs me too. People who win shouldnt have their name broadcast to the community. It invites spam from other players and can potentially cause what you just mentioned. The whole thing of broadcasting the username is wrong in my opinion. If you want to broadcast the character name without the @blah that is fine.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Askray wrote: »
    The fleet roster thing is a bug :)
    Alecto wrote: »
    Not only is that an old time bug which appears to have returned :( but it's impossible for anyone else to log into your STO account while you are all-ready logged in and playing. :)

    That's what I figured, but after last time I didn't want to take the chance :p
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    a frend of mine possabley had his account TRIBBLE i was looking for a piticlar link that used to be on top but now is not it contaned info on what to do if people get TRIBBLE i was wondering where the link went so i may pass it on pls
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    I've just had a similar problem, logged out to change toons and invalid password. Went to main site to check, possibly reset and change, just redirects to main site again.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Same here. changed my password to be safe.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012

    OH Thank God...

    I thought my account was TRIBBLE. :eek:
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    Oh whew. I was really panicking there for a minute when I couldn't even log in to change my password.
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    How to not get your account hijacked:
    1. Don't buy from gold spammers.
    2. Have a real password and not "Passw0rd".

    I highly doubt the keyloggers of the world are out looking for STO passwords. While some of the legacy players might have had an issue where their @handle was the same as their log-in info, that should no longer be the case. So even if someone knows your @handle, they don't know your username. The only way your account is being TRIBBLE into is if you are providing someone that information.

    That being said, visit this website. Running the tests on that page will test your system for security. If any of the tests fail, it'll tell you how to fix them.

    But if you pass all of those tests, your @handle does NOT match your log-in username, and your password would take years to hack (my wireless router would take 5 trillion years to hack), then there is almost no way your account gets TRIBBLE unless you are giving that information out.

    The moral of the story: STAY AWAY FROM GOLD FARMERS!
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    yea i almost thought i got TRIBBLE too!
  • Options
    Archived PostArchived Post Member Posts: 2,264,498 Arc User
    edited April 2012
    As a council member of a fleet that has just suffered a user account compromise which lead to some thefts from our fleet banks, which whilst we're not too concerned about because it was all material things that we can get back,

    what I am concerned about is the poor user in question who has therefore suffered that hack.

    ** THIS THREAD IS NOT TO TALK ABOUT THE EXPERIENCE BUT PREVENTATIVE ACTION, SHOULD CRYPTIC/PWE TAKE IT **

    So, as a ticket is raised, I won't be drawn into ANY details,

    My concern and therefore question is this;

    with the launch of free-to-play and therefore the rise in the game's popularity, would it not be prudent for a relatively small investment in an RSA server? granting us the ability to have RSA token clients on our smart phones (iOS/Android) as other big titles do?

    As a gold member, I would like to ensure that my account is as safe as possible, and if need be, I'd be happy to pay a little premium to have said insurance policy,

    so, as this is a discussion, people play nice :-)

    ** Looks like my thread was moved to "PC & Technical Issues", which it has nothing to do with! **
Sign In or Register to comment.