Page 1 of 3

for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 10:28 pm
by Xwarbi95x
hi, i have been off the game for a while, i have just tried to log back into my account (username is the same as my forum username) however the server popped up with a message saying that my password has been leaked from another site, please rocover your account on forums.

first of all i have a massive issue with the fact my password is able to be leaked via a 3rd party, it demonstrates security for pkhonor is very poor, noone should have access to any data regarding players passwords, purchase details made in game, card details used to make those purchases ect, other than those of the staff who maintain the actual server and the data held within.

secondly how do i go about recovering my account so i can continue playing on my account?

i would also like to claim compensation for the lack of security of the protection of my personal password being leaked as i use the same password for most things, the amount of compensation i require is 25b in game currency not too much to ask for for a breach in security.

my laptop is abit broken so i am not able to do the printscreen required to provide evidence as it comes out blurry for some reason, i am happy to share my current password only with the member of staff that will deal with my situation but not through anyone else.

many thanks xWarbi95x

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 10:34 pm
by 026
Hey,

Please make a thread on here viewforum.php?f=58

Regards,
026.

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 10:37 pm
by Iron adam
Xwarbi95x wrote:first of all i have a massive issue with the fact my password is able to be leaked via a 3rd party, it demonstrates security for pkhonor is very poor, noone should have access to any data regarding players passwords, purchase details made in game, card details used to make those purchases ect, other than those of the staff who maintain the actual server and the data held within.
A third party site is a website that is not associated with PkHonor. This means that you reused your information on a different website or RSPS that had a data breach. We heavily encrypt all of our users' information and data. Unfortunately this happens far too often. You can see what databases your information has been leaked in here: https://rslookup.com/lookup Looks like you were infact compromised by another RSPS.
Xwarbi95x wrote:secondly how do i go about recovering my account so i can continue playing on my account?
Post a recovery here: viewforum.php?f=58
Xwarbi95x wrote:i would also like to claim compensation for the lack of security of the protection of my personal password being leaked as i use the same password for most things, the amount of compensation i require is 25b in game currency not too much to ask for for a breach in security.
You can post a refund for any items you lost and we will do our best to recover them.
Xwarbi95x wrote:i am happy to share my current password only with the member of staff that will deal with my situation but not through anyone else.
This wouldn't help us at all for a few reasons. First, as I already said, we heavily encrypt all our data. Not even Mike and Rapsey could tell you your password as we don't store in plaintext. Second, if your password was leaked on another site, knowing that leaked password doesn't prove that you are the owner of the account.

Going forward, just use a unique password on Pkhonor and you wont have any issues.

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 10:48 pm
by Isaac
Xwarbi95x wrote: i would also like to claim compensation for the lack of security of the protection of my personal password being leaked as i use the same password for most things, the amount of compensation i require is 25b in game currency not too much to ask for for a breach in security.
This man bringing a civil claim against PkHonor god damn, link me your lawyer we can work it out x

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 11:05 pm
by Xwarbi95x
i have followed the correct procedure in which to recovery my account and have spoken with moderator 026 in game via my alternative account regarding my main account.

adam i have veiwed the link and it does indeed state my username is within a database, however it does not tell me which database i am in? does this mean i am liable for futher hacks from the unknown culprit?

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 11:26 pm
by Will be ok
Isaac wrote:
Xwarbi95x wrote: i would also like to claim compensation for the lack of security of the protection of my personal password being leaked as i use the same password for most things, the amount of compensation i require is 25b in game currency not too much to ask for for a breach in security.
This man bringing a civil claim against PkHonor god damn, link me your lawyer we can work it out x
Bahahahahah compensation... “hey look I’m gonna put my info out on multiple sources on the internet then get mad when someone uses it”

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 11:42 pm
by Rizz0
Xwarbi95x wrote: my laptop is abit broken so i am not able to do the printscreen required to provide evidence as it comes out blurry for some reason
please post anyway i wanna see this

Re: for the attention of development staff URGENT

Posted: Tue Feb 05, 2019 11:55 pm
by Iron adam
Xwarbi95x wrote:i have followed the correct procedure in which to recovery my account and have spoken with moderator 026 in game via my alternative account regarding my main account.

adam i have veiwed the link and it does indeed state my username is within a database, however it does not tell me which database i am in? does this mean i am liable for futher hacks from the unknown culprit?
Once your username and a password have been leaked in a database, they are out there forever. If the database is public, then anyone who finds it, can use your information. You should also scan your computer for keyloggers and any other viruses. I also recommend removing any other RSPS clients that you don't play on anymore. There have been several cases in the past of some shady owners hacking their player's accounts on OSRS.

I strongly recommend that you never use a previous password again on any type of site. Forget PkHonor for a second, if you were to reuse a username and password for something like online banking, someone could ruin your life. Every site that you ever register on should be with a unique username and password.

Re: for the attention of development staff URGENT

Posted: Wed Feb 06, 2019 2:13 am
by Braxton
Like I said, corruption. How about Staff look at my staff report for once, it's been nearly 4 weeks. Oh yeah. Corruption. I quit along with many others, this shit won't change.

Re: for the attention of development staff URGENT

Posted: Wed Feb 06, 2019 2:25 am
by Iron adam
Braxton wrote:Like I said, corruption. How about Staff look at my staff report for once, it's been nearly 4 weeks. Oh yeah. Corruption. I quit along with many others, this shit won't change.
Did you even read the thread? He got his own information leaked by using it on another private server.
Send Ryan a message, he is the only one who deals with Staff Reports.