It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
avatar
micktiegs_8: It has to be something to do with Galaxy usage.
There must be a vulnerability in Galaxy that is easily exploited, and when someone logs in there info is stolen.

My friend has Witcher 3 but he hasn't used Galaxy at all, only the GOG downloader. No problems yet.
Not necessarily. Using Galaxy since very first alpha and no one stole my account with Tyrian 2000 on it, yet.. ; )

avatar
micktiegs_8: There must be a vulnerability in Galaxy that is easily exploited, and when someone logs in there info is stolen.
avatar
F4LL0UT: I wonder if a single account has been stolen which did not have Witcher 3 registered to it. I don't see how TW3 may be the cause of this but the overlap is remarkable.
I've been thinking about this same. Could be a problem with nvidia way of redeeming The Witcher or using VPN in some cases..
Post edited June 27, 2015 by mike_cesara
avatar
Randalator: So why is it that no GOG regulars have had their account stolen yet? There's 1.000.000+ people using Galaxy. If it was a Galaxy vulnerability, it wouldn't be just a few zero reppers, it would be fucking everyone.
avatar
Maighstir: Us forum regulars are just a very small minority of GOGs customer base, 95+% are most likely such "zero reppers" because they haven't yet made a single post.
That doesn't invalidate my argument. If it's a general vulnerability in Galaxy we would have seen someone with 1.000+ rep getting their account stolen. Or a blue. We'd also have seen a hell of a lot more people getting their account stolen.

But we haven't. The total numbers and the zero rep trend point to a cause outside GOG/Galaxy.
avatar
Randalator: So why is it that no GOG regulars have had their account stolen yet? There's 1.000.000+ people using Galaxy. If it was a Galaxy vulnerability, it wouldn't be just a few zero reppers, it would be fucking everyone.
avatar
Maighstir: Us forum regulars are just a very small minority of GOGs customer base, 95+% are most likely such "zero reppers" because they haven't yet made a single post.
Indeed. Also, forums regulars are more likely to spend a lot of time on the Intercatworld, which means they are more likely to have failsafe credentials protocols.
Post edited June 27, 2015 by Potzato
avatar
Maighstir: Us forum regulars are just a very small minority of GOGs customer base, 95+% are most likely such "zero reppers" because they haven't yet made a single post.
avatar
Potzato: Indeed. Also, forums regulars are more likely to spend a lot of time on the Intercatworld, which means they are more likely to have failsafe credentials protocols.
We know
But their argument was that it's a vulnerability in Galaxy. You can't put up failsafes against having you credentials stolen through a bug in the client.
Post edited June 27, 2015 by Randalator
avatar
Potzato: Indeed. Also, forums regulars are more likely to spend a lot of time on the Intercatworld, which means they are more likely to have failsafe credentials protocols.
We know
avatar
Randalator: But their argument was that it's a vulnerability in Galaxy. You can't put up failsafes against having you credentials stolen through a bug in the client.
Oops, a bit of my post was 'eaten'.
I meant to add :
We know that some of the people that got hacked didn't use galaxy at all (allegedly), one of the only thing that would make sense is people (edit : I mean hackers) using 'old' lists of credentials to try to harvest and resell gog accounts with The witcher 3.
I have yet to hear someone tell he got hacked whereas he had a strong and unique password for his gog account.
Post edited June 27, 2015 by Potzato
avatar
micktiegs_8: It has to be something to do with Galaxy usage.
There must be a vulnerability in Galaxy that is easily exploited, and when someone logs in there info is stolen.

My friend has Witcher 3 but he hasn't used Galaxy at all, only the GOG downloader. No problems yet.
avatar
mike_cesara: Not necessarily. Using Galaxy since very first alpha and no one stole my account with Tyrian 2000 on it, yet.. ; )
It could also be a combination of factors, such as TW3, Galaxy and NVidia codes. It wouldn't be the first time a vulnerability was caused, not by a single piece of software in itself, but by the way two or more software processes interacted with one another.
avatar
mike_cesara: I thought we're still talking about GoG ; )
It was a bit confusing for me, as I stated lost password for email, hence my confusion ;)

avatar
mike_cesara: That's ok. You already found your own answer ; )
Yeah, but some people are just ..... some people O-) I think you know what I mean ;)
avatar
Maighstir: Then they need to learn to keep track of their "throwaway" email accounts, maybe even use a single account for every signup. Or just find the account settings and make sure it's set up to not send emails about everything.
You never used throwaway I assume, some of them just stay for a day or so.
avatar
F4LL0UT: You do the exact thing you do if your account gets stolen right now, namely contact support and convice them somehow that you're the legit owner.

So you're saying that a group of remarkably stupid users who decided to use a throw away address to sign up on a service they wish to spend money on deserves protection more than the far less stupid majority? :P
Yes some users and owners of computers are so stupid, they shall have not the right to even own one. Sorry if it sounds harsh. But you need a driving license for driving, you need a license to operate a lot of things, some of them even trival....but for f*cks sake, not for computer....A lot of problems are coming from stupid users. Let´s say passwords: Yes 12345 is still one of the most common ones!!!!!

And sorry didn´t see your post 7, we must have typed at the same time ;)

Here for GOG slightly different, but as some people above (or below your post) pointed out, if this has something to do with any promotion/sale from another side, yes the Problem might come from there and even related to e-mails being used there.

Like:

Enter e-mail on Vendor A to get your code for GOG TW3

Here, if they used there normal e-mail might be already a problem. As I said before, I would use on a for me unkown website a throwaway account, just to get the code. Most users don´t bother.

Now they might even have to go to Vendor B

see above

finally they reach GOG, but because of weak password (or even wrong Galaxy, I read somewhere that their is already a hacked version of Galaxy)

Yes, a lot of users a plain stupid (when it comes to computers)! You can ask anyone working in IT-support!

For your point about continues access, didn´t say anything against it ;)

Maighstir:

Again, a lot of users are not intelligent enough for the web. Same goes for smartphones....How many idiots are not even applying the most basic security....Just think of, how many gazillion times have companies/websites/friends warned people:

DO NOT OPEN ANY ATTACHMENT FROM AN UNKNOWN SOURCE!!

And it is still No.1 for Virus infection.

For the support, see above ;)

Before I forget: Yeah, some people do not log in all the time or chat or pester around here ;)

So they might just come for summer/wintersale with a special e-mail address. In the moment, they can just change it, if they forgot.

And one important thing: If you never backed up your emails, how do you want to convince support, that YOU are the legit owner? (ups, talking about lost access to email ;) )

Sorry if I missed out something ;)
It could be just a "classic" case of rootkit + keylogger credentials swipe and nothing whatsoever related to Galaxy...
avatar
Goodaltgamer: Yeah, but some people are just ..... some people O-) I think you know what I mean ;)
..some people just deserve the shit they get.
Personally I wouldn't mind a bit if there was an IQ test before one were allowed to have access to internet or even walk out of home in some cases.. ; )
avatar
mike_cesara: ..some people just deserve the shit they get.
Personally I wouldn't mind a bit if there was an IQ test before one were allowed to have access to internet or even walk out of home in some cases.. ; )
Didn´t wanted to say it so harsh, but my idea as well ;)
avatar
mike_cesara: ..some people just deserve the shit they get.
Personally I wouldn't mind a bit if there was an IQ test before one were allowed to have access to internet or even walk out of home in some cases.. ; )
avatar
Goodaltgamer: Didn´t wanted to say it so harsh, but my idea as well ;)
Might be not very popular opinion those days but sometimes it is mandatory to say loudly, the king is naked! ; )
No offence to OP at all, just in general..

otherwise i start feeling like in bloody Harrison Bergeron novel..
Post edited June 27, 2015 by mike_cesara
avatar
mike_cesara: Might be not very popular opinion those days but sometimes it is mandatory to say loudly, the king is naked! ; )
No offence to OP at all, just in general..

otherwise i start feeling like in bloody Harrison Bergeron novel..
Right, we forgotten the disclaimer:

None of the above was written in the purpose to discredit or whatsoever the OP ;)

Now this is out of the way ;)

Harrison Bergeron? Doesn´t ring a bell....
avatar
Goodaltgamer: Harrison Bergeron? Doesn´t ring a bell....
Kurt Vonnegut short novel, worth every penny ; ) Also movie, not as good as the novel but still worth giving it a try.
avatar
mike_cesara: Kurt Vonnegut short novel, worth every penny ; ) Also movie, not as good as the novel but still worth giving it a try.
I just read the info of the link, it does sound familiar! I was never good at remembering names or titles....

Might have read/seen it looong time ago ;)

SO tonight I will watch it.

AND

IF I don´t like it, I will slap you silly ;) *getting beer and popcorn ready*
avatar
Goodaltgamer: Some people use throw away email accounts to get registered, like they don´t want any newsletter or similar....what about them?
avatar
mike_cesara: Not very clever move, isn't it?
Throwaway accounts are better for cases where you are forced to enter an email to do something like a survey to win a PS4 or something... Who would ever use a throw away account when you put money down on something?

but yeah, if they do, then they are seriously asking for trouble.