• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Ubisoft security incident [Update your uPlay password]

Stumpokapow

listen to the mad man
To add to this, semi-fringe case, but iCloud Keychain in iOS7/Mavericks once they're out publicly, free and works well (in it's current beta form).

Unfortunately for a lot of us, even primarily Mac/iOS users, we're going to have an office computer or something that runs Windows and we're going to need a cross-platform solution. :/
 
Skimmed the thread so maybe this has been answered already, but Yes, if you have used UPlay on consoles, a UPlay account exists in the email that your Gamertag is listed under. The actual username will have been randomly generated by UPlay however, but an account exists nontheless.

Thanks for explaining. I'll check out what I need to do.
 

CrunchinJelly

formerly cjelly
I'm getting sick of receiving these kind of e-mails on what seems like a fortnightly basis.

I knew I should've jumped on 1Password when they had a sale on a few weeks back. I'm gonna give iCloud Keychain a try for now.
 
I'm using 1password after using Keepass for what, 10 years?

1password
+ Awesome iPhone and OSX apps. Windows app is good though nowhere near the slickness
+ Native dropbox support for your password database
+ Can create USB key export as needed
+ Awesome password generation and auto-fill options to promote using strong passwords
- Expensive; now that the sale is over it's $18 on iOS and $50 on OSX, though there's an OSX+W9X combo deal.

KeePass
+ Free, vaguely recall it being open source
+ KeePassX runs off of USB keys without any install required
+ Very strong; can generate passwords, require both a key file AND a password
+ Tiny and not resource intensive in any way
- No browser integration or dropbox; that stuff is up to you.
- Any phone apps that exist are 3rd party

Bottom line; 1pass was great at the sale price (50% off) but is really expensive right now. KeePass gives you mostly the same experience and it costs nothing.
 
I use Keypass on Windows, iOS and OSX but the current state of the OSX support is a little lacking (a new updated client is currently in development, I'm using a beta) . The iOS app is pretty terrific though and the Chrome Windows plugin that works with the standard windows client is perfect.
 
With all due respect, that's not going to happen. First because most password managers use local storage, so it's not possible to blanket hack them. Second because those that don't still use absurdly strong encryption and rely on the user having a secure master password--it's not remotely similar to your standard hack a vulnerable web server, steal a gazillion unsalted md5 passwords scenario, so a hack wouldn't result in the kind of data disclosure that's problematic here.

If everyone starts using password managers to remember their essentially uncrackable passwords, then hackers are going to change their methods accordingly. And no system is perfect. The very nature of password managers is a glaring weakness by making all your passwords protected by a single password.

It's like authenticators. When they're not widespread, they offer good protection because attackers go after the low-hanging fruit instead. When everyone has to use one there's a huge incentive to attack it, and that's precisely what you see.

Further, you can't make blanket statements like "that's not going to happen". Previously secure algorithms do get broken from time to time. Or sometimes bugs in the software implementation present weaknesses. Anyone who knows anything about the matter will find this to be nothing new.

There are a lot of intelligent and dedicated people out there interested in breaking these systems, and as a result many people spend a lot of time, effort, and money trying to stop them. Security and complacency do not go hand in hand.
 

dangeROSS

Member
I got an E-mail as well. I forgot that I had even signed up for Uplay. I'm guessing it must have been to play Driver -San Fransisco for the 360 I think. I thought it was odd that I had to make a Ubisoft account in addition to my 360 Gamertag to play that one. I dislike all these different accounts being forced down our throats to play games that shouldn't even need them.
 

Zushin

Member
Getting pretty tired of this bullshit TBH. Sick of having a million different accounts, emails, passwords that have to be seemly changed constantly because these companies can't get their act together :|
 
Ugh, Uplay, what a terrible idea it is.

xhibit+meme.jpg


"I heard you like to login when you login so we added some logins to your logins".

It can't be worse than the Konami thing to try MGO though.
 

Li Kao

Member
I don't "do" a lot of mobile log-ins, so I'll be taking a look at lastpass and keepass.

That's my problem, I do a ton of mobile log-ins... So what ? I must choose between unsecured and using a probably shitty browser on ios ? The question has been bugging me for a few months but this new hack is really trying my patience with password security.
Maybe I could still use my passwords and just use a manager for sensible stuff that I don't browse on mobile, but that doesn't strike me as ideal.
 
Goddammit Ubisoft, if you had just let me play Far Cry 3 on Steam without requiring me to create a worthless Uplay account, this wouldn't be a problem.

Oh well. They'd never crack my password anyway since it's a long string of gibberish created by LastPass.
 

Tunesmith

formerly "chigiri"
Unfortunately for a lot of us, even primarily Mac/iOS users, we're going to have an office computer or something that runs Windows and we're going to need a cross-platform solution. :/

Apple has an iCloud Control panel for Windows as well, and I believe their plan is to have the functionality on Windows as well through it (and likely Safari). But I'm not 100% certain on that part yet.
 

Joeki11a

Banned
This is some Viral watchdogs crap?

I figure some hackers would take offense to the watchdog game having a hacker cause chaos and crap
 

malfcn

Member
I have played several uPlay games (Ass Creeds and Conviction) but nothing show sup in my uPlay history other than a new account earlier this year. What's that about?
 

RivalCore

Member
- Open email link

- Right click and select "generate secure password" from my Lastpass plugin

- Done.

Pretty swift all things considered. I don't even know what my original password for uPlay was.
 
I have played several uPlay games (Ass Creeds and Conviction) but nothing show sup in my uPlay history other than a new account earlier this year. What's that about?

I'm having the same problem, I think the uplay servers are getting hammered right now. It shows in the top right "There is a problem connecting to a Uplay service, We will restore connection as soon as possible"

EDIT: Go into Offline mode and all your games should be there.
 

The_Monk

Member
Thank you for creating this thread fellow GAFfer.

I changed my Password, not sure what else I can do.

Last week I Logged in on Uplay to check those points you get for playing Ubisoft titles and decided to spend some and get a Theme from Assassins Creed 3 for the PS3.

Changing our Password is all we can do now, right?
 

Dr Dogg

Member
Those of you saying that you're 'excited' for an all digital future are you saying that you use the same password for every website and service? Surely that's asking for trouble if a leak occurs. Do you also use the same email address to register an account for social and sales related sites?

It may seam like a hassle having a different password for every site and multiple email addresses but it's a lot easier to manage than having to go change every single set of credentials if just one company is either unfortunate or happens to be careless.
 

sakipon

Member
My only link to Ubisoft is via Wii U (uPlay app). I assume this does not effect such users? I can't remember if one had to create any passwords or such. Admittedly I haven't received any mail yet.

Though I remember the app suggested I should login on the website in order to finish my avatar or something.
 

Xanathus

Member
Weird, I haven't received an email warning me to change my password but I've been playing AC3's multiplayer the past few days and yesterday my credits weren't showing up at all and it wasn't letting me purchase any new abilities/perks.
 

Caelestis

Member
I got the e-mail, but I don't remember making an account with them or even playing any of their games in general that have that uplay thing... Other than Prince of Persia '08. Did it require it?
 
Ugh, I'm a member on like a million websites (obvious exaggeration). I don't remember which password I use where; Firefox remembers that for me. Dammit, Ubisoft. What a pain.
 

Willy Wanka

my god this avatar owns
I'm pretty sure this will be the second time I've had to change my Ubisoft password because of a security breach. Didn't they also have some kind of security problem relating to uPlay DRM last summer too?
 
Top Bottom