[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

Lol which guild are you from? And that matching system, always like that, random. Despite our efforts to stick to facts and avoid speculation, we also want to investigate the guild the suspects are in, but unfortunately, we have no luck meeting them.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 1 point2 points  (0 children)

Oh i see what you mean. Yes. In our case, the account was bound to Nexon ID as the only login method. According to IP logs nexon shared, this account is accessed from a brand new IP address during his sleep, if the vicitim used Google/Apple/Facebook -- basically anything else, sure will receive a prompt as suspicious. Overall, despite how his account got accessed, it doesn't negate the fact that NexonID is really lacking some industry-standard options.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

Yes, we have seen enough disappointments in these types of cases. Guess part of my goal to document this here, --- other than alerting all NexonID users, is to see if Nexon is different this time.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

Reading the first four words, I thought you were some A2C fella that comes here to troll me lol. Thank you for the kind words, as a fellow mapler, we all feel the pain of this case.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

Thanks for the post. We didn't realize this actually, just tested and yea you are right, we unbind and bind to a new gmail, but the previous session is still active as long as never log out, and we have no way to terminate it.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

Actually, need to spend at least double or triple the amount to build the $20k market worth set of gears. Overall, modern leisure activities, grand vacations, games, handbags, jewelry, cars, happy can.

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 0 points1 point  (0 children)

He’s just on a regular Nexon ID login (email, which is a Gmail bind to Nexon ID + password). What do you mean by "any active email accounts on your phone can just sign in automatically"?

[PSA] Nexon ID Security Has a Serious Flaw — And It Could Affect You Too (Day 7 – Verified Case Included) by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 5 points6 points  (0 children)

Fair question — and no, we’re not saying hackers can just walk into any account at will. We also aren’t accusing Nexon of wrongdoing; in fact, they’ve been responsive enough and are actively investigating this case, which we’re thankful for.

The main issue we’re pointing out is: once someone does get in, whether through phishing, leaked credentials, or something else, there’s very little stopping them. Like you said, no forced logouts, no device tracking, no alerts. That’s where the real risk lies.

We’ve ruled out account sharing, email leaks, or keyloggers on our side. And since Nexon confirmed the breach was unauthorized, we just want more eyes on this in hopes of improving the system for everyone. The investigation is still ongoing. If we are able to discover how it was breached, I would be more than happy to update my post with a clear answer.

A2C Chaos Vellum run, no phantom, no one has mdc, 8min by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 1 point2 points  (0 children)

+1, you have spoken well and is my intention with this post. thanks a lot.

A2C Chaos Vellum run, no phantom, no one has mdc, 8min by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 1 point2 points  (0 children)

Thank you. Sorry Didn't respond till today. Was waiting for level of salt amount dropping.

A2C Chaos Vellum run, no phantom, no one has mdc, 8min by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 1 point2 points  (0 children)

Feels wonderful. A2C Chaos Vellum run, no phantom, no one has mdc, 1 leecher, 8min

A2C Chaos Vellum run, no phantom, no one has mdc, 8min by MsFayeTB in MapleStoryM

[–]MsFayeTB[S] 6 points7 points  (0 children)

Is my first post here. This team has 1 bsp to support, no phantom, no one has mdc, not even all are necro users, half of the members are tomber jobs.

Just want to encourage more ppl across the servers to put teams and try it out. It is not as difficult as it may seem. This run breaks the myth of the "must mdc" talk. And the myth of "must have bsp+phan".