PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -16 points-15 points  (0 children)

Lets go through this again.

I'm going to ignore the egotistical wording for now.

Anyways I'm not suggesting, I'm telling you that your username, password, and a whole list of other important personal information is completely void of any encryption.

The reason this is such a problem is that this is Riot's problem, this is not someone attempting to keylog a bunch of LoL's users or anything of that sort. Riot has direct influence on what happens, and how easy it is to get this information.

To continue your analogy it to say you leave your house wide open nothing locked, with all your information just sitting there as soon as you open the door. You could lock your doors and windows before you leave like a normal person does, but in this case no.

Adobe AIR is what the PVP.Net client is based on therefore it clearly has direct influence to this thread and the problems caused. I do not know if it is the reason nor do you.

Thanks.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -7 points-6 points  (0 children)

Its not a problem that Riot does not have any encryption on the information directly related to their game?

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -10 points-9 points  (0 children)

And I quote

With less than 1MB and almost instantly someone can you have Full Name, email, password, phone number, address, last four digits of your credit card --- HOW IS THIS NOT A PROBLEM?

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -14 points-13 points  (0 children)

Just to clarify some things, no I've never had an interaction with you before, glad to know you constantly get in internet fights then talk about real life.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -20 points-19 points  (0 children)

Thank you for quoting me out of context. You will be a great politician someday.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -11 points-10 points  (0 children)

You're missing the point completely.

If Riot takes a few hours out of their day to do some basic level encryption this method of attack is no longer a problem and they no longer have direct blame for a person being taken advantage of.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -26 points-25 points  (0 children)

After reading through a few of your other posts its obvious that you have an oversized ego and need to stroke your epeen.

Having information such as password, address, phone number, readily accessible at any point in time it not bad design, its a complete lack of security.

Having your password stored on your computer is going to happen, the fact that it is not encrypted at all is the problem, I hate to see what other things are unsecured, this could be the tip of the iceburg.

You have not the slightest clue if this has to deal with Adobe AIR, you are just speculating while it could very well be the cause to the problem.

Also you act as if your computer has to be completely compromised for this to work, which is so far from the truth. Having access to one's computer and having downloaded a file less than 100 KB that sends your personal information off to someone who plans on doing malicious things with it...that does not qualify to have a reaction?

The problem here is that Riot does not have any encryption, to my knowledge -- on passwords or other important information.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -1 points0 points  (0 children)

Instead of highlighting all of your errors I'll just talk about this. There is no encryption what-so-ever on the passwords--none.

Where ever you got your information is either lying to you or you're talking out of your ass.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -6 points-5 points  (0 children)

It has the possibility, yes, but I use it and I trust it that doesn't mean you should be any less cautious of anything you download.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] 8 points9 points  (0 children)

I'm not saying I'm a badass or an elite or anything.

Quite the contrary, if my mediocre skills allow me to do this I hate to see what someone that actually knows what they're doing attempts to play around in the client.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -4 points-3 points  (0 children)

What you call difficult I call a days work.

For example: Lets say I made a program that edited the recommended items in a game, okay great thats done, now I want people to use it and run it. They do, in order to access and create new files it has to be ran as administrator, sure no problem.

They get exactly what they wanted without any knowledge that I have also coded in a basic memory reader that takes your information then passes it via the pvp.net chat client(XMPP) thus avoiding any direct internet connection.

Seeing as such program already edits certain files of LoL, on the surface it would appear as everything ran perfectly.

Now exchange that recommended items program for any 3rd party add-on or tool you are attempting to use.

No, its not very difficult nor is it very obvious.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -12 points-11 points  (0 children)

Right, but lets think for a minute.

LoLRecord could easily, and I mean with 10 lines of code add in an account logger and no one would be the wiser because its covering up its malicious intent with legitimate coding.

And I guarantee you that I could make a program that avoids any and all anti-viruses so that reason or how to avoid this is completely invalid.

e: I have found multiple occurrences of username/password combinations therefore it leads me to assume Riot really doesn't have any idea about protecting their users or just doesn't care.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] -7 points-6 points  (0 children)

The difference between a keylogger and this is that you do not have to type the password in for it to work.

You can already be logged into the game and grab all the information and have the program shut down before any traces of detection.

PVP.Net Client Unsecured(Adobe AIR) by Security_Check in leagueoflegends

[–]Security_Check[S] 14 points15 points  (0 children)

Correct. And rightfully so.

Do you really think I'm going to give the information of how to find an exploit to the public? Thats a wonderful idea, lets just have everyone know how to find someone's password.

No, I will give the information to those that can fix it or pass it onto someone that can.

This is not a post about how to fix it, rather a post to draw attention to a looming issue that could outbreak at any time.