The phone hacking situation and phone security

GREE

DECAGAMES Forum - Powered by vBulletin
Page 1 of 2 12 LastLast
Results 1 to 15 of 21

Thread: The phone hacking situation and phone security

  1. #1
    Consistent Contributor zwiswoo's Avatar
    Member Since
    Jan 2013
    Post Count
    234

    The phone hacking situation and phone security

    The phone hacking story and discussion is great, but can we take a step back in this thread from the specifics of the SAS issue? It sounds frighteningly easy to gain certain kinds of control of someone's phone if you have access to some ID, but it's not clear to me how much and who can do it. I obviously don't want other game players to have such access, but more to the point I don't want anyone to have this kind of power over MY phone.

    Can someone in the know (don't disclose how to do the attack obviously!) explain
    a) What control precisely is gained? Is it over the CC app alone, or does it include e-mail/address book/browser etc? What about access to the phone hardware itself - calling, camera, GPS...
    b) Is this issue iOS or Android specific? Is a Bluestacks app safe? In principle it should be sandboxed, but the consequences of a breach are that much more severe.
    c) Is it possible (depending on whether the phone is rooted or jailbroken or as bought) to change permissions etc to limit the risk?

    Depending on the answer to a) - c) I am considering uninstalling and cleaning Crime City from my phone/computer. Obviously Gree employees will have access/change rights over my game stats, but there's no way I'd want them or anyone else to be able to take over my phone.

    Edit:
    1. I would really like for some Gree admin to make clear what/how severe any security vulnerability is, and whether there's a patch upcoming. Cheating and hacking game stats is one thing; losing control of the phone to strangers is a whole 'nother level of dangerous.
    2. What precisely is this ID? Is it a phone ID or something generated in-game? Why on earth is it being transmitted in plaintext in every support email if it can be misused?
    3. I really hope Gree can do *much* better than their usual tardy response on this one. Most people, even (especially?) heavy spenders, won't want a dangerous application running on their phone.
    Last edited by zwiswoo; 05-26-2013 at 11:55 AM.
    S
    Level 153
    57.8M A 39.8M D
    25.1M IPH

    Best shanty evar!

  2. #2
    Verbose Veteran the_dude's Avatar
    Member Since
    Oct 2012
    Location
    Welcome to Costco, I love you.
    Post Count
    603
    If you send a ticket to gree that info is in the header. Do not post tickets sent or received, this is against policy anyway.

  3. #3
    Articulate Author Beardy's Avatar
    Member Since
    Apr 2012
    Post Count
    368
    Don't panic..

    It's only possibly to gain access to your Crime City account. Everything else on your phone is safe.

    Just don't give out/show people your UDID and your be OK.

    Edit:
    1.
    The only thing in danger is your Crime City account (or other games you might play on that phone). But your phone's picture, contacts, etc are fine.

    2.
    The ID is the UDID, which is your phone's ID. Looks something like this: db72cb76a00cb81675f19907d4ac2b298628d83 (No, it's not mine.)
    Yeah, Gree should really be encrypting this in the emails. But it shouldn't be a problem unless you give it out to people.

    3.
    Don't count on it.
    Last edited by Beardy; 05-26-2013 at 12:16 PM.
    Transtech Hijinks Event - http://www.funzio.com/forum/showthre...Building-Event
    Dockside Mill Madness - http://www.funzio.com/forum/showthre...ide-Mill-Event
    Pagoda Pandamonium - http://www.funzio.com/forum/showthre...da-Pandamonium




    I am the danger. A guy opens his door and gets shot, and you think that of me? No. I am the one who knocks!

  4. #4
    Articulate Author
    Member Since
    Aug 2011
    Post Count
    345
    Quote Originally Posted by Beardy View Post
    Don't panic..

    It's only possibly to gain access to your Crime City account. Everything else on your phone is safe.

    Just don't give out/show people your UDID and your be OK.

    Edit:
    1.
    The only thing in danger is your Crime City account (or other games you might play on that phone). But your phone's picture, contacts, etc are fine.

    2.
    The ID is the UDID, which is your phone's ID. Looks something like this: db72cb76a00cb81675f19907d4ac2b298628d83 (No, it's not mine.)
    Yeah, Gree should really be encrypting this in the emails. But it shouldn't be a problem unless you give it out to people.

    3.
    Don't count on it.
    From an SAS member! It must be true!
    Lolz jk bro

  5. #5
    Banned
    Member Since
    Nov 2011
    Post Count
    4,193
    I've heard a rumour that someone with the right combination of skills and knowledge can use a udid to clone a device. The implication here is that everything that is stored on your device will be visible to someone who clones your device because the clone is essentially an identical copy of your entire device.

    From my understanding, however, this does not give someone "remote access" to your device. So your camera/mic/GPS can't be viewed/used by "whoever".

  6. #6
    Articulate Author camper killer's Avatar
    Member Since
    Jan 2013
    Post Count
    341
    Ok here are the straight facts from someone who has seen this done....

    by obtaining your device details the "hacker" can take over your entire game.

    it's as if the device the account is ported to is the device the game is meant to be on.

    they can act as the owner of the account in all manners. they can even transfer the account fully to another device and it would never go back to original owner..... unless Gree reassigned it, which takes weeks to do.

    as well, the "hacker" can buy, sell, use, get rid of everything and anything.... if they are really a "hacker" they can add units and delete them at will. they could modify the account in ways you would not imagine.
    Just a little ole friend with a hockey mask and my lucky machete!

  7. #7
    Steady Scribe
    Member Since
    May 2013
    Post Count
    79
    So is it your phones identification number what links your phone with your crime city account? Say for instance when you uninstall crime city and wipe all the data and cache, and then when you reinstall the game it remembers your account on your phone. If someone gets your identification number can they basically create another phone with a fake id number which is the same as yours install the game so that it recognises it as you?

  8. #8
    Banned
    Member Since
    Nov 2011
    Post Count
    4,193
    Quote Originally Posted by Alex_ View Post
    So is it your phones identification number what links your phone with your crime city account? Say for instance when you uninstall crime city and wipe all the data and cache, and then when you reinstall the game it remembers your account on your phone. If someone gets your identification number can they basically create another phone with a fake id number which is the same as yours install the game so that it recognises it as you?
    Correct.

    10

  9. #9
    Banned
    Member Since
    Sep 2012
    Post Count
    179

    UDID

    From my understanding they could access all data that is stored in the cloud, identified by your phone and not password protected. They would still need to log into your google account, for example (bad example because of the password needed, but google's servers might think that their phone is yours after they replace their phones UDID with yours)

    I'm pretty sure that this UDID info was given freely so that a team-mate could play while they were out of the game for a while. Someone Could start randomly changing their phone's ID numbers until they stumbled upon a CC player, but it would take the life time of the universe to find the person you are TRYING to find.

    This isn't like running a password cracker on a web login that doesn't stop you after 10 wrong tries.
    This process would take human intervention and couldn't be run at blindingly fast speeds. They might be able to check 100 UDID's and any associated CC accounts per day if they were dedicated. There are...
    800000000000000000000000000000000000000000000000(4 7 [forty seven] 0's) x 16 (? 0-9,a-f ?) combinations to try!

    The Worst case scenario if you don't give out any information: Someone is changing their UDID randomly and then starting CC. They FINALLY (after 1000 years of trying for 8hrs a day) stumble upon a player that is better than themselves, transfer the account, and are now that person. They change their UDID back, change their real accounts name to the name of the person they FINALLY found to hack, change their new, stolen account name to their original name and no one but GREE is the wiser (except their friends who noticed the crazy changes to their account). Now the player that got hacked logs into the game to find that their name is right, their mafia code is wrong and they are playing with a crappy account. GREE would fix this eventually as they would have the logs of the transfer (without a transfer, both devices would still be playing the same account). The account would be reverted to it's previous state as of the initial date, 1 day before the transfer.

    P.S. before you accuse me of spreading game hacking information please remember that this process would take about 1000yrs - 1million yrs to have a decent chance of stumbling upon a good UDID to hack. The hacker would be better off just playing the game.

    tl;dr - stop worrying and just keep your phone's info private if you play CC
    Last edited by gambet1234; 05-26-2013 at 02:45 PM. Reason: can't make the numbers 4 and 7 not have a space between them!

  10. #10
    Articulate Author
    Member Since
    Nov 2012
    Post Count
    285
    Hey it's crime city! When crime city gets real. Now go find out where they live and put some taps on them. Use your skills that you have learned, and stop crying.!!

    Lol.

  11. #11
    Lurker
    Member Since
    Mar 2013
    Location
    Cali
    Post Count
    21

    Angry

    Another post so I can meet the stupid minimum and create my own posts.

  12. #12
    Verbose Veteran
    Member Since
    May 2012
    Location
    MD
    Post Count
    831
    So if they can remotely do this with other people's accounts just imagine what they can do with theirs.
    Probably create a syndicate of "top" players.

    Anyway all home movies are now off my phone.
    Last edited by Sandukan; 05-26-2013 at 07:49 PM.

  13. #13
    Banned
    Member Since
    May 2012
    Location
    Las Vegas
    Post Count
    1,651
    Quote Originally Posted by 932 View Post
    So monte are you staying in the syn with the account hackers?? Since your mr righteous and is against all hackers??
    A remedial english course would do you well.

  14. #14
    Master of Musings
    Member Since
    Apr 2012
    Location
    England
    Post Count
    3,981
    Quote Originally Posted by ($$$) snowman View Post
    That has to be a new level of hacking that gree is not prepared for authorities should get in and scope these types of hacks
    Would it be a "glitch" if Solo did it, lol
    "The Tokyo Rose of the Trailer Park"

  15. #15
    Consistent Contributor evj's Avatar
    Member Since
    May 2012
    Location
    Somewhere
    Main Game
    Crime City
    Post Count
    180
    Quote Originally Posted by gambet1234 View Post
    I'm pretty sure that this UDID info was given freely

    tl;dr - stop worrying and just keep your phone's info private if you play CC

    Follow his advice and you're safe.

    The truth is only how its presented!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •